TCH-Rob Posted December 14, 2004 Posted December 14, 2004 As of December 14, 2004 8:13 AM PST, TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_ZAFI.D. TrendLabs has received several infection reports indicating that this malware is spreading in Germany, France and Spain. The following is a brief overview of the worm process: This worm spreads via email or peer-to-peer (P2P) file-sharing networks. Here is a sample of the email: Subject: Re: Merry Chrsitmas! Message body: Happy Hollydays! Pamela M. Attachment: postcard.index.php1111.pif Note that the language of the email may change depending on the domain of the recipients. Quote
boxturt Posted December 14, 2004 Posted December 14, 2004 I've caught 4 today - before they got to my machine thank goodness. Quote
Madmanmcp Posted December 14, 2004 Posted December 14, 2004 Info From McAfee -- Update Dec 14th 2004 -- The risk assessment of this threat was raised to Medium due to increased prevalence. The 4414 DATs were released early for this threat. -- This new variant contains the following characteristics: contains its own SMTP engine to construct outgoing messages spoofs the From: address harvests target email addresses from the victim machine outgoing email message body is either in Hungarian or English displays p2p worm behaviour shuts down security services Payload In an attempt to thwart manual identification and cleaning of an infected machine, the worm will attempt to render the following processes containing the following strings unavailable: reged msconfig task The worm also attempts to shutdown security services like firewalls, and AV software upon execution. Indications of Infection Method of Infection This worm does not use any exploit code in order to execute the mail attachment automatically. A user has to doubleclick on an infected attachment or a file shared via P2P to infect Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.