The new "D" variant of the Zafi worm family is an advanced email attack that uses a well-design social engineering approach. It disquises itself as a holiday e-card which might be accidently opened by a lot of folks. McAfee, F-Secure, and other AV vendors have escalated this to MEDIUM RISK.
Zafi.D Worm - Holiday e-Card Risk (MEDIUM RISK)
http://vil.nai.com/vil/content/v_130371.htm
This new variant contains the following characteristics:
* contains its own SMTP engine to construct outgoing messages
* spoofs the From: address
* harvests target email addresses from the victim machine
* outgoing email message body is either in Hungarian or English
* displays p2p worm behaviour
* shuts down security services
Secunia has declared this new threat as MEDIUM RISK
http://secunia.com/virus_information/13874/
Zafi.D Worm - Holiday e-Card Risk (MEDIUM RISK)
http://vil.nai.com/vil/content/v_130371.htm
This new variant contains the following characteristics:
* contains its own SMTP engine to construct outgoing messages
* spoofs the From: address
* harvests target email addresses from the victim machine
* outgoing email message body is either in Hungarian or English
* displays p2p worm behaviour
* shuts down security services
Secunia has declared this new threat as MEDIUM RISK
http://secunia.com/virus_information/13874/
This post has been edited by harrywaldron: 14 December 2004 - 12:10 PM

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.



Back to top









