
Yes, I got that one too. To my peering alias by coincidence. ClamAV identifies it as "Worm.Bagle.A2". ClamAV added it the database today, and mentioned that it was not in most signature databases yet. On Fri, Feb 27, 2004 at 07:12:42PM -0500, Todd Vierling wrote:
This one may be a variant of the recent worms. It's spreading by way of zipfile attachments. I don't have more info yet, but my $orkplace has just been hit by it and it's unknown to McAfee and Symantec at this time.
It's not W32.Netsky, as best I can tell, because of the attachment filename: this one uses things like accabaacc.zip that are new to me. I don't have more info on it at this time, but will try to snare a sample in transit if it hits my home system.
Just a heads-up,
-- -- Todd Vierling <tv@duh.org> <tv@pobox.com>
-- Stephen Milton - Founder/VP Internet (425) 881-8769 x102 ISOMEDIA.COM - Premium Internet Services (425) 869-9437 Fax milton@isomedia.com http://www.isomedia.com