  | |  | Virus on the list | Virus on the list 2004-01-19 - By Eucke Warren
Back Hey, this may be information you already have.....but....
My Vexira server just nabbed a message with a worm in it that appears to have originated from the list. The Worm is Worm/Bagle.B. I doubt that the other headers are unaltered so I don 't know that there 's enough information to figure out which of the list members is infected. Just an FYI.
Here is the Alert I received from my milter
Message-Id: <esbeqpfmekjyxlvlrmk@(protected) >
Sender: redhat-list-admin@(protected)
From: toshi.esumi@(protected)
To: redhat-list@(protected)
Date: Mon, 19 Jan 2004 21:35:21 +0000
Subject: Hi
Mail-From: <redhat-list-admin@(protected) >
Rcpt: <euckew@(protected) >
Queue-Id: 23528-799AB1E6
Status: The mail was not delivered!
--8 <--
Log-File:
--8 <--
info: extracting attachment 1 to /var/tmp/av-23531-ccE6xT/av-0
(encoding= "8bit ", name= "(no name) ", filename= "(no name) ")
info: extracting attachment 2 to /var/tmp/av-23531-ccE6xT/av-1
(encoding= "base64 ", name= "qjktyrpf.exe ", filename= "xgcjkahnf.exe ")
checking file "/var/tmp/av-23531-ccE6xT/av-0 "
checking file "/var/tmp/av-23531-ccE6xT/av-1 "
--8 <--
--
Eucke Warren
Today 's quote: "The software package said 'REQUIRES WINDOWS 9X OR BETTER ' so I installed Linux " <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN " >
<HTML > <HEAD >
<META http-equiv=Content-Type content= "text/html; charset=iso-8859-1 " >
<META content= "MSHTML 6.00.2800.1276 " name=GENERATOR >
<STYLE > </STYLE >
</HEAD >
<BODY bgColor=#ffffff >
<DIV > <FONT face=Arial size=2 >Hey, this may be information you already
have.....but.... </FONT > </DIV >
<DIV > <FONT face=Arial size=2 > </FONT > </DIV >
<DIV > <FONT face=Arial size=2 >My Vexira server just nabbed a message with a worm
in it that appears to have originated from the list. The Worm is <FONT
face= "Times New Roman " size=3 >Worm/Bagle.B. I doubt that the other headers
are unaltered so I don 't know that there 's enough information to figure out
which of the list members is infected. Just an FYI. </FONT > </FONT > </DIV >
<DIV > </DIV >
<DIV > <FONT face=Arial size=2 >Here is the Alert I received from my
milter </FONT > </DIV >
<DIV > <FONT face=Arial size=2 > </FONT > </DIV >
<DIV >Message-Id: < <A
href= "mailto:esbeqpfmekjyxlvlrmk@(protected) " >esbeqpfmekjyxlvlrmk@(protected) </A >> <BR > Sender:
<A
href= "mailto:redhat-list-admin@(protected) " >redhat-list-admin@(protected) </A > <BR > From:
<A href= "mailto:toshi.esumi@(protected) " >toshi.esumi@(protected) </A > <BR > To:
<A
href= "mailto:redhat-list@(protected) " >redhat-list@(protected) </A > <BR > Date:
Mon, 19 Jan 2004 21:35:21 +0000 <BR > Subject: Hi <BR > Mail-From: < <A
href= "mailto:redhat-list-admin@(protected) " >redhat-list-admin@(protected) </A >> <BR > Rcpt:
< <A
href= "mailto:euckew@(protected) " >euckew@(protected) </A >> <BR > Queue-Id:
23528-799AB1E6 <BR > Status: The mail was not
delivered! <BR >--8<-- <BR > <BR > <BR >Log-File: <BR >--8<-- <BR >info: extracting
attachment 1 to
/var/tmp/av-23531-ccE6xT/av-0 <BR >
(encoding= "8bit ", name= "(no name) ", filename= "(no name) ") <BR >info: extracting
attachment 2 to
/var/tmp/av-23531-ccE6xT/av-1 <BR >
(encoding= "base64 ", name= "qjktyrpf.exe ", filename= "xgcjkahnf.exe ") <BR >checking
file "/var/tmp/av-23531-ccE6xT/av-0 " <BR >checking file
"/var/tmp/av-23531-ccE6xT/av-1 " <BR >--8<-- <BR > <BR >-- </DIV >
<DIV > </DIV >
<DIV > <FONT face=Arial size=2 >Eucke Warren </FONT > </DIV >
<DIV > </DIV >
<DIV > <FONT face=Arial size=2 >Today 's quote: "The software package said 'REQUIRES
WINDOWS 9X OR BETTER ' so I installed Linux " </FONT > </DIV > </BODY > </HTML >
|
|
 |