MIME filtering immune to new MyDoom

"lsi" <[email protected]>
Newsgroups gmane.comp.security.virus
Message-ID <421B7863.18217.4A26590@localhost>
Well, the new MyDoom "was created by repackaging an older MyDoom 
variant in an encrypted "wrapper" so that anti-virus software could 
not recognise it" according to Techworld - seeing a red rag I quickly 
checked my filtered folder and oopsie!  Thar' she blows ...

According to Symantec the worm may send itself as a double-zipped 
file (a zipfile within a zipfile) - if this is the "encrypted 
wrapper" referred to by Techworld I can report it makes absolutely no 
difference to the appearance of the worm from a MIME perspective:

Content-Disposition: attachment;
	filename="instruction.zip"

XEsDBAoAAA [...etc...] 

(first character changed to avoid tripping AV filters)

No need to change any settings (or update any sigs!) to detect this 
one!

URLs:

http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

http://www.techworld.com/security/news/index.cfm?NewsID=3163

http://www.cyberdelix.net/tech/filtering.htm

Stu

---
Stuart Udall
stuart [email protected] net - http://www.cyberdelix.net/

--- 
 * Origin: lsi: revolution through evolution (192:168/0.2)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.