MIME filtering immune to new MyDoom
"lsi" <[email protected]>
| Newsgroups | gmane.comp.security.virus |
|---|---|
| Message-ID | <421B7863.18217.4A26590@localhost> |
Well, the new MyDoom "was created by repackaging an older MyDoom variant in an encrypted "wrapper" so that anti-virus software could not recognise it" according to Techworld - seeing a red rag I quickly checked my filtered folder and oopsie! Thar' she blows ... According to Symantec the worm may send itself as a double-zipped file (a zipfile within a zipfile) - if this is the "encrypted wrapper" referred to by Techworld I can report it makes absolutely no difference to the appearance of the worm from a MIME perspective: Content-Disposition: attachment; filename="instruction.zip" XEsDBAoAAA [...etc...] (first character changed to avoid tripping AV filters) No need to change any settings (or update any sigs!) to detect this one! URLs: http://securityresponse.symantec.com/avcenter/venc/data/[email protected] http://www.techworld.com/security/news/index.cfm?NewsID=3163 http://www.cyberdelix.net/tech/filtering.htm Stu --- Stuart Udall stuart [email protected] net - http://www.cyberdelix.net/ --- * Origin: lsi: revolution through evolution (192:168/0.2)