03.03.2004 - Level 3 Virus: W32.Beagle.J@mm
|
W32.Beagle.J@mm is a mass-mailing worm that opens a backdoor on TCP port 2745 and uses its own SMTP engine to spread through email. It also sends the attacker the port on which the backdoor listens, as well as the IP address. W32.Beagle.J@mm also attempts to spread through file-sharing networks, such as Kazaa and iMesh, by dropping itself into the folders that contain "shar" in their names.
The email has the following characteristics:
From: spoofed to appear as though its coming from the one of the following addresses at the recipient's domain: management, administration, staff, noreply, support
Subject:
Attachment: A randomly named .exe file, inside a .zip file, or an .pif file. The zip file will be password-protected.
- View Threat Information
- Visit Symantec Corporation
|
|
|