05.19.2003 - Worm dupes with fake Microsoft address
|
W32/Palyh.A-mm
Beware of the new "Palyh" email-borne mass-mailing virus
On 17th May 2003, MessageLabs the email security company intercepted copies of a new mass-mailing virus called W32/Palyh-mm. The initial copies all originated from the Netherlands, although it is now active in at least 69 countries.
Name: W32/Palyh.A-mm
Number of copies intercepted so far: 11,161
Time & Date first Captured: 17th May 2003 07:55GMT
Origin of first intercepted copy: Netherlands
Number of countries seen active: 69
Top three most active countries: Hong Kong 5.8%, United States 8.2%, United Kingdom 57.5%
Email characteristics:
It appears that many emails are possible, and all contained attachments. Typical emails may appear as follows:
From: support@microsoft.com (NB: The email sender from: address is spoofed, and does not indicate the true address of the sender.)
- If you would like more information, visit CNET.
Or you can get some detailed information on the virus itself, at Message Labs.
- Source: CNET News
|
|
|
|
NID: 732 / Submitted by: Zero_Tolerance
|
| Categories:
Anti-Virus
|
| Most recent AntiVirus related news. |
|
Virus alert: Spies prize Webcams' eyes
|
|
W32.Mydoom@mm + W32.Zindos.A + Backdoor.Zincite.A Removal Tool 1.0.9.4
|
|
Level 3 Virus: W32.Beagle.AO@mm
|
|
Level 3 Virus: Mydoom, Zindos, and Doomjuice Worm Removal Tool (KB836528)
|
|
W32.Mydoom@mm + W32.Zindos.A + Backdoor.Zincite.A Removal Tool 1.0.9.3
|
|
View archive of AntiVirus related news.
|
Digg
del.icio.us
Furl
Google Bookmarks
Yahoo! My Web
AddThis Bookmark
|