martymas Posted January 21, 2005 Report Share Posted January 21, 2005 To read an HTML version of this newsletter, go to: havent read the board so im not sure if has been posted yet.we can never be to careful martyhttp://www.trendmicro.com/en/security/report/overview.htmIssue Preview: 1. Trend Micro Updates - Pattern File & Scan Engine Updates2. Tsunami Worm – WORM_ZAR.A (Low Risk)3. Top 10 Most Prevalent Global Malware 4. Submit your Spam & Suspicious Files for AnalysisNOTE: Long URLs may break into two lines in some mail readers. Should this occur, please copy and paste the URL into your browser window.************************************************************************1. Trend Micro Updates - Pattern File & Scan Engine Updates ------------------------------------------------------------------------PATTERN FILE: 2.363.00 http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VRSCAN ENGINE: 7.500 http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VS2. Tsunami Worm – WORM_ZAR.A (Low Risk)------------------------------------------------------------------------WORM_ZAR.A is a mass-mailing worm that uses its own MessagingApplication Programming Interface (MAPI) engine to propagate. It gathers emailaddresses from Microsoft Outlook, and sends itself as an attachment. It runs onall Windows platforms (95, 98, ME, NT, 2000, and XP), and is currentlyspreading in-the-wild.This mass-mailing worm drops the following files in the Windows folder: crssr.exe raz32.exe tsunami.exe It then creates a registry entry to ensure that it automatically executesat every Windows startup. The worm propagates via email using MAPI. It gathers recipient addressesfrom Microsoft Outlook, and sends a copy of itself as an attachment. Theemail it sends contains the following details: Subject: Tsunami Donation! Please help!Body: Please help us with your donation and view the attachment below! We needyou! Attachment:tsunami.exeThis worm also also attempts to perform a distributed denial of serviceattack (DDoS).If you would like to scan your computer for WORM_ZAR.A or thousands of other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VTWORM_ZAR.A is detected and cleaned by Trend Micro pattern file#2.359.00 and above. For additional information about WORM_ZAR.A please visit: http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VU3. Top 10 Most Prevalent Global Malware (from January 14 to January 20, 2005)------------------------------------------------------------------------1. WORM_NETSKY.P2. HTML_NETSKY.P3. JAVA_BYTEVER.A4. EXPL_DHTML.GEN5. WORM_NETSKY.D6. SPYW_GATOR.D7. SPYW_GATOR.C8. WORM_NETSKY.B9. SPYW_GATOR.B10. WORM_NETSKY.C4. Submit your Spam & Suspicious Files for Analysis------------------------------------------------------------------------ Found a file on your computer, with a strange name, and it's not detectedas malware? Tired of getting spam email? Send it to us, for our engineers to analyze.Submit your spam for analysis:http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VWSubmit a suspicious file or undetected virus for analysis:http://trendnewsletter.rsc03.net/servlet/c...pgLlQgLlQgFV2VY***********************************************************************************______________________________________________________________________This message was sent by Trend Micro's Newsletters Editor using ResponsysInteract .To unsubscribe from Trend Micro's Newsletters Editor: http://trendnewsletter.rsc03.net/servlet/o...RFpgLmDgLmDgSE0To update your subscription preference, or to change your email address:http://trendnewsletter.rsc03.net/servlet/w...pkNlyLihkm_U_VU Quote Link to post Share on other sites
tg1911 Posted January 22, 2005 Report Share Posted January 22, 2005 Thanks, martymas. Quote Link to post Share on other sites
Oni Posted January 22, 2005 Report Share Posted January 22, 2005 Ohh never heard of a DDoS worm beforeThanks Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.