AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2005-05-31
Updated May 31st 2005 19:18 UTC
>>> "New Bagel Virus(es?)
We have received a few reports that readers are receiving what appears to be a new version of the Bagle virus in email this morning. The attachments (so far) appear to be named as a single digit number zip file (eg: "5.zip" or "7.zip") as a string (eg: "Be_not_jealous.zip") with a payload of "16_05_2005.exe" or "19_04_2005.exe". The .zip file is approximately 18k and is 36352 when extracted. Upon execution, this file will be copied to C:\WINDOWS\System32\winshost.exe and will then drop another 11k file into C:\WINDOWS\System32\wiwshost.exe
The registry key HKLM/Software/Microsoft/Windows/Current Version/Run is then updated to execute this winshost.exe file at boot…
>>> New Mytob Virus
We're also getting reports of a new Mytob virus. It appears that this one may be exploiting the MS05-016 vulnerability, as described in this bugtraq posting: http://www.securityfocus.com/archive/1/399…28/2005-06-03/0
Signature updates are starting to show up and catch this…"

- http://isc.sans.org/diary.php?date=2005-05-31
Updated May 31st 2005 19:18 UTC
>>> "New Bagel Virus(es?)
We have received a few reports that readers are receiving what appears to be a new version of the Bagle virus in email this morning. The attachments (so far) appear to be named as a single digit number zip file (eg: "5.zip" or "7.zip") as a string (eg: "Be_not_jealous.zip") with a payload of "16_05_2005.exe" or "19_04_2005.exe". The .zip file is approximately 18k and is 36352 when extracted. Upon execution, this file will be copied to C:\WINDOWS\System32\winshost.exe and will then drop another 11k file into C:\WINDOWS\System32\wiwshost.exe
The registry key HKLM/Software/Microsoft/Windows/Current Version/Run is then updated to execute this winshost.exe file at boot…
>>> New Mytob Virus
We're also getting reports of a new Mytob virus. It appears that this one may be exploiting the MS05-016 vulnerability, as described in this bugtraq posting: http://www.securityfocus.com/archive/1/399…28/2005-06-03/0
Signature updates are starting to show up and catch this…"