Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Anyone seeing 21486 byte Attach.zip/password protected/.ex..

 
Goto page 1, 2
   Security Forums (Home) -> General Discussions RSS
Next:  Bagle  
Author Message
Don Taylor

External


Since: Oct 06, 2003
Posts: 26



(Msg. 1) Posted: Wed Mar 03, 2004 5:09 pm
Post subject: Anyone seeing 21486 byte Attach.zip/password protected/.exe file?
Archived from groups: alt>comp>virus (more info?)

Subject: ello! =))

I don't bite, weah!

48028 -- archive password

and a 21486 byte Attach.zip with password that contains gcqlk.exe.

Latest Norton scan sees nothing, googling finds nothing, searching
AV sites turns up nothing.

Spewed from Comcast with forged header claiming it is from
fp0.TakeThisOut@goaway.cc.monash.edu.au, as if that makes any difference.


I ain't gonna execute that, mummy didn't raise the stupid children.

 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Will Dormann

External


Since: Jun 17, 2004
Posts: 110



(Msg. 2) Posted: Wed Mar 03, 2004 11:13 pm
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Don Taylor wrote:

> Subject: ello! =))
>
> I don't bite, weah!
>
> 48028 -- archive password
>
> and a 21486 byte Attach.zip with password that contains gcqlk.exe.
>
> Latest Norton scan sees nothing, googling finds nothing, searching
> AV sites turns up nothing.
>
> Spewed from Comcast with forged header claiming it is from
> fp0.TakeThisOut@goaway.cc.monash.edu.au, as if that makes any difference.
>
>
> I ain't gonna execute that, mummy didn't raise the stupid children.


It's likely Bagle.K


-WD

 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
me

External


Since: Dec 27, 2004
Posts: 198



(Msg. 3) Posted: Thu Mar 04, 2004 12:05 am
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Imported from groups: per prev. post (more info?)

Back to top
Login to vote
Big Will

External


Since: Feb 29, 2004
Posts: 76



(Msg. 4) Posted: Thu Mar 04, 2004 12:05 am
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

me DeleteThis @tadyatam.invalid wrote:

> Don Taylor wrote:
>
>>Subject: ello! =))
>>
>>I don't bite, weah!
>>
>>48028 -- archive password
>>
>>and a 21486 byte Attach.zip with password that contains gcqlk.exe.
>>
>>Latest Norton scan sees nothing, googling finds nothing, searching
>>AV sites turns up nothing.
>>
>>Spewed from Comcast with forged header claiming it is from
>>fp0@goaway.cc.monash.edu.au, as if that makes any difference.
>>
>>I ain't gonna execute that, mummy didn't raise the stupid children.
>
>
> 'Atta boy! Smile
>
> Discovery date today, 3/3.
>
> It appears to be bagle/beagle, as the other replies note.
> A.k.a. I-Worm.Bagle.j, Beagle.A, Bagle.K, Bagle.Variant.Worm,
> Bagle.gen, ... (more?)
>
> J
Bagle.zz

--
William


If it don't work, hit it
If it still don't work, kick it
If it works after hitting it or kicking it, then it doesn't matter if
that helped, what's important is it worked.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Don Taylor

External


Since: Oct 06, 2003
Posts: 26



(Msg. 5) Posted: Thu Mar 04, 2004 12:05 am
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Big Will <SPAMWSPAMiSPAMlSPAMlSPAMBSPAM4SPAMeSPAMvSPAAAAAMeSPAMMITTYrSPAAAAAM DeleteThis @nIeDONTtLIKEzSPAMero.net> writes:
>me@tadyatam.invalid wrote:
>> Don Taylor wrote:
>>>Subject: ello! =))
>>>
>>>I don't bite, weah!
>>>
>>>48028 -- archive password
>>>
>>>and a 21486 byte Attach.zip with password that contains gcqlk.exe.
>>>
>>>Latest Norton scan sees nothing, googling finds nothing, searching
>>>AV sites turns up nothing.
>>>
>>>Spewed from Comcast with forged header claiming it is from
>>>fp0@goaway.cc.monash.edu.au, as if that makes any difference.
>>>
>>>I ain't gonna execute that, mummy didn't raise the stupid children.
>>
>> 'Atta boy! Smile
>> Discovery date today, 3/3.
>>
>> It appears to be bagle/beagle, as the other replies note.
>> A.k.a. I-Worm.Bagle.j, Beagle.A, Bagle.K, Bagle.Variant.Worm,
>> Bagle.gen, ... (more?)
>>
>> J
>Bagle.zz

Went ahead and unzipped it. Once decrypted Norton saw it and killed it.
W32.Beagle.H

So the password/encryption on the zip is going to get these right past
all the virus checkers. Cute. Is this worth reporting? Where?

And the game goes to the next level.

Thanks to everyone for help with the diagnosis
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Big Will

External


Since: Feb 29, 2004
Posts: 76



(Msg. 6) Posted: Thu Mar 04, 2004 12:05 am
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Don Taylor wrote:

> Big Will <SPAMWSPAMiSPAMlSPAMlSPAMBSPAM4SPAMeSPAMvSPAAAAAMeSPAMMITTYrSPAAAAAM.DeleteThis@nIeDONTtLIKEzSPAMero.net> writes:
>
>>me@tadyatam.invalid wrote:
>>
>>>Don Taylor wrote:
>>>
>>>>Subject: ello! =))
>>>>
>>>>I don't bite, weah!
>>>>
>>>>48028 -- archive password
>>>>
>>>>and a 21486 byte Attach.zip with password that contains gcqlk.exe.
>>>>
>>>>Latest Norton scan sees nothing, googling finds nothing, searching
>>>>AV sites turns up nothing.
>>>>
>>>>Spewed from Comcast with forged header claiming it is from
>>>>fp0@goaway.cc.monash.edu.au, as if that makes any difference.
>>>>
>>>>I ain't gonna execute that, mummy didn't raise the stupid children.
>>>
>>>'Atta boy! Smile
>>>Discovery date today, 3/3.
>>>
>>>It appears to be bagle/beagle, as the other replies note.
>>>A.k.a. I-Worm.Bagle.j, Beagle.A, Bagle.K, Bagle.Variant.Worm,
>>>Bagle.gen, ... (more?)
>>>
>>>J
>>
>>Bagle.zz
>
>
> Went ahead and unzipped it. Once decrypted Norton saw it and killed it.
> W32.Beagle.H
>
> So the password/encryption on the zip is going to get these right past
> all the virus checkers. Cute. Is this worth reporting? Where?
>
> And the game goes to the next level.
>
> Thanks to everyone for help with the diagnosis
The next step would be to then set up filters to have attackments (sorry
Art) that have encrypted archives attatched to them to be automatically
deleted.

--
William


If it don't work, hit it
If it still don't work, kick it
If it works after hitting it or kicking it, then it doesn't matter if
that helped, what's important is it worked.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Bass

External


Since: Mar 04, 2004
Posts: 2



(Msg. 7) Posted: Thu Mar 04, 2004 8:55 am
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Don Taylor" <dont.RemoveThis@agora.rdrop.com> wrote in message
news:3N6dncEgkvdd-NvdRVn-vg@scnresearch.com...
> Subject: ello! =))
>
> I don't bite, weah!
>
> 48028 -- archive password
>
> and a 21486 byte Attach.zip with password that contains gcqlk.exe.
>
> Latest Norton scan sees nothing, googling finds nothing, searching
> AV sites turns up nothing.
>
> Spewed from Comcast with forged header claiming it is from
> fp0.RemoveThis@goaway.cc.monash.edu.au, as if that makes any difference.
>
>
> I ain't gonna execute that, mummy didn't raise the stupid children.

For what its worth , lately I have been receiving a heap of suspicious mail
from all sorts of edu sites such as yours - Monash is one of many . I don't
normally communicate with anyone from any of these places so I have just
been using mailwasher and deleting them at the server .
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Big Will

External


Since: Feb 29, 2004
Posts: 76



(Msg. 8) Posted: Thu Mar 04, 2004 8:55 am
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Bass wrote:

> "Don Taylor" <dont.TakeThisOut@agora.rdrop.com> wrote in message
> news:3N6dncEgkvdd-NvdRVn-vg@scnresearch.com...
>
>>Subject: ello! =))
>>
>>I don't bite, weah!
>>
>>48028 -- archive password
>>
>>and a 21486 byte Attach.zip with password that contains gcqlk.exe.
>>
>>Latest Norton scan sees nothing, googling finds nothing, searching
>>AV sites turns up nothing.
>>
>>Spewed from Comcast with forged header claiming it is from
>>fp0@goaway.cc.monash.edu.au, as if that makes any difference.
>>
>>
>>I ain't gonna execute that, mummy didn't raise the stupid children.
>
>
> For what its worth , lately I have been receiving a heap of suspicious mail
> from all sorts of edu sites such as yours - Monash is one of many . I don't
> normally communicate with anyone from any of these places so I have just
> been using mailwasher and deleting them at the server .
>
>
>
>
Did you trace IPs back to these .edu domains, or did you just go by the
from field?

--
William


If it don't work, hit it
If it still don't work, kick it
If it works after hitting it or kicking it, then it doesn't matter if
that helped, what's important is it worked.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Bass

External


Since: Mar 04, 2004
Posts: 2



(Msg. 9) Posted: Thu Mar 04, 2004 10:57 pm
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Big Will"
<SPAMWSPAMiSPAMlSPAMlSPAMBSPAM4SPAMeSPAMvSPAAAAAMeSPAMMITTYrSPAAAAAM@nIeDONT
tLIKEzSPAMero.net> wrote in message news:40467fa7$1@darkstar...
> Bass wrote:
>
> > "Don Taylor" <dont DeleteThis @agora.rdrop.com> wrote in message
> > news:3N6dncEgkvdd-NvdRVn-vg@scnresearch.com...
> >
> >>Subject: ello! =))
> >>
> >>I don't bite, weah!
> >>
> >>48028 -- archive password
> >>
> >>and a 21486 byte Attach.zip with password that contains gcqlk.exe.
> >>
> >>Latest Norton scan sees nothing, googling finds nothing, searching
> >>AV sites turns up nothing.
> >>
> >>Spewed from Comcast with forged header claiming it is from
> >>fp0@goaway.cc.monash.edu.au, as if that makes any difference.
> >>
> >>
> >>I ain't gonna execute that, mummy didn't raise the stupid children.
> >
> >
> > For what its worth , lately I have been receiving a heap of suspicious
mail
> > from all sorts of edu sites such as yours - Monash is one of many . I
don't
> > normally communicate with anyone from any of these places so I have just
> > been using mailwasher and deleting them at the server .
> >
> >
> >
> >
> Did you trace IPs back to these .edu domains, or did you just go by the
> from field?
>
> --
> William
>
>
> If it don't work, hit it
> If it still don't work, kick it
> If it works after hitting it or kicking it, then it doesn't matter if
> that helped, what's important is it worked.

hi William , no I didn't trace back , I just went on the from field , which
I know doesn't mean much in these cases . But strange that they all seem to
come from edu domains . Because these messages aren't from anyone I know and
they look suspicious plus they all carry attachments I just delete em at the
server .
Bass
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
mat

External


Since: Mar 14, 2004
Posts: 1



(Msg. 10) Posted: Sun Mar 14, 2004 3:24 pm
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

i just got this too....
how does something like this spread?
are people actually opening zip files and running randomly named exe's??
it's completely insane.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Big Will

External


Since: Feb 29, 2004
Posts: 76



(Msg. 11) Posted: Sun Mar 14, 2004 3:43 pm
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

mat wrote:

> i just got this too....
> how does something like this spread?
> are people actually opening zip files and running randomly named exe's??
> it's completely insane.
Yup. This is the product of stupid people on the internet.

--
William


If it don't work, hit it
If it still don't work, kick it
If it works after hitting it or kicking it, then it doesn't matter if
that helped, what's important is it worked.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Dave Cohen

External


Since: Mar 14, 2004
Posts: 4



(Msg. 12) Posted: Sun Mar 14, 2004 11:29 pm
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Not surprising really, the average computer user is non technical and simply
isn't aware of these issues. At some point in time the provider either
voluntarily or by legislation will do more to control the spread of all
sorts of malware.
"mat" <matpalm.DeleteThis@yahoo.com> wrote in message
news:212fa4a5.0403141524.331890ba@posting.google.com...
> i just got this too....
> how does something like this spread?
> are people actually opening zip files and running randomly named exe's??
> it's completely insane.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
FromTheRafters

External


Since: Sep 19, 2003
Posts: 1207



(Msg. 13) Posted: Mon Mar 15, 2004 10:03 am
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"mat" <matpalm RemoveThis @yahoo.com> wrote in message news:212fa4a5.0403141524.331890ba@posting.google.com...

> i just got this too....how does something like this spread?

Like wildfire.

> are people actually opening zip files and running randomly named exe's??

Passworded zip files no less.

> it's completely insane.

Not really - completely insane would be to have the e-mail
client do so automatically. I often wondered about the idea
that Eudora was a safer client due to the fact that it required
more steps to be taken before the malware is executed by a
user - it has now been shown that users stop at nothing and
will go to great lengths to execute malware on their systems.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
FromTheRafters

External


Since: Sep 19, 2003
Posts: 1207



(Msg. 14) Posted: Mon Mar 15, 2004 10:24 pm
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

<null.RemoveThis@zilch.com> wrote in message news:tmob50tlh8o8h72stvr5e580f121r2p3uv@4ax.com...
> On Mon, 15 Mar 2004 10:03:53 -0500, "FromTheRafters"
> <!0000@nomad.fake> wrote:
>
> >
> >"mat" <matpalm.RemoveThis@yahoo.com> wrote in message news:212fa4a5.0403141524.331890ba@posting.google.com...
> >
> >> i just got this too....how does something like this spread?
> >
> >Like wildfire.
> >
> >> are people actually opening zip files and running randomly named exe's??
> >
> >Passworded zip files no less.
> >
> >> it's completely insane.
> >
> >Not really - completely insane would be to have the e-mail
> >client do so automatically. I often wondered about the idea
> >that Eudora was a safer client due to the fact that it required
> >more steps to be taken before the malware is executed by a
> >user - it has now been shown that users stop at nothing and
> >will go to great lengths to execute malware on their systems.
>
> The idea is that sane apps are immune from malware no matter what the
> user does while using the app. Sane apps force the user to Save
> attackments, then either minimize the app or Exit from it, and then go
> into Explorer, find the test folder and the file, and double click in
> order to get zapped. In the case of zip attackments there's an
> additional step or two.

If they have decided to run the attachment, what difference does it
make? This is like the Linux zealots saying that viruses won't work
on Linux because you have to set them as executable. Users will
(with the developers help) find a way to make things easier for
themselves and malware to use their computers.

> So, users with any kind of clue at all concerning the dangers of email
> attackments are protected from inadvertent clcking. That's the idea.

Obviously, inadvertent clicking isn't the problem - it is the purposeful
running of attachments that would be better residing in the bit bucket
that is the problem.

> And those without any clue at all may not even know how to get zapped
> when using a sane email app Smile

Sure, but a really sane e-mail app wouldn't allow any attachments
in the first place - there are already enough ways to transfer files
over the network.

> The problem is convincing the public
> that they would be far better off using sane apps.

Truer words have never been spoken. :O)
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
FromTheRafters

External


Since: Sep 19, 2003
Posts: 1207



(Msg. 15) Posted: Tue Mar 16, 2004 5:34 pm
Post subject: Re: Anyone seeing 21486 byte Attach.zip/password protected/.exe file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

<null RemoveThis @zilch.com> wrote in message news:5e0e50pg4uc118e7h6ekon7fr5u2bceai5@4ax.com...
> On Mon, 15 Mar 2004 22:24:27 -0500, "FromTheRafters"
> <!0000@nomad.fake> wrote:

[snip]

> But how are they put them in the bit bucket?

Delete them, pipe them to the null device.

> >> And those without any clue at all may not even know how to get zapped
> >> when using a sane email app Smile
> >
> >Sure, but a really sane e-mail app wouldn't allow any attachments
> >in the first place - there are already enough ways to transfer files
> >over the network.
>
> Oh? You expect that users would put up with apps that don't allow the
> freedom of sending JPG's to their friends via email? I think you're
> dreaming Smile

No, I don't expect that any more than you expect anyone to give
up OE's useful HTML, Scripting, and ActiveX enhancements. ;o)

....but sane would be textual e-mail only by the KISS method.
 >> Stay informed about: Anyone seeing 21486 byte Attach.zip/password protected/.ex.. 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Do anti-virus scan zip password protected files? - Kaspersky do _not_ scan zip password protected files. Does anybody know if NOD32 and VirusScan Enterpise 7.0 scan Zi protected files? Thanks in advance, -- Angelo Lopes da Silva Porto, Portugal

Help : Worm Attach Mystery - Hello I am sure I have a worm/virus/trojan horse but I can't identify it. My system: runs win98 with all the latest patches Nortons Anti Virus 2002 with latest downloads no firewall Mailwasher used to screen out spam IPC runs anti-virus filter. 56k..

I have many "myphoto" not cleanable in Attach folder. help! - Hi, I have AVG Pro and when it runs it doesn't see many Worms I have in Attach folder of Eudora. I have just run online PC-Cillin and it has seen many Worms but it doesn't succeed to cleanable them. Why? In fact I have : Worm MIMAIL.R, Worm DUMARU.Y and....

My Attach folder is full of infected files. - Hi, I use Eudora and it has "Attach" folder full of infected files. I'm sure about it because two days ago it was empty, before bombing from Swen worm. But I have checked that folder with updated AVG antivirus and I have just done an online s...

Am I protected enough - I am using Win XP Pro behind a router with a hardware firewall. The I also have ad-aware installed as well as Sygate Pro, and then Norton Anti-virus 2003 Pro. I regularly update all. Is there anything else I can do that is free as I already have much..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Goto page 1, 2
Page 1 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]