New virus outbreak
dnsadmin at 1BIGTHINK.COM
Mon Jan 26 23:34:59 GMT 2004
At 10:59 PM 1/26/2004 +0000, you wrote:
>On Mon, 2004-01-26 at 22:35, Dustin Baer wrote:
> > Jeff Falgout wrote:
> > >
> > > Looks like we are fighting a new outbreak - random
> > > file names with extensions of .scr, .pif, .exe, .zip, etc
> > Yes and it spoofs sender addresses. I have turned off "Notify Senders Of
> > Blocked Filenames Or Filetypes"
>Looks like Clam is detecting this as Worm.SCO.A
I noticed an unusual amount of these on a client's SonicWall over the past
12 hours (mine hasn't registered any more than usual, but I host mail):
01/26/2004 17:49:48.720 - Sub Seven Attack Dropped
- Source:xx.xxx.xx.xxx, 1785, WAN - Destination:xxx.xxx.xx.xx,
27374, WAN - -
There is no mail hosted there. Port 110 is closed.
Hunker down and watch!
More information about the MailScanner