|
Due to the increased rate of submission, researchers at the Symantec
AntiVirus Research Centre (SARC) have upgraded the threat level of
W32.Sircam.Worm@mm from 3 to 4.
W32.Sircam.Worm@mm is a worm which is network aware and has email
spreading capabilities.
The worm is particularly dangerous because it cannot be identified by
the subject line and message, therefore filtering for subject lines and
attachments is ineffective.
The worm can arrive as an email message or from another machine on the
network.
Subject: The subject of the email will be random, and will be the
same as the file name of the attachment in the email.
Message: The message body will be semi-random, but will always
contain one of the following two lines (either English or Spanish) as the
first and last sentences of the message.
Typically the Spanish version will feature:
First line: Hola como estas ?
Last line: Nos vemos pronto, gracias.
The English version will feature:
First line: Hi! How are you?
Last line: See you later. Thanks |