AVERT Threat Notice: W32/Nachi.worm.b UPDATE
From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 02/12/04
- Next message: David H. Lipman: "AVERT Threat Notice: W32/Doomjuice.worm.b"
- Previous message: David H. Lipman: "Re: Win Virus"
- Messages sorted by: [ date ] [ thread ]
Date: Thu, 12 Feb 2004 10:30:15 -0500
Notice
This is a Low-Profiled Threat Notice update for W32/Nachi.worm.b
Justification
This worm has been updated from Low to Low-Profiled due to Media Attention at:
http://www.vnunet.com/News/1152735.
W32/Nachi.worm.b is referred to as Nachi-B or Welchi within the article.
Read About It
Information about W32/Nachi.worm.b is located on VIL at:
http://vil.nai.com/vil/content/v_101013.htm
Detection
W32/Nachi.worm.b was first discovered on 02/11/2004 and detection was available from the
4290 DAT files (Release Date: 08/28/2003) as Exploit-DcomRpc.gen . Named detection will be
added to the 4324 dat files (Release Date: 02/19/2004).
Though we consider this a low threat, AVERT has posted an extra.dat as part of the above
description for your convenience.
If you suspect you have W32/Nachi.worm.b, please submit a sample to
http://www.webimmune.net/
Risk Assessment Definition
For further information on the Risk Assessment and AVERT Recommended Actions please see:
http://www.networkassociates.com/us/security/resources/risk_assessment.htm
Best Regards,
McAfee AVERT - Anti Virus Research, Analysis, and Outbreak Management visit us at
www.avertlabs.com
- Next message: David H. Lipman: "AVERT Threat Notice: W32/Doomjuice.worm.b"
- Previous message: David H. Lipman: "Re: Win Virus"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|