[linux-elitists] Swen

Dragan Stancevic visitor@xalien.org
Mon Sep 22 10:25:07 PDT 2003


On Sunday 21 September 2003 16:40, Andrew Morton wrote:
> James Morris <jmorris@intercode.com.au> wrote:
> > Does anyone have a good procmail recipe for catching this one?  I've
> > managed to block 26MB of it (just for my account), but can't keep up with
> > all of the variations.
>
> I've been dying from it.  The below is lame, but seems to trap it all.

Andrew-

this is a very lame virus, obviously written by a kindergarden kid.

I filter it by it's signature, the weakness of the virus is in the junk it 
carries. 

1. It's always an html with 2 gifs and an exe.
2. The md5sum is always the same(look bellow)
3. It has a programming bug where sometimes the executable included is 0 bytes

Like having a sticker on it's back "It's me Swen". Amateurs :-)


Look:
linux:/kgdb # md5sum /tmp/virus*
b09e26c292759d654633d3c8ed00d18d  /tmp/virus1.exe
476225849b39aff9bb18d7fac79ad7da  /tmp/virus1.gif
b09e26c292759d654633d3c8ed00d18d  /tmp/virus2.exe
476225849b39aff9bb18d7fac79ad7da  /tmp/virus2.gif
b09e26c292759d654633d3c8ed00d18d  /tmp/virus3.exe
476225849b39aff9bb18d7fac79ad7da  /tmp/virus3.gif
linux:/kgdb # md5sum /tmp/virus*.gif
476225849b39aff9bb18d7fac79ad7da  /tmp/virus1.gif
476225849b39aff9bb18d7fac79ad7da  /tmp/virus2.gif
476225849b39aff9bb18d7fac79ad7da  /tmp/virus3.gif
linux:/kgdb # md5sum /tmp/virus*.exe
b09e26c292759d654633d3c8ed00d18d  /tmp/virus1.exe
b09e26c292759d654633d3c8ed00d18d  /tmp/virus2.exe
b09e26c292759d654633d3c8ed00d18d  /tmp/virus3.exe
linux:/kgdb #

-- 
Peace can only come as a natural consequence
of universal enlightenment. -Dr. Nikola Tesla



More information about the linux-elitists mailing list