[Esd-l] SirCam [As per your request!]

Dave Clendenan clendenan at squirrel.mine.nu
Tue Sep 4 19:15:01 PDT 2001

I just received the following SirCam-infected message, whose
attachment has only one (.exe) extension.  Is this a new version of
the virus?

Anyone else seen similar things?

I tried adding the SirCam signature filter from
http://www.impsec.org/email-tools/sanitizer-configuration.html, but I
could still mail it to myself. (This may be an issue with my setup
of the local-rules file, tho).

I have successfully caught a large number of double-extension SirCams,
probably nearly as many as all other viruses in total...
This is the first single-extension version I've seen.


----- Forwarded message from [poor infected guy] -----

Mailing-List: list cvsgui at yahoogroups.com; contact cvsgui-owner at yahoogroups.com
Delivered-To: mailing list cvsgui at yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:cvsgui-unsubscribe at yahoogroups.com>
Date: Tue, 4 Sep 2001 15:04:06 +0200
Reply-To: cvsgui at yahoogroups.com
Subject: [cvsgui] As per your request!
X-Security: MIME headers sanitized on squirrel
	See http://www.impsec.org/email-tools/procmail-security.html
	for details. $Revision: 1.129 $Date: 2001-04-14 20:20:43-07 

Please find attached file for your review.
I look forward to hear from you again very soon.  Thank you.

------------------------ Yahoo! Groups Sponsor ---------------------~-->
CLICK HERE to search
600,000 scholarships!

To unsubscribe from this group, send an email to:
cvsgui-unsubscribe at egroups.com


Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 
[-- Attachment #2: readme.31999DEFANGED-exe --]
[-- Type: application/octet-stream, Encoding: base64, Size: 32K --]

----- End forwarded message -----

Dave Clendenan
clendenan at squirrel.mine.nu

PGP key: 0xBF4BDF75  
fingerprint: 910E 8400 7A16 822C 9B62  209F 6CAB DEDF BF4B DF75

Duct tape is like the force.  It has a light side, and a dark side, and
it holds the universe together ...
		-- Carl Zwanzig

More information about the esd-l mailing list