W32.Zafi.b

  • Thread starter Thread starter John Coutts
  • Start date Start date
J

John Coutts

Does anyone have more insight into this latest virus (also called W32.Erkez.B)?
This one bears some resemblance to the MyDoom virus, in that it seems to
undertake a dictionary type attack. The names used are strange:
-------------------------------------------------------------------
raha, boca, sivucu, mauuc, ogaj, dojumul, ezogau, ugiveb, sifu, zeceuc,
valo, siki, rulo, podi, utaz, eseuuce, izudo, imel, gakef, sijo, owedose,
rasat, nudoril, naba, weserin, tivewo, sera, sofil, uusepiz, rofi,
cigicoc, sace, papi, miur, osej, dosi, bizugo, jura, efud, wune, beruh,
zula, jifa, dauz, tatofis, huwihof, wusu, hune, ifef, zirahab, uricu,
wijihaf, fimu, wupa, imou, vajujo, gokufe, fago, ilacu, dija, sofi,
begu, kidi, mifirek, giwowo, biuh, five, hukal, iremejo, nejum, epou,
mahoj, juuriv, juwu, jupa, uziv, nagibaz, ubos, fobuu, wivuzov, fola,
osag, norov, besi, howe, ocotosu, asose, ponu, ujobiw, kareh, ihok, camu,
hore, cumo, cazaw, cibam, hobe, somo, hipesic, cegi, jawubo, hutaheh,
peli, renelu, repeu, haci, poli, cowab, upit, igis
 
On that special day, John Coutts, ([email protected])
said...
Does anyone have more insight into this latest virus (also called W32.Erkez.B)?
This one bears some resemblance to the MyDoom virus, in that it seems to
undertake a dictionary type attack. The names used are strange:

I can only guess, but this looks like it is language specific, maybe
romanian. Which means, the malware isn't capable to get past password
protected shares, if the passwords are in any other language.


Gabriele Neukam

(e-mail address removed)
 
Later versions are multi-lingual
Gabriele Neukam said:
On that special day, John Coutts, ([email protected])
said...


I can only guess, but this looks like it is language specific, maybe
romanian. Which means, the malware isn't capable to get past password
protected shares, if the passwords are in any other language.


Gabriele Neukam

(e-mail address removed)
 
Back
Top