Zafi-D wishes us Happy Hollydays

Wednesday, December 15, 2004
Author: Webmaster

W32/Zafi-D is a mass mailing worm spreading Christmas cheer. It will also spread itself via peer-to-peer networks.

It is observed to be spreading rapidly. More information can be found at Sophos and Symantec which calls it Erkez.D. The payload consists of disabling antivirus services, using the address book to spread itself, and opening up a backdoor on tcp port 8181 to remote attackers. Even if you're blocking all executable attachments at your gateway, this worm will randomly send the infector file inside a zip file.


http://www.antisource.com/article.php/200412152022437