NetPlus Communications     W32.Nimda.A @mm  Virus

Discovered on: September 18, 2001
Last Updated on: September 18, 2001 at 10:12:26 AM PDT

Symantec Security Response has received a number of submissions on W32.Nimda.A.@mm and is rating it as a Category 4.

W32.Nimda.A@mm is a new mass-mailing worm that utilizes email to propagate itself. The threat arrives as a file named readme.exe in an email.

In addition, the worm sends out probes to Microsoft IIS servers attempting to spread itself by using the Unicode Web Traversal exploit similar to W32.BlueCode.Worm. Compromised servers may display a webpage prompting a visitor to download an Outlook file which contains the worm as an attachment.

Also, the worm will create an open network share allowing access to the system. The worm will also attempt to spread via open network shares.

Type: Worm

Threat Assessment:

 
High Low High
Wild:
High
Damage:
Low
Distribution:
High

Wild:

Damage:

Distribution:


Write-up by: Eric Chien

Symantec AntiVirus Research Center (SARC)
http://www.symantec.com/avcenter