W32.Nimda.A @mm Virus| Discovered on: September 18, 2001 |
| Last Updated on: September 18, 2001 at 10:12:26 AM PDT |
Symantec Security Response has received a number of submissions on W32.Nimda.A.@mm and is rating it as a Category 4.
W32.Nimda.A@mm is a new mass-mailing worm that utilizes email to propagate
itself. The threat arrives as a file named readme.exe in an email.
In addition, the worm sends out probes to Microsoft IIS servers attempting to
spread itself by using the Unicode Web Traversal exploit similar to
W32.BlueCode.Worm. Compromised servers may display a webpage prompting a visitor
to download an Outlook file which contains the worm as an attachment.
Also, the worm will create an open network share allowing access to the system.
The worm will also attempt to spread via open network shares.
Type: Worm
| Wild: High |
Damage: Low |
Distribution: High |

Write-up by: Eric Chien
Symantec AntiVirus Research
Center (SARC)
http://www.symantec.com/avcenter