Advertisement
Promo

Security threats Toolkit

New Zafi variant goes for Google

Munir Kotadia ZDNet Australia

Published: 28 Oct 2004 12:04 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The latest variant of the Zafi worm was discovered on Wednesday and unlike the previous two variants, Zafi.C has been coded to launch a distributed denial-of-service (DDoS) attack against Google.com, Microsoft.com and miniszterelnok.hu, which is the Web site of the Hungarian Prime Minister.

The Zafi worm has evolved since it was first discovered in April of this year. Zafi.A contained Hungarian text and only tried to send itself to email addresses inside Hungary. Also, it did not contain a destructive payload. Two months later Zafi.B was released and this time the worm was able to terminate antivirus and firewall applications and 'speak' in numerous languages, including English, Spanish, Russian and Swedish.

Mikko Hyppönen, director of antivirus Research at F-Secure, said that if Zafi.C is worse than Zafi.B there could be trouble because the second variant has been in the company's top 20 virus list since it was released.

"Zafi.C might be bigger news as the previous variant of this Hungarian virus, Zafi.B, has been in our Top 20 for the past four months. However, so far we've received few reports of this virus."

Once active, Zafi.C scans the infected computer's Windows Address Book and hard drive for email addresses. It spreads by composing emails using a "complex set of rules" and sending them out with its built-in SMTP engine.

Paul Ducklin, head of technology at Sophos, Asia Pacific, told ZDNet UK sister site ZDNet Australia that the new variants are yet to have any affect on Australian users.

"The good news for Australia is that we haven't had any reports of any infections, so these viruses rate at the bottom of the prevalence scale. It's important to remember that around 1000 new viruses turn up every month -- approximately one every 45 minutes," said Ducklin.

Wednesday was a busy day for antivirus companies because apart from dealing with the new Zafi worm they also found a new version of MyDoom and another variant of the Agobot worm, which uses an Internet Relay Chat (IRC) server to give hackers remote access to infected systems.

Ducklin said the latest Agobot is the 359th variant.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
110 out of 200 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters