Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Mitchell
Good, you're still as sharp as ever, now...

September 18, 2003

Kaspersky Labs, a leading information security expert, announces the detection of the network worm, I-Worm.Swen. This malicious program spreads via email, the Kazaa file sharing network and IRC channels.

The worm, which goes by a variety of names, including Swen, W32/Swen@MM, Gibe, and W32/Gibe-F, can pose as an e-mail from Microsoft bearing a bogus security update as a file attachment.

October 9, 2003

Two additional variants of this worm have been received by AVERT, created by minor edits of certain strings within the initial worm, and subsequent packing with UPX. Both are already detected as virus or variant W32/Swen@MM with the 4294 DATs or greater. Exact identification of the first (as W32/Swen@MM ) was included in the 4297 DATs. Exact identification of the latter will be included in 4298 DATs. Both of these variants are of filesize 52,224 bytes.

When first launched, the worm accesses the following remote website:

http://ww2.fce.vutbr.cz/bin/counter.gif/link=bacillus&width=6&set=cnt006

37 posted on 12/20/2003 1:27:38 AM PST by Van der Waals
[ Post Reply | Private Reply | To 33 | View Replies ]


To: Shermy
Ping.
38 posted on 12/20/2003 1:33:30 AM PST by Van der Waals
[ Post Reply | Private Reply | To 37 | View Replies ]

To: Van der Waals; Allan; Shermy
Cute. Needless to say, this isn't the same situation as with Nimda, because when Swen was released in 2003, the significance of the dates Sept. 18 and Oct. 9 was public knowledge (as was the theory that Nimda might have been related in some way to the anthrax mailings). Anybody could have intentionally released a virus on those anniversary dates in 2003 to make the virus appear to have something to do with the anthrax mailings. (In contrast, at the time of Nimda's release, nobody knew the significance of those dates except for the people involved with the anthrax mailings.)

By the way, I don't think the "bacillus" keyword for the counter means much here. Perhaps you look at the word "Bacillus" and imagine "anthracis" after it, but I think it would be quite natural for computer virus writers to pick words with biological connotations, like "bacillus", for use in their code.

Also note that the worm called Swen is apparently the latest incarnation of the earlier Gibe worm, so 9/18/2003 and 10/9/2003 are just the latest two dates in a longer series of release dates.

So, here are three possibilities regarding Swen:

My guess is that it's just a coincidence - Possibility 1.
40 posted on 12/20/2003 9:50:27 PM PST by Mitchell
[ Post Reply | Private Reply | To 37 | View Replies ]

To: Van der Waals
I tend to agree, nevertheless the "link=bacillus" - not just "bacillus" is, as you say, cute.

BTW, have you by chance taken a look at the "hoax" chemical letters released in Europe some months ago?

41 posted on 12/21/2003 8:43:08 AM PST by Van der Waals
[ Post Reply | Private Reply | To 37 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson