There's a new variant of SDBOT making the rounds, arriving via IM as a link to a file called parishilton.scr . Those few AV that already detect it, seem to call it Sdbot.XD. Maybe a good moment to check your proxy logs to see who of your IM users clicked on it... SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System - Current Infosec News and Analysis

Linked by shanmuga Friday, 21st October 2005 1:31PM