Very interesting and useful article at the f-secure blog today.
Particularly the list of possible domains that the worm will attempt to use
in the next few days. This is useful to anyone who runs a web proxy as it
will allow you to compare the list to web traffic to determine if anyone
using the proxy is infected, or by anyone to create a preemptive block list
for the next three days...
See: http://www.f-secure.com/weblog/archives/00001579.html
The list of domains for 1/13/09 - 1/16/09 can be found here:
http://www.f-secure.com/weblog/archives/00001578.html


Reply With Quote