Hello Dr. Martin,
I don't believe that rule would work at all unless the
message misspells "respresented" Hehe..

BTW, SCO is already report a DoS of their site due to
this worm and are offering a $250,000 reward for the
worm writers and it is not Feb. 1 yet!

I just finished an email that addressed the new worm
rules which basically stated that I used the existing
"VIRUS OUTBOUND .pif/.scr file attachment" rules to
find out who had it here, and it worked flawlessly.
Good luck.



The MyDoom/Novarg virus won't start utilizing port 80
until February 1st
when it attempts the denial of service on SCO.com. 
(See other related
email.)  But that does, however, pose an interesting

Does anyone have a signature for detected the actual
infection of

I have seen this one:
alert tcp any any -> any any (msg:"MyDoom"; content:
"respresented in
7-bit ASCII"; nocase; sid: 1000569; classtype:

BUT, according to NAI
(http://vil.nai.com/vil/content/v_100983.htm) and
.html) there are many variations on the infection
algorithm.  This one
apparently only looks for SMTP traffic with
"represented in 7-bit ASCII"
in the packet.


