Warning of gestating worm
The company said the attachment was sufficiently different from other mass mailing worms in circulation -- such as the MyDoom variants -- for it to class the threat as new.
MessageLabs spokesperson, David Banes, said its scanning engine had filtered about 800 emails bound for its clients that carried a suspicious 12-kilobyte pay load.
While the company is yet to carry out a detailed analysis of the code, there are indications that its creators are seeding the email in preparation for a denial-of-service attack.
The attachment contains a mail engine, a list of domain names associated with Undernet.org and some parts of the code suggest it may be designed to communicate with a chat room.
MessageLabs was unable to say whether the email's activity was concentrated in any geographical region.
MessageLabs said the threat alarm policy of its scanning engine, Sceptic, was guided by a number of criteria, including detection frequency and the characteristics of the threat.