Security Basics mailing list archives

Re: Annoying virus being mailed to me


From: Su Wadlow <swadlow () utdallas edu>
Date: Fri, 07 Feb 2003 13:20:54 -0600

--On Friday, February 07, 2003 10:54 AM +0100 Chris Carter <chris.carter () ebunda com> wrote:

For the last two months or so I have been receiving emails with the
I-Worm/Sobig virus attached about twice a day. My anti-virus sw
protects me well so I am not infected in any way (nor has anybody
else here). Initially, I used to ignore the messages and delete them;
after a couple of weeks I decided to trace the source IP from the
mail header and send complaint messages to the corresponding ISP. But
the Bast**d keeps finding other IP's to mail me from. Messages come
from big () boss com. Is anyone else being targeted? Is this a common
occurrence? Am I the only one?

It's probable that someone with whom you've corresponded or who's
visited a web page with your email address on it is infected and
doesn't know it.  From NAI's Virus Library:

<quote>
Email addresses may be harvested from files on the victim machine
with the following extensions:

WAB
DBX
HTM
HTML
EML
TXT
</quote>

http://vil.nai.com/vil/content/v_99950.htm

big () boss com is, like, something that's just made up and hardcoded
into the worm's code.

It's doubtful that you're being targeted, someone's machine is just
infected.

--
Su Wadlow
swadlow () utdallas edu
Faculty/Staff Support


Current thread: