Security Incidents mailing list archives

Re: Romeo&Juliet (fwd)


From: Antonio Carlos Pina <apina () INFOLINK COM BR>
Date: Fri, 17 Nov 2000 17:28:37 -0200

Hello,

Be careful. this e-mail is supposed to be able to infect Outlook Express
only by READING it (you don't even need to run the attachment).

Look at: http://www.datafellows.com/v-descs/blebla.htm

Best regards,


----- Original Message -----
From: "Micha³ 'CeFeK' Nazarewicz" <Michal.Nazarewicz () SAYDK CO UK>
To: <INCIDENTS () SECURITYFOCUS COM>
Sent: Thursday, November 16, 2000 8:57 PM
Subject: Romeo&Juliet (fwd)


Hi List,
I've just received strange e-mail from the person living in my
country, but one i've never written to. It looks very, very suspicious:
message body looks corrupted (pine says it's encoded in qp, but contains
non-hexadecimal characters). There are two attachments: one is of
APPLICATION/X-MSWORD type, but it's extension is .EXE. The second one is
of .CHM extension, I haven't looked at it yet.
The subject of this e-mail os Romeo&Juliet... so this looks like
just one another funny e-mail from someone you should know.
If anyone is interested, I can email him these attachments. I'm
very curious, what's this.

Regards,
--
Michal 'CeFeK' Nazarewicz   / CAOL, DK GROUP SYSADMIN ^ NETADMIN         B
ICQ 47171266 / +48 (601) CEFEK 0 / http://www.dkgroup.pl/index.html      O
mailto:cefek at saydk dot co dot uk / MN4735-RIPE / Pengiun #164007      F
Linux kanton 2.4.0-test7 #9 sob wrz 2 12:46:51 CEST 2000 i686 slackware7 H




Current thread: