RE: [Full-Disclosure] SoBig.F strange problem

From: Risser, Nathan (BLM) (nathan.risser_at_express-scripts.com)
Date: 08/19/03

  • Next message: Drew Copley: "RE: [Full-Disclosure] Anyone? Important Security Update for the .NET Messenger Service"
    To: <full-disclosure@lists.netsys.com>
    Date: Tue, 19 Aug 2003 15:41:56 -0500
    
    

    It would seem to me that someone who has your email address is infected
    with the worm.

    ---------------------------------
    From Symantec's W32.Sobig.F page:
    W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself
    to all the email addresses that it finds in the files with the following
    extensions:

    .dbx
    .eml
    .hlp
    .htm
    .html
    .mht
    .wab
    .txt

    The worm utilizes it's own SMTP engine to propagate and will attempt to
    create a copy of itself on accessible network shares.

    ---------------------------------------

    Nate

    -----Original Message-----
    From: Scott Phelps / Dreamwright Studios [mailto:scottp@dreamwright.com]

    Sent: Tuesday, August 19, 2003 2:01 PM
    To: full-disclosure@lists.netsys.com
    Subject: [Full-Disclosure] SoBig.F strange problem

    All day today I've been getting copies of SoBig.F. I've gotten around
    150 copies so far, and a large number of postmaster bounces saying that
    a copy sent from my address was undeliverable.

    I know that SoBig forges the from address from files it finds on the
    victims machine, but I can't for the life of me figure out why I'm the
    attempted victim for so many other copies. I'm not infected with the
    virus, I'm running antivirus that strips the attachment before it lands
    in my inbox, and I'm running a version of outlook that disallows the
    attachment extensions that SoBig uses. I've run manual scans on all of
    my machines, in case of infection through a network share, but I don't
    have any of those from outside either. All the emails seem to be coming
    from different places, but around 90% are using a from address of
    @msu.edu.

    Is there some logical explanation why I'm being singled out here? My
    antivirus is driving me insane with popups, so I've had to shut down my
    mail program to get some work done.

    I'm sorry for the off topic nature of this question, but this makes no
    sense to me!

    Scott

     

    ******* Confidentiality Notice *******
    This email, its electronic document attachments, and the contents of its website linkages may contain confidential health information. This information is intended solely for use by the individual or entity to whom it is addressed. If you have received this information in error, please notify the sender immediately and arrange for the prompt destruction of the material and any accompanying attachments.

    ******* Avis de confidentialite *******
    Ce courriel ainsi que tout document y etant joint de meme que le contenu des liens vers des sites Web peuvent reunir des renseignements confidentiels sur la sante. Cette information s'adresse uniquement a l'usager ou a l'organisation auxquels elle est destinee. Si vous avez recu ce message par erreur, veuillez en aviser l'expediteur immediatement et proceder a la suppression du document et des fichiers joints sans tarder.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Drew Copley: "RE: [Full-Disclosure] Anyone? Important Security Update for the .NET Messenger Service"

    Relevant Pages

    • [REVS] Curious Yellow: The First Coordinated Worm Design
      ... The Warhol worm design began the theoretical discussion of so-called ... very quick infection of the network. ... Warhol superworm is to pre-scan the network for vulnerable targets. ... The method for nominating a worm to attack a target is easy. ...
      (Securiteam)
    • CERT Advisory CA-2003-04 MS-SQL Server Worm
      ... code that most likely exploits two vulnerabilities in the Resolution ... traffic generated between hosts infected with the worm targeting SQL ... Activity of this worm is readily identifiable on a network by the ... protection whatsoever against the initial infection of systems. ...
      (Cert)
    • Re: NETBIOS Browsing (Long Reply)
      ... > Possibly attributed to the recent Bugbear worm also. ... > New worm, Opasoft, targets Windows systems ... > of the Network Basic Input/Output System, ... > machines on the network are particularly vulnerable to infection by ...
      (comp.security.firewalls)
    • Re: NETBIOS Browsing (Long Reply)
      ... >> Possibly attributed to the recent Bugbear worm also. ... >> New worm, Opasoft, targets Windows systems ... >> of the Network Basic Input/Output System, ... >> machines on the network are particularly vulnerable to infection by ...
      (comp.security.firewalls)
    • Re: My Doom Creators - incomprehensible
      ... your project is not a target; a worm has ... Usenet newsgroup using what appears to be a valid email address. ... e-mail for virus infection. ... the worm can harvest a lot of e-mail addresses to send itself to. ...
      (microsoft.public.security.virus)