Alert: Worm posing as IE cumulative patch

From: Russ (Russ.Cooper@RC.ON.CA)
Date: 03/06/02


Date:         Wed, 6 Mar 2002 13:08:44 -0500
From: Russ <Russ.Cooper@RC.ON.CA>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Lots of people have emailed me about the email making the rounds which
states its from "Microsoft Corporation Security Center" and has a
subject line of "Internet Security Update".

The email has an attachment which the message claims to be the "1 Mar
2002 Cumulative Patch" for IE.

In case you don't already know, there isn't such a patch and its not
from Microsoft. Microsoft never emails out patches.

The bogus email is actually the GIBE worm, a description for which can
be seen at;

http://www.f-secure.com/v-descs/gibe.shtml
http://www.sarc.com/avcenter/venc/data/w32.gibe@mm.html
http://vil.nai.com/vil/content/v_99377.htm
http://www.antivirus.com/cgi-bin/vinfo.pl?OneVirus=WORM_GIBE.DR

Just to provide a few references (check the home page of your anti-virus
vendor for details)

Cheers,
Russ - NTBugtraq Editor



Relevant Pages

  • hoax - Newest Internet Security Update
    ... Subject: Newest Internet Security Update ... Microsoft ... eliminates all known security vulnerabilities affecting ...
    (microsoft.public.security.virus)
  • IE fail after MSblast remove
    ... Microsoft Corporation Security Section ... >My WinXP was infected by Blaster worm. ... >instruction from PC Cillin to clean up the worm and ...
    (microsoft.public.security.virus)
  • Re: Weird E-mails FROM Microsoft
    ... Microsoft Corporation Security Division ... Fortunately I have the latest updates and outlook blocked ... since yesterday I have been getting about 5 emails ...
    (microsoft.public.security.virus)
  • Re: Virus or Patch
    ... > I just received a cumulative patch supposedly ... I thought this was odd and sure enough, ... > this a Microsoft patch or the real deal virus? ...
    (microsoft.public.security.virus)
  • Valid MS Mailing or Not?
    ... Microsoft Corporate Network Security Division? ... >SUBJECT: Newest Internet Security Update ...
    (microsoft.public.security)