| Home Forum Radio Memberlist Help Search Quick Links |
| Forum Index » Internet » Security Alerts and vulnerabilities » Mass mailing Worm |
| Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here.. |
![]() |
![]() |
|
Thread Tools | Display Modes | ![]() |
|
#1
|
||||
|
||||
|
WORM_SOBER.I
As of November 19, 2004, 1:31 AM (GMT - 08:00), TrendLabs has declared a Yellow Alert to control the spread of this malware, which is spreading via email in Germany, France, and Austria. Users are advised to be wary of email messages containing the following message body: *-*-* Mail_Scanner: No Virus *-*-* SKYNET- Anti_Virus Service *-*-* http://www.skynet.be It sends similar content in German to email addresses in Germany, Austria, Liechtenstein, Switzerland, and other areas (it checks target addresses for country-level domains): *-*-* X-MS_Scanner: Kein Virus erkannt *-*-* Attachment-Scanner: NO VIRUS *-*-* Anti_Virus: Es wurde kein Virus gefunden For additional information on the email that this worm sends out, please refer to the Technical Details section. Users should note that the worm messages are spoofed and may appear to be sent by a familiar source. Network administors who would like to block email messages associated with this worm can check for more email details in the Technical Details section. This worm may cause some increase in network traffic. Distribution, however, may not necessarily be localized, and the worm may not severely affect corporate mail servers since it obtains email targets from files instead of the global address book. This worm arrives as an email attachment that executes and infects upon manual execution. A good visual clue to spot this worm is the fake WinZip message box that it displays: ![]() This message box is likely designed to tricked into thinking that the worm file is damaged and does not actually run. In contrast, this worm will have likely infected systems on which the message box has been displayed, especially machines with no antivirus protection. This worm runs on Windows 95, 98, ME, NT, 2000, and XP. |
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Zotob Suspects Arrested | Mobo | News & Announcements | 0 | 09-05-2005 09:30 PM |
| Mytob Worm | LJM Master | Security Alerts and vulnerabilities | 0 | 03-31-2005 01:04 PM |
| W32/VBSun-A worm | pmf45 | Security Alerts and vulnerabilities | 1 | 01-17-2005 11:54 AM |
| Cellery worm | Mobo | Security Alerts and vulnerabilities | 0 | 01-13-2005 07:42 AM |
| Santy.a Worm | Mobo | Security Alerts and vulnerabilities | 0 | 12-21-2004 12:07 PM |
|
|
||