<Bài viết đã được chỉnh sửa lúc < Edited by: <b>viviy2k</b> -- <b>8/22/2003 1:16:23 AM </b> >>
New Virus Warning ( Sobig.f)
W32.Sobig.F@mm
Discovered on: August 18, 2003
Last Updated on: August 21, 2003 01:26:18 PM
Due to the number of submissions received from customers, Symantec Security Response has upgraded this threat to a Category 4 from a Category 3 threat as of August 21, 2003.
W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses it finds in the files that have the following extensions:
The worm uses its own SMTP engine to propagate and attempts to create a copy of itself on accessible network shares, but fails due to bugs in the code.
Email routine details
The email message has the following characteristics:
From: Spoofed address (which means that the sender in the " From" field is most likely not the real sender). The worm may also use the address admin@internet.com as the sender.
NOTES:
The spoofed addresses and the Send To addresses are both taken from the files found on the computer. Also, the worm may use the settings of the infected computer' s settings to check for an SMTP server to contact.
The choice of the internet.com domain appears to be arbitrary and does not have any connection to the actual domain or its parent company.
Subject:
Thank you!
Your details
Body:
See the attached file for details
Please see the attached file for details.
Attachment:
NOTES:
The worm de-activates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.
W32.Sobig.F@mm uses a technique known as " email spoofing," by which the worm randomly selects an address it finds on an infected computer. For more information on email spoofing, see the " Technical Details" section below
W32.Sobig.F@mm
Discovered on: August 18, 2003
Last Updated on: August 21, 2003 01:26:18 PM
Due to the number of submissions received from customers, Symantec Security Response has upgraded this threat to a Category 4 from a Category 3 threat as of August 21, 2003.
W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses it finds in the files that have the following extensions:
- .dbx
- .eml
- .hlp
- .htm
- .html
- .mht
- .wab
- .txt
The worm uses its own SMTP engine to propagate and attempts to create a copy of itself on accessible network shares, but fails due to bugs in the code.
Email routine details
The email message has the following characteristics:
From: Spoofed address (which means that the sender in the " From" field is most likely not the real sender). The worm may also use the address admin@internet.com as the sender.
NOTES:
The spoofed addresses and the Send To addresses are both taken from the files found on the computer. Also, the worm may use the settings of the infected computer' s settings to check for an SMTP server to contact.
The choice of the internet.com domain appears to be arbitrary and does not have any connection to the actual domain or its parent company.
Subject:
Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details
Body:
See the attached file for details
Please see the attached file for details.
Attachment:
your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif
NOTES:
The worm de-activates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.
W32.Sobig.F@mm uses a technique known as " email spoofing," by which the worm randomly selects an address it finds on an infected computer. For more information on email spoofing, see the " Technical Details" section below