|
|
The Computer Guys Miami to Fort Lauderdale Since 1994 - Thank You!
|
|
|
|
|
We Build the Best & Repair the Rest! © |
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
Top 10 malware reported to Sophos in May 2005
W32/Sober-N is a mass-mailing worm which sends itself to addresses harvested from the infected computer.
The email sent by W32/Sober-N depends on the recipient address. Emails sent to recipients whose email address is in the .de, .ch, .at, .li domains or contains the string "gmx." will receive an email as follows:
Subject line: Ihr Passwort Message text:
Herzlichen Glueckwunsch, Passwort und Benutzer-Informationen befindensich in der beigefuegten Anlage. Diese E-Mail wurde automatisch erzeugt Mehr Information finden Sie unter <URL> Folgende Fehler sind aufgetreten: Fehler konnte nicht Explicit ermittelt werden End Transmission Aus Datenschutzrechtlichen Gruenden, muss die vollstaendige E-Mail incl. Daten gezippt & angehaengt werden. Wir bitten Sie, dieses zu beruecksichtigen. Nun sieh dir das mal an! --- FIFA-Pressekontakt: Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang. Mail-Scanner: Es wurde kein Virus festgestellt,AntiVirus: Kein Virus
gefunden,AntiVirus-
Attached file: Fifa_Info-Text.zip The attached filenames may contain an optional prefix of "error-" or an optional suffix of "-Text" followed by the ZIP extension. Example: our_secret-Text.zip Email sent to other addresses will have the following characteristics:
Subject line: mailing error
Message text: This is an automatically generated E-Mail Delivery Status Notification. Mail-Header, Mail-Body and Error Description are attached Account and Password Information are attached! Visit: <URL> *** AntiVirus: No Virus found Visit: <URL> Visit: <URL> *** Server-AntiVirus: No Virus (Clean) *** AntiVirus: No Virus found
Attached file: mail_info.zip The attached filenames may contain an optional prefix "error-" or an optional suffix "-text" followed by the ZIP file extension. The ZIP file will contain an executable file named Winzipped-Text_Data.txt<spaces>.pif The From address line will be faked.
W32/Sober-N attempts to disable anti-virus products. When it does so, the worm may display a message box containing the following text: No Viruses, Trojans or Spyware found!
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
|
|
Copyright © 1998 The Computer Guys |
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||