Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Two level 3 virus/worms in two days [Netsky.B]
Symantec Security Response website ^ | 2/18/2004

Posted on 02/18/2004 11:18:16 AM PST by FourPeas

The email has the following characteristics:

From: (Spoofed)

Subject: (One of the following)

hi
hello
read it immediately
something for you
warning
information
stolen
fake
unknown

Message: (One of the following)

anything ok?
what does it mean?
ok
i'm waiting
read the details.
here is the document.
read it immediately!
my hero
[here
is that true?
is that your name?
is that your account?
i wait for a reply!
is that from you?
you are a bad writer
I have your password!
something about you!
kill the writer of this document!
i hope it is not true!
your name is wrong
i found this document about you
yes, really?
that is bad
here it is
see you
greetings
stuff about you?
something is going wrong!
information about you
about me
from the chatter
here, the serials
here, the introduction
here, the cheats
that's funny
do you?
reply
take it easy
why?
thats wrong
misc
you earn money
you feel the same
you try to steal
you are bad
something is going wrong
something is fool

Attachment Name: (One of the following)

document
msg
doc
talk
message
creditcard
details
attachment
me
stuff
posting
textfile
concert
information
note
bill
swimmingpool
product
topseller
ps
shower
aboutyou
nomoney
found
story
mails
website
friend
jokes
location
final
release
dinner
ranking
object
mail2
part2
disco
party
misc

Attachment Extension 1: (May include one of the following)

.txt
.rtf
.doc
.htm

Attachment Extension 2: (One of the following)

.exe
.scr
.com
.pif

(Excerpt) Read more at sarc.com ...


TOPICS: Business/Economy; Crime/Corruption; Culture/Society; News/Current Events
KEYWORDS: computer; tech; virus; worm
Gotta love it when they come in bunches.
1 posted on 02/18/2004 11:18:17 AM PST by FourPeas
[ Post Reply | Private Reply | View Replies]

To: FourPeas
Nope. Don't love it one bit.

Vote Death penalty for virus-creators!

I'm half-kidding... I think...

2 posted on 02/18/2004 11:19:59 AM PST by Teacher317
[ Post Reply | Private Reply | To 1 | View Replies]

To: FourPeas
We barely got our mail server blocked before these started pouring in.
3 posted on 02/18/2004 11:20:44 AM PST by eyespysomething (There is no threat. The Communists are not about to take over our McDonald hamburger stands. JFK '71)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Teacher317
Mr. FourPeas works in IT Security. A level three (or four) often means he won't be home tonight. It also means his "super-high priority" project that MUST be finished by this Friday is going to slip because he has to spend time distributing new virus definitions, so he probably won't be home tomorrow night or the night after that, either. Ugh.

Gotta love it when they come in bunches.

4 posted on 02/18/2004 11:24:01 AM PST by FourPeas
[ Post Reply | Private Reply | To 2 | View Replies]

To: eyespysomething
How do you block a mail server?

I use earthlink, btw.
5 posted on 02/18/2004 11:30:25 AM PST by EggsAckley ({...................troll patrol........on duty...................})
[ Post Reply | Private Reply | To 3 | View Replies]

To: FourPeas
At least one of them removes other viruses,
6 posted on 02/18/2004 11:32:45 AM PST by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: EggsAckley
This was at work and the network guy did it. Sorry I wasn't clear.

If you use an internet based email it usually does a good job of blocking the viruses. We don't use Outlook Express at home, we check all our email over the internet.

Of course there are drawbacks, such as file size causes attachments to sometimes be discarded as being too big or suspect, but I have a secondary account I can use if needed.
7 posted on 02/18/2004 11:33:52 AM PST by eyespysomething (There is no threat. The Communists are not about to take over our McDonald hamburger stands. JFK '71)
[ Post Reply | Private Reply | To 5 | View Replies]

To: eyespysomething
Earthlink has "spamblocker" which offers a list of suspected spam. Most of it IS spam and is easily deleted. On a rare occasion there is a legitimate email which I can safely retrieve.

I don't open ANY attachments anymore.
8 posted on 02/18/2004 11:41:32 AM PST by EggsAckley ({...................troll patrol........on duty...................})
[ Post Reply | Private Reply | To 7 | View Replies]

To: FourPeas
Gotta love it when they come in bunches.

Since I use qmail at home I've made up a lot of "dash extension" email addresses. So I have "lelio" for normal email, "lelio-dns" for DNS related issues, "lelio-qmail" for the qmail mailing list, etc.

What kills me is when I get 3 spams to all three addresses at the same time. Its obvious that they have a list of email addresses from mailing lists and just did an alphabetical sort on them.

I'm amazed that an "intellegent spammer" (is there one?) hasn't written up a program to narrow cast spam to people based on where they get the email address from. Granted a lot of spammers just buy the email address with no context and a lot of it is for penis extenders -- which I doubt there's a fan club site about.
9 posted on 02/18/2004 11:47:58 AM PST by lelio
[ Post Reply | Private Reply | To 1 | View Replies]

To: AppyPappy
I forgot about the Welchia version that made it to level three. Make that three level three virus/worms in the past two days.
10 posted on 02/18/2004 11:54:44 AM PST by FourPeas
[ Post Reply | Private Reply | To 6 | View Replies]

To: EggsAckley
I call and ask people if they meant to send me an attachment usually.

I was very happy with earthlink when I used to use it. We use our cable company now for cable DSL.
11 posted on 02/18/2004 11:56:04 AM PST by eyespysomething (There is no threat. The Communists are not about to take over our McDonald hamburger stands. JFK '71)
[ Post Reply | Private Reply | To 8 | View Replies]

To: AppyPappy
Ooops. My mistake. Welchia.B went level three on the 13th IIRC, not in the past two days.
12 posted on 02/18/2004 12:01:03 PM PST by FourPeas
[ Post Reply | Private Reply | To 6 | View Replies]

To: Teacher317
Vote Death penalty for virus-creators!

I'd be in favor of making them subject to civil liabilities. I can see them as defendants in a class action suit where the plaintiff is every one attacked by their worm or virus!

13 posted on 02/18/2004 12:08:13 PM PST by night reader
[ Post Reply | Private Reply | To 2 | View Replies]

To: FourPeas
Now at Level 4. It's going to be a long night.
14 posted on 02/18/2004 1:21:19 PM PST by FourPeas
[ Post Reply | Private Reply | To 1 | View Replies]

To: FourPeas
I just got whacked today.

Finally got around it for a NAV fix.

Hackers should euneched w/o anesthesia!

15 posted on 02/25/2004 1:38:46 PM PST by JimVT
[ Post Reply | Private Reply | To 1 | View Replies]

To: EggsAckley
I set up Outlook to take all incoming mail with attachments and put them into a separate folder.

Then, I can turn off the "preview pane" and check the properties of said email, and determine "friend/foe" without without even viewing them.
16 posted on 02/25/2004 1:43:21 PM PST by Johnny Gage (God Bless our Firefighters, our Police, our EMS responders, and most of all, our Veterans)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Johnny Gage
It's been said before, but also turn OFF any settings that

allow for Network Access when displaying complex HTML
17 posted on 02/25/2004 1:55:54 PM PST by bwteim (Begin With The End In Mind)
[ Post Reply | Private Reply | To 16 | View Replies]

To: JimVT
This is not hackers..
18 posted on 02/25/2004 2:00:03 PM PST by N3WBI3
[ Post Reply | Private Reply | To 15 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson