Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Has anyone else noticed a massive surge in email viruses today?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
EarlG ADMIN Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 01:53 PM
Original message
Has anyone else noticed a massive surge in email viruses today?
At DU we normally receive a bunch of those emailed viruses every day (the amount of spam we get has to be seen to be believed). The virus I'm talking about is the one that generates messages titled things like "Re: Approved" "Re: Details" "Re: Wicked Screensaver" "Re: your Application" etc.

These emails all come with attachments which carry the virus payload. Obviously I've seen these all many times before, but today we've received several hundred, all from different email addresses.

Has anyone else noticed a large surge in these email viruses today?

EG
Printer Friendly | Permalink |  | Top
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 01:54 PM
Response to Original message
1. No, but I read a few related news
Sobig is around again.
Printer Friendly | Permalink |  | Top
 
petersjo Donating Member (192 posts) Send PM | Profile | Ignore Tue Aug-19-03 01:59 PM
Response to Reply #1
7. Yes
Many, many more than usual. Yahoo does a good job of sending them to bulk mail, so just have to dump them.
Printer Friendly | Permalink |  | Top
 
Bossy Monkey Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:07 PM
Response to Reply #1
11. What Kellanved said
Printer Friendly | Permalink |  | Top
 
rabid_nerd Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 01:55 PM
Response to Original message
2. It was discovered today...
And I've been getting many, as has all of draft gore and where I work as well...

W32/SoBig.f@MM

This virus stuffs the inboxes of any email it can get it's hands on.

About the virus:
http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html

Free virus scans:
http://security.symantec.com/default.asp?productid=symhome&langid=ie&venid=sym
http://housecall.antivirus.com/

Printer Friendly | Permalink |  | Top
 
Abe Linkman Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 01:58 PM
Response to Original message
3. I got the "Wicked Screensaver" one today. n/t
n/t
Printer Friendly | Permalink |  | Top
 
TioDiego Donating Member (409 posts) Send PM | Profile | Ignore Tue Aug-19-03 01:58 PM
Response to Original message
4. Yes,
It is funny you should mention that. I just came back from investigating a user's notes with that very problem. He got spammed by 3 different groups with emails containing the same viruses you mentioned. These were from people he has never received mail from All were caught at the firewall. The Nazi Bastridges!
Printer Friendly | Permalink |  | Top
 
proud patriot Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 01:58 PM
Response to Original message
5. Yes !
I'm having a bunch of mail with attatchments coming
to my home email box ,,,I've just been deleting them .
I called my dad and he will come over and
check it out later today.

:-(

Printer Friendly | Permalink |  | Top
 
Rabrrrrrr Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 01:59 PM
Response to Original message
6. Yes, I'm getting POUNDED today on one work email account
Edited on Tue Aug-19-03 02:00 PM by Rabrrrrrr
Can't wait to find out what I'm getting at home...

:scared:
Printer Friendly | Permalink |  | Top
 
demnan Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:00 PM
Response to Original message
8. Yes
I was getting them at the rate of one per minute this morning, but after the daily patch for viruses was downloaded automatically, they stopped.

I imagine my Systems Admin is having quite a day with the email server over this.
Printer Friendly | Permalink |  | Top
 
Chuckup Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:00 PM
Response to Original message
9. Got a ton here
Printer Friendly | Permalink |  | Top
 
EarlG ADMIN Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:05 PM
Response to Original message
10. Hmm... okay
That makes me feel a little better - sorry everyone else is having a hard time though.

I just deleted 300 of the little buggers from our mail server.
Printer Friendly | Permalink |  | Top
 
Ivory_Tower Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:11 PM
Response to Reply #10
14. The assorted virus checkers have updated their files
so you might want to do an update on yours (I'm using McAfee -- DAT file 4287 is out now).

NASA/Goddard apparently got hit hard today by this, and I've had well over 100 messages on my work account alone today (so far).

Looks like this virus spoofs the sender/reply-to fields, so that won't necessarily tell where the email originated.

btw, I heard there's another worm out today, that acts like a "good worm" -- it scans for machines that haven't protected themselves from last week's MSBlaster worm, installs itself, removes MSBlaster if found, and then does a windows update. Weird. Of course, it's still eating processor time and internet bandwidth, so it's not THAT benign.
Printer Friendly | Permalink |  | Top
 
AnnabelLee Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:08 PM
Response to Original message
12. Haven't gotten any myself
But thanks for the headsup, & thanks for all of the info from those who have replied.
Printer Friendly | Permalink |  | Top
 
MoonGod Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:08 PM
Response to Original message
13. New Internet Worm Tries to Patch Hole Exploited By 'Blaster'
http://news.yahoo.com/fc?tmpl=fc&cid=34&in=tech&cat=computer_viruses_and_worms

A new computer worm is spreading worldwide through a security hole in Windows -- also used by last week's Blaster worm -- but then patching the hole instead of crashing the system like Blaster does, security experts said on Monday. The new worm, dubbed "Welchia" or "Nachi," is similar to Blaster, but it purports to patch the hole Blaster exploited to enter into computers in the first place and tries to clean up after Blaster if the computer is infected with it...
Printer Friendly | Permalink |  | Top
 
MiddleRiverRefugee Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:12 PM
Response to Original message
15. Yeah. Lots.
I monitor a group E-mail box at work. Been cleaning out SPAM all day.
Probably 250-300 messages thus far.
Printer Friendly | Permalink |  | Top
 
KC Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:12 PM
Response to Original message
16. On the Thom Hartmann
show today, he just mentioned he'd been getting a ton of them too

KC
Printer Friendly | Permalink |  | Top
 
greenwow Donating Member (729 posts) Send PM | Profile | Ignore Tue Aug-19-03 02:12 PM
Response to Original message
17. No more than usual...
but it's still bad.

This leads to the question why so many idiots use Microsoft products and contribute to the problem. As long as idiots continue to use programs, like Outlook that was never designed to be secure or to not allow the execution attachments, we'll continue to have problems.
Printer Friendly | Permalink |  | Top
 
FlaGranny Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:34 PM
Response to Reply #17
29. The only e-mail worms
Edited on Tue Aug-19-03 02:35 PM by FlaGranny
that I've had a problem with came through my company's server. They were infected several times with different viruses. My McAfee caught them all and I've never had an "infection." My personal ISP's mail server has never allowed an infected e-mail through, and very, very little spam. To be safe I don't open any e-mails from anyone I don't know, and never open an attachment unless I'm expecting it. I'm on automatic updates with McAfee and MS.

Thank you for calling me an idiot, though, as I am an XP (and Outlook Express) user.

Edit to add words in parentheses.
Printer Friendly | Permalink |  | Top
 
Old and In the Way Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:35 PM
Response to Reply #17
30. Really?
Edited on Tue Aug-19-03 02:37 PM by Old and In the Way
Let me guess, you're one of the "smart" Mac users, right?

I am a Microsoft user and I haven't received any virus e-mail's today. And my business is worldwide. Could it be because:

(1) I use Spamfighter (a free Outlook utility) that leverages its entire user community of Outlook users to determine a spam e-mail and delete it before it enters my computer?

(2) My Norton AV is up-to-date and screens my incoming e-mail?

(3) That my Zone Alarm is protecting me from attacks through my com ports?

(4) That my XP Pro operating system is up-to-date with the latest patches, as is my XP Office suite?

(5) Or a combination of all 4?

Whatever it is, I think your insults about us "idiots" using what I find to be an outstanding and rock solid e-mail platform is way too over-the-top to let it pass.

I think most problems people have are because they aren't informed and don't use the tools that are available to protect themselves.
Printer Friendly | Permalink |  | Top
 
greenwow Donating Member (729 posts) Send PM | Profile | Ignore Tue Aug-19-03 03:19 PM
Response to Reply #30
34. Why waste all that money?
And why are you wasting that huge amount of money on all of those things? It's because Microsoft refuses to produce products that or secure or they're so technically inept that they simply can't.

How about getting smart and using a single better product rather than wasting hundreds of dollars on something that might or might not protect you. Given Microsoft's history (like the old MSIE backdoor that would execute attachments when just previewing a message!), you'll eventually get burnt.
Printer Friendly | Permalink |  | Top
 
Old and In the Way Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 03:29 PM
Response to Reply #34
35. Waste money?
Outlook comes with Office....so I don't need a separate unintegrated e-mail client.

Spamfight - free
Zone Alarm - free

I do pay $35.00/year to keep my A/V updated. I could use a free program, but Norton's works well and I write it off.

Again, why do you make statements that simply aren't true? Why is that? I told you that I have no virus issues and I am totally happy with the product suites that I use. Does it piss you off that there are people who will disagree with your uninformative critiques about software?

Printer Friendly | Permalink |  | Top
 
L.A.dweller Donating Member (477 posts) Send PM | Profile | Ignore Tue Aug-19-03 03:32 PM
Response to Reply #17
36. My laptop has Microsoft XP and I use Outlook Express
yet, I have not recieved any viruses as of yet. Outlook Express gets rid of attatchments from e-mail that I dont have on my address list auomatically. Not contributing to any problems here.
Printer Friendly | Permalink |  | Top
 
soleft Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:12 PM
Response to Original message
18. Yes - and I never get them
What I've been getting are messages from postmasters saying emails I sent are undeliverable, but I didn't send the emails. What's interesting is in the message seems to be email info on someone I know who may have me in her address book.
Printer Friendly | Permalink |  | Top
 
ima_sinnic Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:34 PM
Response to Reply #18
28. yes, I've received 2 of those today
"undeliverable" returned messages that I never sent out, to addresses I never heard of. Here is a link to some information on W32/Sobig.f@MM :

http://vil.nai.com/vil/content/v_100561.htm

The web meister at my university department e-mailed me:
A new email virus variant is going around like wildfire. Your address is being spoofed by an infected machine because that machine has the string (my e-mail addy) somewhere on its hard drive. They were not from you, naturally. Check to see that your virus definition files are up-to-date . . .
Printer Friendly | Permalink |  | Top
 
salin Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:13 PM
Response to Original message
19. Yes - I had never received a single one of these til last night
my firewall detects it and "quarantines" it (not quite sure what that does) - but it still gets to my inbox. All I can think to do is click it (highlight not open) and delete immediately and empty my deleted messaged immediately.

I have received four in the past 12 hours.
Printer Friendly | Permalink |  | Top
 
nothingshocksmeanymore Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:14 PM
Response to Original message
20. Yep I am getting them in all my mail boxes
Printer Friendly | Permalink |  | Top
 
arcane1 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:15 PM
Response to Original message
21. I'm clean, but many of my users are being hammered today
lucky me
Printer Friendly | Permalink |  | Top
 
sybylla Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:18 PM
Response to Original message
22. Wow, I just started a thread on this myself.
Edited on Tue Aug-19-03 02:24 PM by sybylla
I guess this answers my biggest question so you can delete or lock my post. Sorry for the dupe, EarlG.

I have so far received 25 since 8 am this morning and all the ones you mentioned are included.

I'm only getting them on my local dem address so I suspected it was a local thing. I guess it isn't.


On edit: Anyone know if this is happening in freeperland or is this just targeting dems? I ask this because it isn't happening on the other five e-mail addresses I monitor.
Printer Friendly | Permalink |  | Top
 
maggrwaggr Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:20 PM
Response to Original message
23. I'm getting a ton. MACS are unaffected tho, right?
one reason I love having a mac. But I'd love for someone to confirm this, since I do actually use Outlook Express for mac
Printer Friendly | Permalink |  | Top
 
SpiralHawk Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:23 PM
Response to Original message
24. I am onstream with the onslaught
comin in fast and furious out here in the high desert of the southwest.

My hunch is THAT a massive attack is underway -- and that it may take some doing to thwart it.

A couple of months ago I saw a NOVA special on PBS that told the story of the Cyber War that has been raging for several years.

There are thousands of probes and attacks on the various parts of the net every day. Someone may gave gotten lucky today, or may have gotten very good after a long series of tests and probes.

Come on you Net Geniuses. To your keyboards and mouses. Tame this ugly e-mail storm before we all choke under a MASSIVE WAVE OF SPAM...
Printer Friendly | Permalink |  | Top
 
hackwriter Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:25 PM
Response to Original message
25. It's the "sobig.e" worm
Edited on Tue Aug-19-03 02:30 PM by hackwriter
This is a new variation of the "sobig" worm called "sobig.f". I have gotten about 30 of these in my Yahoo! mailbox today.

You're probably getting this if you have an e-mail address somewhere on the Web, such as on your Web site or even in a profile on a messageboard.

This from Symantec about Sobig.e. The new one is similar, but expires September 10:

W32.Sobig.E@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses that it finds in the files with the following extensions:

.wab
.dbx
.htm
.html
.eml
.txt

The email falsely purports that Yahoo sent it (support@yahoo.com).

Email Routine Details
The email message has the following characteristics:

From: support@yahoo.com (NOTE: W32.Sobig.E@mm spoofs this field. It could be any address.)

Subject: The subject line will be one of the following:
Re: Application
Re: Movie
Re: Movies
Re: Submitted
Re: ScRe:ensaver
Re: Documents
Re: Re: Application ref 003644
Re: Re: Document
Your application
Application.pif
Applications.pif
movie.pif
Screensaver.scr
submited.pif
new document.pif
Re: document.pif
004448554.pif
Referer.pif


Attachment: The attachment name will be one of the following:
Your_details.zip (contains Details.pif)
Application.zip (contains Application.pif)
Document.zip (contains Document.pif)
Screensaver.zip (contains Sky.world.scr)
Movie.zip (contains Movie.pif)

For more, see:

http://www.msnbc.com/news/954470.asp?0cv=CB20

Printer Friendly | Permalink |  | Top
 
sybylla Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:32 PM
Response to Reply #25
27. None of the attachments on my e-mails are zipped either
Edited on Tue Aug-19-03 02:34 PM by sybylla
And it is coming in on an e-mail address that is only posted on one website - the state dem party website. Yet I have several other e-mail addresses which appear on another website which aren't being hit at all.

Is this somehow being directed at dems or are the freepers trying to deal with it too?

edit: grammar - and to say that I'm really not a tinfoil hat kind of person. Just seems a little sketchy from my perspective.
Printer Friendly | Permalink |  | Top
 
ima_sinnic Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:42 PM
Response to Reply #25
31. here is more info on W32/Sobig.f@MM
http://vil.nai.com/vil/content/v_100561.htm

Discovery Date: 8/19/2003

Subject:

Your details
Thank you!
Re: Thank you!
Re: Details
Re: Re: My details
Re: Approved
Re: Your application
Re: Wicked screensaver
Re: That movie

Attachment:

your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif

The "From:" address may be spoofed with an address extracted from the victim machine. Therefore the perceived sender is most likely not a pointer to the infected user.

Symptoms:

Existence of the WINPPR32.EXE file in %WinDir%
Existence of the Registry hooks detailed above
Unexpected NTP traffic to remote servers

more info at the link above, including removal instructions (caution: techies only! over my head!)
Printer Friendly | Permalink |  | Top
 
Not a robought Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:30 PM
Response to Original message
26. I am starting to get a bunch of emails from people today
in other countries who I don't know from an email address I only use as a forwarder. My main address is private.

One of the emails was from someone warning me that an email attachment movie0045.pif from that email address forwarder contained a virus. I don't use it or the server it's associated to for sending email so I assume the server has been attacked.
Printer Friendly | Permalink |  | Top
 
Ivory_Tower Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:52 PM
Response to Reply #26
32. Since the "from" field is spoofed, it looks like it came from you
even though it didn't. The recipient server rejected the email (deciding it may contain a virus) and sent a message to the spoofed "sender", i.e., you. That's why you're getting that notice. Your server wasn't necessarily attacked, but someone was who had your email address in a file somewhere (address book, html file, whatever).

I've had about a half-dozen of those notices sent to me today.
Printer Friendly | Permalink |  | Top
 
slackmaster Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 02:53 PM
Response to Original message
33. IS SHE READY FOR A MASSIVE PENIS???
Yup.
Printer Friendly | Permalink |  | Top
 
TreasonousBastard Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 03:56 PM
Response to Original message
37. Just one.
"Document02.pif " And I couldn't trace it through the headers like I normally do.

Curiously, AVG didn't catch it, but I hear the damn thing is new today, so the next update should get it. Too late for some, I would assume.

Scary, and I don't relish opening all attachments in a hex editor just to make sure.


Printer Friendly | Permalink |  | Top
 
SOteric Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 04:01 PM
Response to Original message
38. I had one come in today
which isn't really a massive surge by anyone's definition. But then I received only a humble 25 pieces of mail. Symantec quickly dispatched it to the rubbish bin. No harm, no foul.
Printer Friendly | Permalink |  | Top
 
Booberdawg Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 04:15 PM
Response to Original message
39. None here
Office/Outlook/Norton/BlackIce
Printer Friendly | Permalink |  | Top
 
BritishHuman Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 04:53 PM
Response to Original message
40. I take the most effective security precaution there is:
I don't use Outlook for mail.
Printer Friendly | Permalink |  | Top
 
Patriot_Spear Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 05:33 PM
Response to Original message
41. Yes.
Our IT people here at work are on top of it; the Email they sent out says it's a version of the SoBig virus.

At home I updated all my antivirus software and made sure the firewall was active.
Printer Friendly | Permalink |  | Top
 
goobergunch Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-19-03 05:54 PM
Response to Original message
42. No, but I don't get much e-mail anyway (n/t)
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed May 01st 2024, 11:10 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC