We are unable to deliver the message from [my e-mail address] to namimnlist@yahoogroups.com. Your message was not delivered because it was sent to an announcement-only group, where only the moderator may post. A copy of your original message is attached.The original worm was sent to a Yahoo Groups address that automatically bounces messages back to sender. My e-mail address had been pasted into the "From" box when it was sent to the "announcement-only group" . From the perspective of the Yahoo mailbox, it was a legitimate return-mail correspondence. The attachment - entitled "important.zip" - went through the entire process unscathed and arrived intact together with a W32.Netsky.Z@mm worm. This on W32.Netsky.Z@mm from Symantec:
To read the full Symantec security report click here.Uses its own SMTP engine to send itself to jamainlbbbsdef@yahoo.com, as well as all the email addresses that it finds. The email has the following characteristics Subject: (one of the following) Hello Hi Important Important bill! Important data! Important details! Important document! Important informations! Important notice! Important textfile! Important! Information From: (spoofed)
Attachment: (zip file with one of the following file names) Bill.zip Data.zip Details.zip Important.zip Informations.zip Notice.zip Part-2.zip Textfile.zip
No comments:
Post a Comment