Open Tech Support
Open Tech Support Archives
Back to HomeCommunityReviewsGuidesDownloadsTech LinksMarketplaceContact Us
 »  SITE NAVIGATION
»  OTS Home
»  OTS Forums
»  OTS Archives

»  About our site
»  Search our site
»  Support our site

»  What is this site?
»  Who are we?
 
 
 »  ADVERTISMENT
 
  Pages: 1

W32.SoBig.F@mm Worm Spreading Quickly

(Click here to view the original thread with full colors/images)


Posted by: TotalRecall

The "SoBig" worm, discovered on the 18th, has been propogating itself rapidly through email attachments. The worm arrives in emails with subject lines like "Your Details", "Re: Approved", "Re: Details", "Thank You!", "Re: That Movie", and "Re: Wicked Screensaver."

The sender and send to addresses are spoofed from addresses inside certain files on a computer, or the sender may be spoofed to "admin@internet.com." The worm also looks for a valid SMTP server to send itself.

The attachment can contain a variety of files with the extensions of .src or .pif files. Aside from trying to spread itself to every email address it can find on the system, the worm also leaves backdoor ports open and waits for other instructions. Sysmantec has more information and methods for removal.

In similar news, the "white hat" Welchia worm also caused some slowdowns in Air Canada's Check-In system today.



Posted by: Azgard

I get like 1 of these per 4 emails...peope really need to patch, and use their brains.



Posted by: Gunslinger

I'm getting about 20 of these per day.



 
Copyright 2000-2008 Open Tech Support.  All Rights Reserved.  Site Design and Development by Tolitz Rosel.