autox
[Top] [All Lists]

Looks legit -- it ain't

To: ".W2W" <wheeltowheel@wheeltowheel.com>,
Subject: Looks legit -- it ain't
From: "Rocky Entriken" <rocky@tri.net>
Date: Sun, 21 Sep 2003 20:32:58 -0500
Yeah, another virus. Brand new as of last Thursday. At least it's not like
SoBig and flooding the mailboxes. I've received it twice already -- one
addressed to "Microsoft client," the other to "Microsoft consumer," but
otherwise identical.

But insidious -- it looks like a legitimate Microsoft e-mail including all
the right Microsoft logos, language, graphic style, and links. It offers
"the latest version of security update, the 'September 2003, Cumulative
Patch'." It purports to fix "all known security vulnerabilities affecting MS
Internet Explorer, MS Outlook and MS Outlook Express."

But it's bogus.

The attachment is a virus called W32.Swen.A@mm. More info at
http://www.symantec.com/avcenter/venc/data/w32.swen.a@mm.html

I put up a filter for the apparent sender address -- 205.153.246.174.

--Rocky Entriken





<Prev in Thread] Current Thread [Next in Thread>
  • Looks legit -- it ain't, Rocky Entriken <=