[Asrg] 0. General - Virus Alert

Yakov Shafranovich <research@solidmatrix.com> Thu, 21 August 2003 16:10 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA12117 for <asrg-archive@odin.ietf.org>; Thu, 21 Aug 2003 12:10:11 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19ps0Q-0006Ir-WB for asrg-archive@odin.ietf.org; Thu, 21 Aug 2003 12:09:47 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id h7LG9kS9024223 for asrg-archive@odin.ietf.org; Thu, 21 Aug 2003 12:09:46 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19ps0Q-0006Ic-RW for asrg-web-archive@optimus.ietf.org; Thu, 21 Aug 2003 12:09:46 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA12069; Thu, 21 Aug 2003 12:09:40 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19ps0P-00058N-00; Thu, 21 Aug 2003 12:09:45 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19ps0O-00058K-00; Thu, 21 Aug 2003 12:09:44 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19przh-00064b-3y; Thu, 21 Aug 2003 12:09:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19pryn-0005zH-KL for asrg@optimus.ietf.org; Thu, 21 Aug 2003 12:08:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA11898 for <asrg@ietf.org>; Thu, 21 Aug 2003 12:07:59 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19prym-00055I-00 for asrg@ietf.org; Thu, 21 Aug 2003 12:08:04 -0400
Received: from [68.27.246.68] (helo=68.27.246.68 ident=trilluser) by ietf-mx with smtp (Exim 4.12) id 19pryh-00054p-00 for asrg@ietf.org; Thu, 21 Aug 2003 12:08:03 -0400
Message-Id: <6.0.0.14.0.20030821120738.026ce568@solidmatrix.com>
X-Sender: research@solidmatrix.com
X-Mailer: QUALCOMM Windows Eudora Version 6.0.0.14 (Beta)
To: asrg@ietf.org
From: Yakov Shafranovich <research@solidmatrix.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-MimeHeaders-Plugin-Info: v2.03.00
Subject: [Asrg] 0. General - Virus Alert
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/mail-archive/working-groups/asrg/>
Date: Thu, 21 Aug 2003 12:07:39 -0400

Dear Group Members,

A new virus called SOBIG.F has been spreading by email over the last few 
days. Some group members reported receiving the virus at the email 
addresses used only for ASRG activity, so it seems that some of the list 
members have been infected. PLEASE SCAN YOUR COMPUTER AS SOON AS POSSIBLE, 
WITH THE LATEST VERSION OF AN ANTI-VIRUS.

The following information has been taken from the Internet Storm Center's 
website (http://isc.sans.org/diary.html?date=2003-08-20):

---------snip-------
Sobig F

Despite the best efforts of system admins world wide, users are still 
clicking on e-mail attachments. We strongly recommend attachment stripping 
on mail gateways. Please note, that the 'From' address is spoofed. Do not 
send auto replies to senders, as this will just worsen the email flood 
caused by Sobig F. As other Sobig variants, this one includes the ability 
to update the worm remotely, backdoors and a full set of other evilness.
---------snip------- 


_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg