現在地 HOME > 掲示板 > IT1 > 790.html ★阿修羅♪ |
|
ソービッグウイルスを抱えた悪質添付メールは
下記のような特徴があります。
●メールの「件名」欄に次のような題名が記されている。
Re: Application
Re: Movie
Re: Movies
Re: Submitted
Re: ScRe:ensaver
Re: Documents
Re: Re: Application ref 003644
Re: Re: Document
Your application
Application.pif
Applications.pif
movie.pif
Screensaver.scr
submited.pif
new document.pif
Re: document.pif
004448554.pif
Referer.pif
●メールに次のような添付ファイルが付いている
Your_details.zip (contains Details.pif)
Application.zip (contains Application.pif)
Document.zip (contains Document.pif)
Screensaver.zip (contains Sky.world.scr)
Movie.zip (contains Movie.pif)
このような特徴の、ぁゃιぃメールが送られてきたら、メールを開封しないで
ただちに削除したほうがいいということです。
なお、上記の記述は、下記の警告を参考にしました。
-----------------------------------------------------------
Bonjour ? tous,
Certains membres de ce group-list ont leur PC infect? par le virus W32.sobig,
c'est pour cette raison que vous recevez des messages faussement envoy?s du
type " your details ", " Your application " et de plus l'exp?diteur de ce
message est usurp?...
Je vous recommande fortement d'utiliser l'utilitaire Anti-virus de Symantec
et de v?rifier votre ordinateur et disponible ? :
http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.e@mm.html">http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.e@mm.html
<< The email falsely purports that Yahoo sent it (support@yahoo.com).
Email Routine Details
The email message has the following characteristics:
From: support@yahoo.com (NOTE: W32.Sobig.E@mm spoofs this field. It could be
any address.)
Subject: The subject line will be one of the following:
Re: Application
Re: Movie
Re: Movies
Re: Submitted
Re: ScRe:ensaver
Re: Documents
Re: Re: Application ref 003644
Re: Re: Document
Your application
Application.pif
Applications.pif
movie.pif
Screensaver.scr
submited.pif
new document.pif
Re: document.pif
004448554.pif
Referer.pif
Attachment: The attachment name will be one of the following:
Your_details.zip (contains Details.pif)
Application.zip (contains Application.pif)
Document.zip (contains Document.pif)
Screensaver.zip (contains Sky.world.scr)
Movie.zip (contains Movie.pif)
NOTE: The worm de-activates on July 14, 2003, and therefore, the last day on
which the worm will spread is July 13, 2003.
Symantec Security Response has created a http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.e@mm.removal.tool.html">tool to remove W32.Sobig.E@mm.
>>
http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.e@mm.removal.tool.html">
http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.e@mm.removal.tool.html
-----------------------------------------------------------