A Fishing forum. FishingBanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » FishingBanter forum » rec.outdoors.fishing newsgroups » Fly Fishing
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Are you still bothered with the W32.Swen.A@mm worm?



 
 
Thread Tools Display Modes
  #1  
Old October 26th, 2003, 01:55 AM
Stig Arne Bye
external usenet poster
 
Posts: n/a
Default Are you still bothered with the W32.Swen.A@mm worm?

Since September 19, I have so far received almost 5,500 e-mail with the
W32.Swen.A@mm worm in the attachment (the fake Microsoft update patch),
and I'm still receiving something about 100-150 every day.

Some time ago, I started to send abuse messages to the senders ISP.
However, I could have saved me the hard work of locating the infected
senders ISP, and instead sent an alert message directly to the infected
sender.

Here is a header sample from one of the latest Swen.A-infected e-mails I
have received:

From - Sat Oct 25 21:42:16 2003
Return-Path:
Received: from vump (ti200720a149-0067.dialup.online.no [130.67.192.195])
by mail41.fg.online.no (8.9.3p2/8.9.3) with SMTP id TAA23439; Sat, 25 Oct 2003 19:12:43 +0200 (CEST)
Date: Sat, 25 Oct 2003 19:12:43 +0200 (CEST)
Message-Id:
From: MS Net Email Delivery Service
To: Internet User
Subject: failure announcement

Both the "From:"-line and the "To:"-line contain fake e-mail addresses
(that is quite obvious).

However, the "Return-Path:"-line is NOT faked, i.e. the e-mail address
found here is the _REAL_ e-mail address of the infected sender!

This is somewhat unlike other mass-mailing worms (e.g. Klez.H and
Sobig.F) that fake every single e-mail address in the header so it's
completly impossible to know the real sender without doing the trouble
to send an abuse through the senders ISP (if one is able to find out who
the senders ISP is).



Stig Arne Bye

E-mail ......:
Contact .....: AOL IM: VT480TFE / MSN:
/ ICQ: 403349
Snail-Mail ..: P.O.Box 169, NO-9915 Kirkenes, Norway
Homepage ....:
http://home.online.no/~stigbye/index.html
------------------------------------------------------------------------
Located just about 70°N 30°E - Almost at the top of the world!


 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wacky worm setup f.blair Bass Fishing 1 April 21st, 2004 04:49 AM
denser worm resin Salmo Bytes Bass Fishing 3 January 23rd, 2004 08:02 AM
Denser Worm Resin II Salmo Bytes Bass Fishing 0 January 22nd, 2004 10:49 PM
denser, heavier soft plastic (worm) resin Salmo Bytes General Discussion 0 January 22nd, 2004 08:56 PM
VIRUS question.. riverman Fly Fishing 30 October 18th, 2003 11:16 PM


All times are GMT +1. The time now is 07:25 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright ©2004-2025 FishingBanter.
The comments are property of their posters.