| 1:58 am on Sep 22, 2003 (gmt 0)|
I've never heard of them sending the actual patch via e-mail. Sounds fishy.
| 2:01 am on Sep 22, 2003 (gmt 0)|
This is Swen.
Symantec info at
| 2:26 am on Sep 22, 2003 (gmt 0)|
Yeah, I'd be more inclined to expect to see Bill Gates pull up to my front door via a convoy of gold plated Hummers than to receive an email from M$ telling me how to patch them (again)
| 2:36 am on Sep 22, 2003 (gmt 0)|
Just wait until Bill G. starts forcing automatic updates on us. We probably won't be able to tell if it's real or not then.
| 3:23 am on Sep 22, 2003 (gmt 0)|
There are four (to date) of bogus emails all saying they are something to do with Microsoft. The Symantec virus definitions pick all them up - thank goodness.
Love them or hate them the people sending the latest lot have gone a bit further than straight emails this time. The design looks like MS, but, as already stated MS dosen't usually send information out in this fashion.
MS Inet Mail Delivery System
MS Security Services
MS Security Support
network email system
| 11:55 am on Sep 24, 2003 (gmt 0)|
I have been receiving between 20 and 60 of these emails per hour for the last two days. Is there any way I can stop them?
| 12:42 am on Sep 25, 2003 (gmt 0)|
I'm using these rules in a filter in Mozillas Mail/News:
body contains Content-Type: audio/x-wav
body contains Content-Type: application/x-msdownload
body contains Content-Type: audio/x-midi
body contains Worm.Automat.AHB
The first three indentifies the spoofed attacments
The last one identifies emails where the virus has been removed by the spam/virus filter of a smtp-server (I've received this one both in english and spanish)
There's no reason to try to discover all possible permutations of words in subject or sender neither all possible words.
If the message body contains one of the mentioned three Content-Type it's with 99.99999999% certainty a virus.
I haven't observed a single false positive.
I just filter these messages to trash.
Thrash is set to be automagically emptied when Mozilla is shut down.
| 1:10 am on Sep 25, 2003 (gmt 0)|
yeah, definately a virus attached to that message!
When in doubt, never click an email link... instead go straight to the source (in this case, windows update) and see if you need any patching.
Similar: I just got an email telling me to update my EBAY information by clicking the link in the email. I checked the message headers and it did indeed look like it was from ebay. BUT, instead I went to ebay and logged in. Turned out to be a bogus message trying to gather info (credit cards, etc). Glad I went to the source.
| 1:21 am on Sep 25, 2003 (gmt 0)|
when you look at those headers, check the IP numbers as well... the top one is put in by your mail server... that ip number cannot be faked like the domain names can be... spamcop.net is great for these...
also, look at the source and see where the links and submit buttons are taking you... if there's an @ in there, drop everything before it and what follows is the true site you'll be dropping by...
in the above example, you'll be going to 127.0.0.1/whatever... i've had both paypal and ebay messages of similar nature and in both cases, the subterfuge was easy to spot...
in the case of the paypal one, you were dropped by a site that recorded the info from the form variables and then forwarded on to paypal with the necessary ones for the login... this one is called a "man in the middle" attack...
the last thing to remember (maybe the first?) is that microsoft never sends patches out like these emails claim to be... it would be, for one thing, a major traffic load on the network... for another, they don't have everyone's email addresses though they do try to get as many as they can ;)
| 2:12 am on Sep 25, 2003 (gmt 0)|
|when you look at those headers, check the IP numbers as well... the top one is put in by your mail server... that ip number cannot be faked like the domain names can be... |
Oh, yes it can. I've also gotten some emails without any IPs in the headers. I don't know how they do it.
When you get these fake paypal, ebay, or whoever emails, I recommend sending a copy with the header to their abuse department. A lot of these big companies will collect evidence, and then go sue the culprits. Microsoft in particular loves suing people but don't send them any of the viruses/worms or they will get really mad at you.
| 3:09 am on Sep 25, 2003 (gmt 0)|
as i said, the top one is added by your mail server... if it doesn't put the ip number in and accepts what the remote connection tells it, then you will get faked stuff all the way thru...
many's the time that i see 5 or 6 received headers and all of them are faked except for the top one which is either the actual culprit or an open proxy that's being abused...
just like here on WW, spamcop.net is full of info on this stuff and what the spammers are doing and how... not only do you learn about that but also how mail servers operate, should (ideally) be configured and how they are abused... i use xnews to access their newsgroup server... there are other methods of joining in on their discussions, too... be careful and wear your asbestos garments... also note that just like here on WW, "competitors" are there as well...