Forum Moderators: phranque

Message Too Old, No Replies

30 virus attacks in 2 hours! - W32.Sobig.F@mm

After the blaster another one mass mailing virus!

         

lasko

4:15 pm on Aug 19, 2003 (gmt 0)

10+ Year Member



The virus W32.Sobig.F@mm has been really really quite recently howver symantec have just upgraded it to nearly the same level as the blaster.

For some reason in the last two hours I have received 30 attacks all of which where stopped by Norton with no problems.

The virus is sending it self to any email address found on html, htm, txt files and more on the internet.

So now I am taking all my addresses of all my high ranking web sites and using php to protect my email accounts.

Has anyone else seen a sudden increase of attacks from this virus?

What a week its turning out to be :(

Imaster

9:13 am on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I received almost 20k emails on most of my email accounts and I didn't have a spam filter installed yet. Btw, does a spam filter block such emails?

Now instead of deleting each email manually, I am running a command-line query to delete all the emails with the following subjects:

Subject:
Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details

And its working very fast :) But the emails are also multiplying fast. So I have temporarily made a setting on the server that all mails bigger than 25kb should not be received ;) Of course, all above 25kb are 99% spam...

Visit Thailand

9:23 am on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



That is a good idea in blovking any of 25k unfortunately we get many over that amount but will try that on some that do not.

I posted in this earlier thread:
[webmasterworld.com...] but this one seems to be moving better so will ask again here:

Whether there is anyway to turn off the NAV warnings as the pop ups telling me NAV 2003 has found a virus and requiring me to click finish sometimes makes my comp crash as there are just so many of them.

In fact just typing this I have had to click 'finish' 7 times!

lasko

9:29 am on Aug 20, 2003 (gmt 0)

10+ Year Member



I am having the same problem, due the amount of work the antivirus program is having to do it causing my pc to crash or I have to restart the email program.

I can't block emails above 25k as people send me images and most of them are above 40k etc so I am stuck at the moment.

Never seen a mass mailing virus like this so strong.

I am now starting to receive emails from the ISP as well telling me that I have sent viruses. Mind you I have had the virus appearing from big companies, what a mess.

As I said before its not the actual harm of the virus its the extra work load thats causing the problem :(

lasko

11:39 am on Aug 20, 2003 (gmt 0)

10+ Year Member



The person who made this new virus W32.Sobig.F@mm
has been perfecting it for sometime.

This actual strain came about at the beginning of the year named W32.Sobig.A@mm with similar effects but not as strong.

Since then their has been version B,C,D,E and now F.

F being the most strongest.

The person has managed to tweek it from just htm pages to many other extensions plus manipulate the from address. Origianlly it use to come from either Microsoft or Yahoo now it comes from the last person it had sent to.

Can anyone suggest away of deleting all .piff files from an email automatically using Eudora?

jk3210

12:59 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Well, there they went. Both major email systems I use just shut-down.

Last email check, I was getting about 350 every 20 minutes.

lasko

1:18 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



Still receiving these virus attacks every 2 minutes.

Although now my Zone Alarm firewall is working like crazy, its blocking all sorts of access attempts.

I never used to have a firewall before and now I see why I got one, you never know whats happening other wise.

I would hate to see what the virus does to your system if you where infected :(

juniperwasting

1:47 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



Visit_Thailand

Buried in the options on NAV is an option to "Try to delete then quarantine silently." I believe it is under "Options >> Email".

too much information

2:05 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've been hearing on the news about a possible cyber terror attack, does anyone think this may be what they were talking about?

lasko is getting access attempts, and everyone seems to be getting this stupid e-mail.

Am I just being over paranoid? (maybe my Google phobia has spread!) ;)

krieves

2:30 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



So far virus protection has kept me from getting the email. However, I'm getting tons of reply emails (to my webmaster@ address) saying that I sent a virus and the email was rejected. Apparently, a lot of people who opened the attachment had me in their address books.

It's amazing that people haven't yet learned to be very suspicious of any email with attachments (especially executable ones), no matter who they are from.

lasko

2:31 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



I don't think its a terrorist attack on the Internet, more like the viruses are getting stronger.

In any case the Internet is terrorists best friend how else do you think they communicate.

My firewall is working very well as everytime a virus comes in before the Norton picks it up something tries to access my computer either through UDP or TCP and Port 129.

I hope this ends soon as I find my self deleting so many emails and have had to restore a few after deleting the wrong ones.

Someone sent me an email like this

FW: option date

And I deleted it by mistake as it was amoungst emails with titles like

RE: Thank you and FW: Your details

Very frustrating :(

dazz

2:44 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



I have mailwasher and I am receiving loads of these things. I have set it up so it marks them all for delete but is there any way to auto delete them as its getting silly.

Also it is annoying that you get replys from people thinking that you send the damn virus to them as it is making it out its coming from us to some people!

Just sit it out I suppose and see what happens.

lasko

3:27 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



Another problem, those of your customers who use Yahoo email or MSN email their inboxes are now full due to the size of the attachments. Emails can't be sent to some people until they delete their inboxes which is almost impossible at the moment.

Now those free email accounts that manage to stop the attachments are great but all those ISP warnings are now filling up those in boxes.

This is the worst spam virus I have ever known in all the years I have been working with computers.

5stars

3:27 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



God I love this forum. Misery loves company. :)

I was going crazy yesterday and today. We are getting in the upwards of 200 an hour. And those hoax return emails making it sound like you are sending them out. I went through all my machines last night just to be sure.

Phew

krieves

3:29 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



Just received the "thank you" version of the email. It spoofed Microsoft's address. Our mail scrubber removed the attachment without problem. Yep, I too am sick of all the reply emails.

MarkHutch

3:35 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I hate to say this, but it seems to be worse for us today, than yesterday. I just checked our machines and they are clean, but a bunch of folks do not have clean machines and they seem to have our email addresses in their cache somewhere.

I just changed our Norton to check for updates every hour instead of every day. Man, this is sure a waste of time.

[edited by: MarkHutch at 3:36 pm (utc) on Aug. 20, 2003]

skipfactor

3:35 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I have mailwasher and I am receiving loads of these things. I have set it up so it marks them all for delete but is there any way to auto delete them

Click "View", "Filter Sidebar". In your filter, check it to "Add to blacklist", then go to Blacklist tab, options, then choose "Auto-delete blacklisted messages".

sun818

3:44 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



At least for this week anyway, I'm going to delete these messages by body. Anything with the following text is going to the trash:

Please see the attached file for details.

See the attached file for details

I suppose I could do the same for the bounce messages by subject...

Imaster

3:47 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



not sure whether I must post this, but sometimes I suspect that such viruses are sponsored and backed by the anti-virus companies themselves to increase business. Of course, thats only what I think. It may be true or may not be true.

Imaster

3:48 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Click "View", "Filter Sidebar". In your filter, check it to "Add to blacklist", then go to Blacklist tab, options, then choose "Auto-delete blacklisted messages".

Yeah, that would work :)

BlueSky

3:53 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



not sure whether I must post this, but sometimes I suspect that such viruses are sponsored and backed by the anti-virus companies themselves to increase business.

I've often thought that myself because of how quickly they always have a solution soon after a virus or worm is released. The waves of attacks just don't seem natural to me. It's almost like someone is seeding them.

No one in my family has received any of these yet. Does anyone know if ISPs are screening this stuff out?

MarkHutch

3:54 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



It depends on the ISP. I think most large ones are filtering for viruses, now. However, if you're on a cable/dsl modem I don't think that is the case most of the time.

TheDoctor

5:38 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



not sure whether I must post this, but sometimes I suspect that such viruses are sponsored and backed by the anti-virus companies themselves to increase business. Of course, thats only what I think. It may be true or may not be true.

I think they're busy enough with the real viruses. In any case, if they were trying to generate bsuiness they'd create lots of little virus attacks, rather then one big one (you'll only buy a cure for W32.Sobig.F@mm once).

IanTurner

7:23 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



The auto notifications from spoofed sender addresses are nearly as annoying as the virus itself!

MarkHutch

7:33 pm on Aug 20, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The auto notifications from spoofed sender addresses are nearly as annoying as the virus itself!

You are so right. We are getting dozens of those every hour.

musicales

9:48 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



With regard to deleting based on size - I've been going onto the server and deleting any email that's betweeen 97 and 102k - that seems to cover all the current types that are floating around.

tracylee

9:49 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



I'm not getting many, luckily. One of my clients called panicked that people were telling him he was sending out viruses even though he was running anti-virus software. I finally calmed him down enough to get that he was getting the bounced auto responses. Told them to keep running the anti-virus programs and not open attachments.

What's interesting is that all of the ones I've been getting bounced back were supposedly sent to AOL users. I haven't verified the IPs through the whole header. My real job keeps getting in the way!

kellytps

9:56 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



I am not getting anywhere near the amout that some of you have mentioned, but 1 real email = at least 40 virus emails = 40 spam (viagra,sex,lose weight).
I am so afraid of deleting something legit though. I have a filter that send probable spam into a separate folder, but what a pain just scanning over that. And that's after sorting through the inbox with all the junk that doesn't make it there!
And my biggest pet peeve is trying to word everything in my OPT-IN/OPT-OUT newsletter so that I can get by everyone else's spam filters! I canna figure out why my newsletter gets chucked in the bulk mail folder, but real honest to goodness spam makes it into my inbox!
Just seems so awful what these creeps have done with this. I mean 5 years ago, spam was so few and far between it wasn't even a real issue... now I spend more time deleting it than I do reading my real emails.
:)
Kelly
who is still smiling...

alxdean

10:22 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



this is all very interesting stuff.
friend of mine running a small website got hit not too bad, getting both the virus and the "hey you've sent me a virus" emails. I did not get 1 single one.

second person just started getting them. poor bloke does not know what is going to hit him. but his site has even less exposure.

Thank GOD, that i spoof all the email addresses on my website and all the emails of my members, should they wish to post them. Am running a classifieds board and spoof them too. so hopefully my members should not regret having signed up to my community.
with spoofing I mean using javascript to randomly cut the email in two, assign the pieces to two variables and merging them with javascript again. Workes great, not 1 single virus. TOUCH WOOD.!

I don't think that it is ISP related. get some silly virus every day into my inbox. from the same person! anything from that email simply goes to the trash. so my ISP is not filtering too well if at all.
Also one of my mates is on the same provider and receives the virus. so definately no link there.

What I do think is that the size matters. The bigger the website the more damage. obviously the bigger the site, the more people will have your pages in their cache.

Also I have noticed that the people receiving the virus also get the "you sent me a virus" message. so that is obviously linked. The virus does not only send to the emails it finds in the cache it also uses those emails to disguise itself.

Friend of mine told me his inbox got wiped yeasterday. first thought it was the blaster, but now I'm sure it is this bugger which did it, said he did not open any virus but you never know... has anybod dared taking it to bits to see the workings of it?

pjamescowie

10:40 pm on Aug 20, 2003 (gmt 0)

10+ Year Member



Dare I say it? Yeh, I will.....

Maybe it's time to buy a Mac? (system not affected!)

mayor

12:01 am on Aug 21, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Getting hundreds an hour here too, but it's not all virus stuff. Got a UCE from McAfee promoting VirusScan Home Edition 7.0. Hmmmmmmmmm!

Correction ... maybe it's not actually from MCAfee ... could be spoofed.

This 198 message thread spans 7 pages: 198