Posted 08-19-2003 at 17:17:51
[Reply] [No Email]
Date: Tuesday, 19 August 2003, at 7:24 a.m.
New MS worm infecting computers-WARNING!
symantec ^ | 8/19/03 | self
Posted on 08/19/2003 7:22 AM PDT by TheBigB
Due to the number of submissions received from customers, Symantec Security Response has upgraded this threat to a Category 3 from a Category 2 threat.
W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses that it finds in the files with the following extensions:
.dbx .eml .hlp .htm .html .mht .wab .txt
Email Routine Details The email message has the following characteristics:
Subject: Re: Details Re: Approved Re: Re: My details Re: Thank you! Re: That movie Re: Wicked screensaver Re: Your application Thank you! Your details
Body: See the attached file for details Please see the attached file for details.
Attachment: application.zip (contains application.pif) details.zip (contains details.pif) document_9446.zip (contains document_9446.pif) document_all.zip (contains document_all.pif) movie0045.zip (contains movie0045.pif) thank_you.zip (contains thank_you.pif) your_details.zip (contains your_details.pif) your_document.zip (contains your_document.pif) wicked_scr.zip (contains wicked_scr.scr)
NOTE: The worm deactivates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.