[CTS] Re: Spoofing - here's a better example

  • From: "Charles R. Buchanan" <crbgfblab@xxxxxxxxxxxxx>
  • To: computertalkshop@xxxxxxxxxxxxx
  • Date: Thu, 04 Mar 2004 17:05:09 -0800

This is what NOD said about a msg that had a worm attached that was sent
to a mailing list no less (on freelists, but could happen to others):


__________ NOD32 1.651 (20040303) Notification  __________

Warning: NOD32 Antivirus System found the following infiltrations in the 
message:
  AttachedFile.zip - Win32/Bagle.gen.zip worm - quarantined - deleted


On Thu, 04 Mar 2004 07:01:26 -0600, "Russ Blakeman" <rhb57@xxxxxxxxxx> had this 
to say:

RB> Here's a cut/paste of a message that AVG caught...came from MY mailer
RB> supposedly - good trick since I am the one that runs that mail server and
RB> controls what goes in and out:
RB> 
RB> ------
RB> Viruses found in the attached files.
RB> The file Readme.pif: Virus identified  I-Worm/Bagle.J. The attachment was
RB> moved to the virus vault.
RB> 
RB> The original message follows:
RB> --
RB> Dear user of Rbcsweb.net,
RB> 
RB> Your e-mail account will  be disabled because  of improper using in  next
RB> three days, if you are still wishing  to use it, please, resign your
RB> account information.
RB> 
RB> Pay attention on attached file.
RB> 
RB> The Management,
RB>    The Rbcsweb.net team                             http://www.rbcsweb.net



---------------------------------------------------------------------------
Computer Talk Shop http://www.computertalkshop.com
Un-subscribe/Vacation, http://www.computertalkshop.com/list_options.htm

List HowTo: http://www.computertalkshop.com/faq.htm

To join Computer Talk Shop's off topic list, please goto:
http://computertalkshop.com/other_cts_lists.htm
---------------------------------------------------------------------------

Other related posts: