FutureQuest, Inc. FutureQuest, Inc. FutureQuest, Inc.

FutureQuest, Inc.
Go Back   FutureQuest Community > General Site Owner Support (All may read/respond) > Open Discussions
User Name
Password  Lost PW

Reply
 
Thread Tools Search this Thread Display Modes
Old 03-22-2004, 01:26 PM   Postid: 109246
Randall
Fuzzier than thou
 
Randall's Avatar

Forum Notability:
1187 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Nov 2002
Posts: 9,640
New virus?

I don't know if this is really new or not, but I don't remember seeing this tactic before:
Quote:
Subject: Mail Delivery (failure email@domain.com)

If the message will not displayed automatically,
follow the link to read the delivered message.

Received message is available at:
www.domain.com/inbox/info/read.php?sessionid-11255
If I hadn't already been tipped off by Mozilla's status bar that the link actually pointed to a location on the hard drive (ie, an attachment), the poor grammar and the fact that the domain in question is on an NT server and doesn't run PHP should have.

But a non-technical user wouldn't pick up on any of these warning signs (well, maybe the grammar). It doesn't immediately look like an attachment, at least not in Moz.

Randall
Randall is offline   Reply With Quote
Old 03-22-2004, 01:36 PM   Postid: 109248
cindik
Site Owner
 
cindik's Avatar

Forum Notability:
120 pts: Helpful Contributor
[Post Feedback]
 
Join Date: Aug 2002
Location: No Fly Zone
Posts: 774
I think that's one of the later versions of Bagle. I believe this behavior started with Rev. Q.

http://www.trendmicro.com/vinfo/viru...ame=PE_BAGLE.Q
http://us.mcafee.com/virusInfo/defau...virus_k=101063
http://www.f-prot.com/virusinfo/desc...s/bagle_q.html
http://securityresponse.symantec.com...agle.t@mm.html
__________________
"You can't put mayonnaise in a suitcase and expect triumph." --Jill Bernard
Cindi Knox
www.cindik.com - - - e-mail: http://cindik.com/contact/ - - - blog: http://cindik.com/spirituality/trans-cendental/
cindik is offline   Reply With Quote
Old 03-22-2004, 03:03 PM   Postid: 109250
Randall
Fuzzier than thou
 
Randall's Avatar

Forum Notability:
1187 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Nov 2002
Posts: 9,640
It doesn't match their description of Bagle.Q -- there is an actual attachment, disguised as a link -- so I don't think it's that one. We've received three of them so far today, so whatever it is, it's a busy little jerk.

Randall
Randall is offline   Reply With Quote
Old 03-22-2004, 03:24 PM   Postid: 109251
Wassercrats
Site Owner
 
Wassercrats's Avatar

Forum Notability:
291 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Nov 2001
Posts: 7,092
Is there ordinarily something on people's hard drives that could be damaging if opened? Maybe the email was trying to activate a previously downloaded virus.
Wassercrats is offline   Reply With Quote
Old 03-22-2004, 03:44 PM   Postid: 109253
cindik
Site Owner
 
cindik's Avatar

Forum Notability:
120 pts: Helpful Contributor
[Post Feedback]
 
Join Date: Aug 2002
Location: No Fly Zone
Posts: 774
Quote:
Originally posted by Randall:
It doesn't match their description of Bagle.Q -- there is an actual attachment, disguised as a link -- so I don't think it's that one. We've received three of them so far today, so whatever it is, it's a busy little jerk.

Randall
My mistake - I've been getting a lot of Bagles lately. It looks like Netsky: http://www.trendmicro.com/vinfo/viru...TSKY.P&VSect=T
__________________
"You can't put mayonnaise in a suitcase and expect triumph." --Jill Bernard
Cindi Knox
www.cindik.com - - - e-mail: http://cindik.com/contact/ - - - blog: http://cindik.com/spirituality/trans-cendental/

Last edited by cindik : 03-22-2004 at 03:55 PM.
cindik is offline   Reply With Quote
Old 03-22-2004, 04:05 PM   Postid: 109255
Randall
Fuzzier than thou
 
Randall's Avatar

Forum Notability:
1187 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Nov 2002
Posts: 9,640
Quote:
Is there ordinarily something on people's hard drives that could be damaging if opened? Maybe the email was trying to activate a previously downloaded virus.
No, that's just the way Mozilla treats links to attached files -- they look like

   mailbox://c|/path-to-file

I think they lead to the actual file where the email is stored on disk, but I'm not sure.

Well, I did a little experiment, and found that it does show an attachment in Outlook Express -- so it's a flaw in Mozilla that's disguising the true nature of the virus.

Viruses suck.

Randall
Randall is offline   Reply With Quote
Old 03-22-2004, 04:25 PM   Postid: 109256
cindik
Site Owner
 
cindik's Avatar

Forum Notability:
120 pts: Helpful Contributor
[Post Feedback]
 
Join Date: Aug 2002
Location: No Fly Zone
Posts: 774
__________________
"You can't put mayonnaise in a suitcase and expect triumph." --Jill Bernard
Cindi Knox
www.cindik.com - - - e-mail: http://cindik.com/contact/ - - - blog: http://cindik.com/spirituality/trans-cendental/
cindik is offline   Reply With Quote
Old 03-22-2004, 04:30 PM   Postid: 109257
Wassercrats
Site Owner
 
Wassercrats's Avatar

Forum Notability:
291 pts: An Honor To Be Around
[Post Feedback]
 
Join Date: Nov 2001
Posts: 7,092
I was just looking at how temporary internet files are stored. There's a bracketed number appended to the original file name. I'm not sure why that's needed for caching a web page, but to prevent different email attachments with the same file name from confusing things, something like the date and time should be added to the file name, and if it is, I don't see how an emailer could know the name.
Wassercrats is offline   Reply With Quote
Old 03-22-2004, 05:08 PM   Postid: 109260
Randall
Fuzzier than thou
 
Randall's Avatar

Forum Notability:
1187 pts: A True Crowd-pleaser!
[Post Feedback]
 
Join Date: Nov 2002
Posts: 9,640
Yep, that's the one, Cindi. In Mozilla it doesn't show the message.scr attachment -- until you've clicked on the link and hosed your system. (This is in v1.3 ... I oughta upgrade it and see if they've fixed that yet.)

I hope the little brats involved in this "virus war" get decapitated soon.
Quote:
I'm not sure why that's needed for caching a web page, but to prevent different email attachments with the same file name from confusing things, something like the date and time should be added to the file name, and if it is, I don't see how an emailer could know the name.
They wouldn't. It's the link in the email that matters:
Quote:
<a href=cid:031401Mfdab4$3f3dL780$73387018@57W81fa70 height=0 width=0>www.domain.com/inbox/info/read.php?sessionid-11255</a>
That's what it looks like in the HTML source of the email. The link is pointing to a specific MIME segment of the email, which is the virus attachment. It's up to the email program to decide how to represent that to the user. IE shows it as "mhtml:mid://00000000/!cid:031401M..." etc when you hover the mouse over the link. Of course, if you're not paying attention it looks like a link to domain.com.

Randall
Randall is offline   Reply With Quote
Old 03-25-2004, 12:06 PM   Postid: 109451
JRepici
Site Owner
 
JRepici's Avatar

Forum Notability:
10 pts: User-friendly
[Post Feedback]
 
Join Date: Feb 2000
Location: Riverside, NJ
Posts: 478
I'm getting these by the dozen too...

Always the same cid. Is there any more information on the Win-process this clid points to?

Also of note: It looks like someone who uses English as a second language or who possibly used an automated translation service.

re:

Code:
[EDIT]
ON second thought, it's probably a bad idea to show the HTML here after all.
[/EDIT]
__________________
www.creativyst.com
Explored - Designed - Delivered(sm)
JRepici is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 visitors)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:18 AM.


Running on vBulletin®
Copyright © 2000 - 2013, Jelsoft Enterprises Ltd.
Hosted & Administrated by FutureQuest, Inc.
Images & content copyright © 1998-2013 FutureQuest, Inc.
FutureQuest, Inc.