LABachlr
Registered
A buddy of mine has a Mac and received the following emails.
He received this one yesterday:
He then received this email this morning (this is a worm for Windows!):
He received this one yesterday:
Very bizarre seeing that no one has access to his domain except me, and "administration@[hisdomain].com" is not even a valid email address. There is only one valid email address on his domain, and that's his. This is pretty much a joke seeing that there are no known trojan's for Mac's, right? My guess is the attached file is a trojan itself, or some sort of program that would send info back to the sender of this email if he were to execute the attachment, which he didn't.> From: administration@[hisdomain].com
> Date: Wed Mar 10, 2004 02:11:43 PM US/Pacific
> To: [hisusername]@[hisdomain].com
> Subject: E-mail account disabling warning.
>
> Dear user of [hisdomain].com,
>
> Some of our clients complained about the spam (negative e-mail
> content)
> outgoing from your e-mail account. Probably, you have been infected
> by
> a proxy-relay trojan server. In order to keep your computer safe,
> follow the instructions.
>
> Please, read the attach for further details.
>
> Attached file protected with the password for security reasons.
> Password is 84054.
>
> Cheers,
> The [hisdomain].com team
> http://www.[hisdomain].com
He then received this email this morning (this is a worm for Windows!):
Can anyone tell me what the deal is with this? I assume all of this is totally bogus.> From: MadWeb01/Antena3TV@antena3tv.es
> Date: Fri Mar 12, 2004 12:50:08 AM US/Pacific
> To: "Antigen_Notification_List:_Default"@antena3tv.es
> Subject: ALERT: Message from [his name] was purged; Detected worm:
> Win32.Netsky.D (aka W32/Netsky.d@MM, Win32/Netsky.D.Worm)
>
>
>
>
>
>
>
> INCIDENT
> ------------------------------------------------------------------------------------------------------------------------
>
> Scan Time: 12/03/2004 09:50:08
> Detection: Detected worm: Win32.Netsky.D (aka W32/Netsky.d@MM,
> Win32/Netsky.D.Worm)
> Disposition: Note has been purged
> Incident doc: (Document link: Antigen Incident and Quarantine Area
> document) CN=MadWeb01/O=Antena3TV!!antqarea2.nsf
> Version: Antigen 7.0 SR1 (Build 711)
>
>
> MESSAGE
> ------------------------------------------------------------------------------------------------------------------------
>
> Message ID: 003087D9
> Sender: [hisusername]@[hisdomain].com
> Subject: Re: Here
> Recipients: asanz@antena3tv.es
> Routing:
>
>
> SYNOPSIS
> ------------------------------------------------------------------------------------------------------------------------
>
> FILE ATTACHMENT 'yours.pif'
> << Detected worm:Win32.Netsky.D (aka W32/Netsky.d@MM,
> Win32/Netsky.D.Worm) >>
> File size: 17424 bytes
> Host type: MSDOS
> Content type: Exe.Win32
> Compression: OFF
> Attributes: PUBLIC READ-WRITE
> File flags: 2
> Created: 12/03/2004 09:50:05
> Modified: 12/03/2004 09:50:05
> Status: Purged
> Scanner: CA(Vet) 11.4.0.1 [11.4.32.12] Win32.Netsky.D
> Scanner: NAI 4.2.0.60 [4.3.0.35] W32/Netsky.d@MM
> Scanner: CA(InoculateIT) 23.64.0.1 [23.64.0.33]
> Win32/Netsky.D.Worm
> Scanner: Sybari 6.0.664 [119.115.5157] Matched WormPurge
> filter: *netsky*