Security Incidents mailing list archives

Re: New virus disguised as Microsoft patch?


From: Alex Lambert <alambert () quickfire org>
Date: Sat, 20 Sep 2003 23:00:21 -0500

David:

It's Swen, the worm of the week. I first received it on Friday. It sends out the fake Microsoft updates as well as fake postmaster messages designed to exploit an old Outlook vulnerability.

See http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SWEN.A




Cheers,

apl

David Gillett wrote:
  No, this isn't the crude "500,000 already infected!"
garbage. This is an extremely polished and convincing looking html email which claims to be a "September 2003, Cumulative Patch" and includes an attached "patch8678.exe".

  I've got four of these overnight, from broadband users
as far away from Microsoft as Greece. Each is followed by an odd little NDR, presumably reporting failed delivery of
a delivery confirmation message.

David Gillett



---------------------------------------------------------------------------
----------------------------------------------------------------------------




---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: