[61083] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Brace yourselves.. W32/Sobig-F about to mutate...

daemon@ATHENA.MIT.EDU (Stephen J. Wilcox)
Fri Aug 22 14:18:38 2003

Date: Fri, 22 Aug 2003 19:14:36 +0100 (BST)
From: "Stephen J. Wilcox" <steve@telecomplete.co.uk>
To: Valdis.Kletnieks@vt.edu
Cc: nanog@merit.edu
In-Reply-To: <200308221807.h7MI78sn018727@turing-police.cc.vt.edu>
Errors-To: owner-nanog-outgoing@merit.edu



On Fri, 22 Aug 2003 Valdis.Kletnieks@vt.edu wrote:

> A quick heads up, if anybody hasn't heard:
> 
> At 1900GMT today, ET phones home, and picks up the next payload of
> instructions.  Nobody knows (yet) what they'll be, but SoBig-E erased itself,
> put in a password grabber, and then installed a mail proxy for spammer use.

"On this moment, the worm starts to connect to machines found from an encrypted 
list hidden in the virus body. The list contains the address of 20 computers 
located in USA, Canada and South Korea."

erm so why dont we just block (preferably bgp null route) these sites?



home help back first fref pref prev next nref lref last post