[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <200308191500150.SM01020@genero>
From: scottp at dreamwright.com (Scott Phelps / Dreamwright Studios)
Subject: SoBig.F strange problem
All day today I've been getting copies of SoBig.F. I've gotten around 150
copies so far, and a large number of postmaster bounces saying that a copy
sent from my address was undeliverable.
I know that SoBig forges the from address from files it finds on the victims
machine, but I can't for the life of me figure out why I'm the attempted
victim for so many other copies. I'm not infected with the virus, I'm
running antivirus that strips the attachment before it lands in my inbox,
and I'm running a version of outlook that disallows the attachment
extensions that SoBig uses. I've run manual scans on all of my machines, in
case of infection through a network share, but I don't have any of those
from outside either. All the emails seem to be coming from different places,
but around 90% are using a from address of @msu.edu.
Is there some logical explanation why I'm being singled out here? My
antivirus is driving me insane with popups, so I've had to shut down my mail
program to get some work done.
I'm sorry for the off topic nature of this question, but this makes no sense
to me!
Scott
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3230 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20030819/bb6e6897/smime.bin
Powered by blists - more mailing lists