Please be advised that a new virus is making the rounds as an email attachment. If you receive an email message with an attachment, DO NOT ATTEMPT TO OPEN THE ATTACHMENT unless you know exactly what it is and were expecting someone to send it to you.
The virus is attached to an email message that appears to come from the administrator of your domain name (they are forging the FROM: address to appear that it is coming from your domain). The message may look official, but the attached virus (possibly described as a README file) is a virus, not a legitimate document. Again, do not attempt to open the attached document.
Here are samples of the type of message you may receive:
=============================
SUBJECT: E-mail account disabling warning.
Dear user of Bigsea.com,
Your e-mail account will be disabled because of improper using in next
three days, if you are still wishing to use it, please, resign your
account information.
For more information see the attached file.
Have a good day,
The Bigsea.com team http://www.bigsea.com
Attached file: Message.pif (12.0 KB)
=============================
SUBJECT: E-mail account security warning.
Dear user, the management of Bigsea.com mailing system wants to let you know that,
We warn you about some attacks on your e-mail account. Your computer may
contain viruses, in order to keep your computer and e-mail account safe,
please, follow the instructions.
For details see the attach.
Sincerely,
The Bigsea.com team http://www.bigsea.com
Attached file: Readme.pif (12.0 KB)
================================
SUBJECT: E-mail account disabling warning.
Dear user, the management of Precisionpros.com mailing system wants
to let you know that,
Our main mailing server will be temporary unavaible for next two
days, to continue receiving mail in these days you have to configure
our free auto-forwarding service.
For details see the attached file.
For security reasons attached file is password protected. The password
is "72800".
The Management,
The Precisionpros.com team http://www.precisionpros.com
Attached File: MoreInfo.zip
===================================
Again, they are forging the FROM: address to look like it is coming from your domain name, but is not. Again, DO NOT OPEN THE ATTACHED FILE!
More specific information about this virus can be found here:
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]
Posted by Scott Girard on 3/3/04; 12:40:21 PM
from the News dept.
|