New Virus on the loose

MysticLlama

Golden Member
Sep 19, 2000
1,003
0
0
Hey guys, I?m not sure what the name of this thing is, but we have a pretty pesky new virus going around if you haven?t already heard.

There aren?t yet any virus definitions available from Symantec. (I?m using AV and Filtering for Exchange) , but it?s easy enough to block once you see how it works.

Basically, the thing gets through by putting a .pif file into a valid zip. The zip is called your_details.zip. The user opens the zip then runs the pif, causing the infection.

It also seems to spoof the return address to someone in your address book, though I can?t 100% confirm this yet, and it doesn?t always do it.

Subject lines I?ve noticed so far are Re: Movie, and Fw: Application, along with a couple others, but the attachment name is always the same, thus the easy blocking. (I did see one variant that was details.zip, so expect more to come)

It?s going around pretty fast right now, so far in WA the biggest offender from outside sending me mail is wa.gov of all places.

Update your filters to look for your_details.zip and details.zip.

Good luck to all
 

MysticLlama

Golden Member
Sep 19, 2000
1,003
0
0
Okay, slight modification.

I've been doing some research, and it's not 100% new, I think it's a modified version or something.

It seems to be this, but the scanning engine (since I use Symantec) isn't picking it up, and there are no new updates at the moment that I can get.
 

Soybomb

Diamond Member
Jun 30, 2000
9,506
2
81
Your virus scanner on the mail server doesn't check the contents of compressed files? *tsk*tsk* ;)
 

Saltin

Platinum Member
Jul 21, 2001
2,175
0
0
The June 25th definitions (available yesterday) handle SoBig type E.

And the Symantec Exchange scanner/filter picks them up just fine, i.e. it scans compressed files.
 

MysticLlama

Golden Member
Sep 19, 2000
1,003
0
0
Yeah, it does scan compressed files, but the virus defs weren't out for it until yesterday evening.

And you can't have it block certain file types within archives, which would be somewhat counter-productive anyway, you'd be getting zips with all of the .exe, .vbs, etc. things blocked if you block those initially.

I got the definitions upgraded, I actually have it auto-update every night, and this is the only one that has caused me a problem so far.
 

Saltin

Platinum Member
Jul 21, 2001
2,175
0
0
ML, it got one of my users too.

Symantec sort of dropped the ball, update wise, on this one. There was a window of about 6 work hours where most of my clients were on June 18th def's and we suddenly got slammed by SoBig E.

I don't block zips at the mail proxy either, so they all got through.

All of my users are pretty clever too (it's a software development house, all computer savvy), but the VP got one with subject Re: Application, and he's expecting some applications for a job opening, hehe. Course, most resumes don't come in .pif format...hehe.