North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Don't beat me, but i've noticed a huge influx of these .pifvirii today.

  • From: Jade E. Deane
  • Date: Tue Aug 19 16:44:47 2003

Drew,
You're not seeing things.  I would say you can thank "W32/Sobig.F-mm",
referenced in http://news.com.com/2100-1002_3-5065494.html.

Allow me to quote a bit from the story:

[quote]
The sender appears to be someone from a recognized domain name, such as
ibm.com, zdnet.com or microsoft.com. The subject line typically says
"Re: Details," "Resume" or "Thank you." 

Attachment names may include: your_document.pif, details.pif,
your_details.pif, thank_you.pif, movie0045.pif, document_Fall.pif,
application.pif, and document_9446.pif. 
[/quote]

Regards,
Jade

On Tue, 2003-08-19 at 15:33, Drew Weaver wrote:
>             Don't kill me for posting this, it may be slightly off
> topic but I have noticed a very odd spike in traffic with these virii
> that have .pifs attached to them. 
> 
>  
> 
> The subject is random.
> 
>  
> 
> The body always says:
> 
>  
> 
> "See attached file for details" and they're always a pif file.
> 
>  
> 
> Anyone else notice this?
> 
>  
> 
> -Drew
> 
>  

Attachment: signature.asc
Description: This is a digitally signed message part