« December 2004 »
S M T W T F S
1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31
You are not logged in. Log in
JunSamboy's Work Blog
Monday, 13 December 2004
Dec. 13
Topic: Viruses

The following e-mail messages were found to have viruses in them:

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: A9F521DD325
Report: ClamAV: Fish.zip contains Worm.Bagle.Gen-zippwd

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 231A71DD325
Report: ClamAV: Secret.scr contains Worm.Bagle.AG
MailScanner: Windows Screensavers are often used to hide viruses (Secret.scr)

Posted by Samboy at 1:38 PM WST
Friday, 10 December 2004
Dec. 10
Topic: Viruses
The following e-mail messages were found to have viruses in them:

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 24E601DD325
Report: ClamAV: foto2.com contains Worm.Bagle.AG
MailScanner: Executable DOS/Windows programs are dangerous in email (foto2.com)

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 4D5CD1DD325
Report: ClamAV: Garry.zip contains Worm.Bagle.Gen-zippwd

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 6D5C61DD325
Report: ClamAV: Cat.com contains Worm.Bagle.AG
MailScanner: Executable DOS/Windows programs are dangerous in email (Cat.com)

Sender: 5d4371@roxette.org
IP Address: 61.106.200.145
Subject: SunTrust Bank Fraud Verification Process
MessageID: 1ADBF1DD325
Report: ClamAV: msg-22591-7.html contains HTML.Phishing.Bank-1

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 69CA81DD325
Report: ClamAV: Garry.exe contains Worm.Bagle.AG
MailScanner: Executable DOS/Windows programs are dangerous in email (Garry.exe)

Posted by Samboy at 12:01 AM WST
Thursday, 9 December 2004
Dec. 9
Topic: Viruses
The following e-mail messages were found to have viruses in them:

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 99AE41DD325
Report: ClamAV: Doll.exe contains Worm.Bagle.AG
MailScanner: Executable DOS/Windows programs are dangerous in email (Doll.exe)

Posted by Samboy at 12:01 AM WST
Wednesday, 8 December 2004
Dec. 8
Topic: Viruses
The following e-mail messages were found to have viruses in them:

Sender:
IP Address: 129.250.35.106
Subject: Mail delivery failed: returning message to sender
MessageID: D13211DD325
Report: ClamAV: msg-31461-3.txt contains Worm.Sober.I

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 694C91DD325
Report: ClamAV: Cat.scr contains Worm.Bagle.AG
MailScanner: Windows Screensavers are often used to hide viruses (Cat.scr)

Posted by Samboy at 12:01 AM WST
Tuesday, 7 December 2004
Dec. 7
Topic: Viruses
The following e-mail messages were found to have viruses in them:

Sender: ivylistic@yahoo.com
IP Address: 203.115.189.25
Subject: Re:
MessageID: 248611DD325
Report: ClamAV: Cat.cpl contains Worm.Bagle.AG
MailScanner: Control panel items are often used to hide viruses (Cat.cpl)

Posted by Samboy at 12:01 AM WST
Sunday, 5 December 2004
Dec 5 Viruses
Topic: Viruses
Wow, no viruses for several days! (11/28 to Dec 4)

The following e-mail messages were found to have viruses in them:

Sender: justinian@skyinet.net
IP Address: 202.78.104.25
Subject: Re:
MessageID: 7EE051DD325
Report: ClamAV: Fish.scr contains Worm.Bagle.AG
MailScanner: Windows Screensavers are often used to hide viruses (Fish.scr)

Sender: labaya@tei.ph
IP Address: 202.78.104.25
Subject: Re:
MessageID: 360C01DD325
Report: ClamAV: Doll.scr contains Worm.Bagle.AG
MailScanner: Windows Screensavers are often used to hide viruses (Doll.scr)

Posted by Samboy at 12:01 AM WST
Thursday, 25 November 2004
Nov 25
Topic: Viruses
The following e-mail messages were found to have viruses in them:

Sender:
IP Address: 167.181.33.37
Recipient: auto-mailer@xxx
Subject: Delivery Status Notification (Failure)
MessageID: 4E1951DD325
Report: ClamAV: re_mail_9292.com contains Worm.Sober.I
MailScanner: Executable DOS/Windows programs are dangerous in email (re_mail_9292.com)

Sender: webmaster@edsamail.com.ph
IP Address: 210.23.174.225
Recipient: mr. d, rocks, azil (@xxx)
Subject: Re: Mail Error <3028>
MessageID: 3CA211DD325
Report: ClamAV: mail.xls.scr contains Worm.Sober.I
MailScanner: Windows Screensavers are often used to hide viruses (mail.xls.scr)

Posted by Samboy at 12:01 AM WST
Wednesday, 24 November 2004
Nov 24
Topic: Viruses
The following e-mail messages were found to have viruses in them: still the common
Recipient: ate jo

Sender: hostmaster@dti.dti.gov.ph
IP Address: 165.243.0.231
Subject: Registration confirmation
MessageID: 71F191DD325
Report: ClamAV: dti.xls.pif contains Worm.Sober.I
MailScanner: Shortcuts to MS-Dos programs are very dangerous in email (dti.xls.pif)

Sender: auto-mailer@lge.com
IP Address: 165.243.0.231
Recipient: joel@sfelapco.com
Subject: Mail_Delivery_failure
MessageID: CEE821DD325
Report: ClamAV: lge.scr contains Worm.Sober.I
MailScanner: Windows Screensavers are often used to hide viruses (lge.scr)

It's getting unwieldy, so I just blacklisted the 3 address from the 165.243.0.0 block that have sent mails to ate jo. No more SOBER-infected mails! :-P

Posted by Samboy at 12:01 AM WST
Tuesday, 23 November 2004
Nov 23
Topic: Viruses
The following e-mail messages were found to have viruses in them:
Each one's Recipient: ate jo

Sender: user_info@dti.dti.gov.ph
IP Address: 165.243.0.226
Subject: Registration confirmation
MessageID: 267911DD325
Report: ClamAV: dti.scr contains Worm.Sober.I
MailScanner: Windows Screensavers are often used to hide viruses (dti.scr)

Sender: new_account@edsamail.com.ph
IP Address: 165.243.0.226
Subject: FwD: Registration confirmation
MessageID: ABC671DD325
Report: ClamAV: edsamail_8942.zip contains Worm.Sober.I

Sender: audred24@yahoo.com
IP Address: 165.243.0.226
Subject: Details
MessageID: CED791DD325
Report: ClamAV: oh_nono4801.bat contains Worm.Sober.I
MailScanner: Batch files are often malicious (oh_nono4801.bat)

Posted by Samboy at 12:01 AM WST
Monday, 22 November 2004
Nov 22 Viruses
Topic: Viruses
The following e-mail messages were found to have viruses in them:

Each one's recipient is ate jo

Sender: re-mail_system@yahoo.com
IP Address: 165.243.0.231
Subject: Faulty_mail delivery
MessageID: 5DAD81DD326
Report: ClamAV: re_mail_9838.word.com contains Worm.Sober.I
MailScanner: Executable DOS/Windows programs are dangerous in email (re_mail_9838.word.com)

Sender: user_info@lge.com
IP Address: 165.243.0.230
Subject: Your mail password
MessageID: ABBBB1DD325
Report: ClamAV: lge.5366.DOC.bat contains Worm.Sober.I
MailScanner: Batch files are often malicious (lge.5366.DOC.bat)

Sender: info@lge.com
IP Address: 165.243.0.226
Subject: illegal signs in your mail
MessageID: 88DC81DD325
Report: ClamAV: re_mail.TXT.zip contains Worm.Sober.I

Sender: re-mail_system@lge.com
IP Address: 165.243.0.231
Subject: Faulty_mail delivery
MessageID: 587161DD325
Report: ClamAV: mail8784.pif contains Worm.Sober.I
MailScanner: Shortcuts to MS-Dos programs are very dangerous in email (mail8784.pif)

Sender: new_account@lge.com
IP Address: 165.243.0.230
Subject: Re: Confirmation
MessageID: 2FAB51DD325
Report: ClamAV: lge_7500.eml.zip contains Worm.Sober.I

Sender: roland@lge.com
IP Address: 165.243.0.230
Subject: Details
MessageID: 9CEC01DD325
Report: ClamAV: thats_hard168.pif contains Worm.Sober.I
MailScanner: Shortcuts to MS-Dos programs are very dangerous in email (thats_hard168.pif)

Sender: mr_lorenzo33@hotmail.com
IP Address: 165.243.0.231
Subject: FwD: Oh God it's
MessageID: 4139D1DD325
Report: ClamAV: thats_hard.3771.scr contains Worm.Sober.I
MailScanner: Windows Screensavers are often used to hide viruses (thats_hard.3771.scr)

Sender: info@lge.com
IP Address: 165.243.0.226
Subject: Confirmation
MessageID: A49C11DD325
Report: ClamAV: lge2556.scr contains Worm.Sober.I
MailScanner: Windows Screensavers are often used to hide viruses (lge2556.scr)

Sender: jhco2000@lge.com
IP Address: 165.243.0.226
Subject: Re: Details
MessageID: 4313E1DD325
Report: ClamAV: thats_hard.doc.com contains Worm.Sober.I
MailScanner: Executable DOS/Windows programs are dangerous in email (thats_hard.doc.com)

Sender: error_mail@saversmart.com.ph
IP Address: 165.243.0.230
Subject: Delivery_failure_notice
MessageID: 22C2A1DD325
Report: ClamAV: saversmart.1051.scr contains Worm.Sober.I
MailScanner: Windows Screensavers are often used to hide viruses (saversmart.1051.scr)

Sender: webmaster@dti.dti.gov.ph
IP Address: 165.243.0.226
Subject: Mail Error
MessageID: 952711DD325
Report: ClamAV: auto__mail.dti.doc.bat contains Worm.Sober.I
MailScanner: Batch files are often malicious (auto__mail.dti.doc.bat)

Posted by Samboy at 12:01 AM WST

Newer | Latest | Older