DD

David

18/05/2005 1:07 PM

OT: anyone else here getting deluged with emails with German language subjects? (Sober virus is the payload)

I've wondered why I've been inundated with German language e-mail this
past week. I just uncovered a news story about the Sober virus in
German language e-mail. Anyone else getting these ALL DAY LONG?

http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594


Dave


This topic has 19 replies

f

in reply to David on 18/05/2005 1:07 PM

25/05/2005 2:20 PM


A better question might be is anyone NOT getting it.

Anyhow, for the latest and greatest about spam, check out
news.admin.net-abuse.email.

--

FF

f

in reply to David on 18/05/2005 1:07 PM

25/05/2005 2:22 PM



Lee Michaels wrote:
> "Buddy Matlosz" <[email protected]> wrote in message
> news:[email protected]...
> > Visit any unusual websites lately? Some months ago I looked up some info
> > on
> > Brazil nuts just out of curiosity, and have been getting Portuguese spam
> > on
> > a daily basis ever since.
> >
>
> One way to handle that is to use a spam filter that allows you to imput "bad
> words". Put in some Portuguese words.

A better way is to configure your browser so it does not give your
email address out to web sites.

--

FF

DD

David

in reply to David on 18/05/2005 1:07 PM

24/05/2005 7:45 PM

The deluge has let up today. I've gone the entire day without any junk
mail in German. Anyone else who's been getting this crap seen a let-up
today?

Dave

David wrote:

> I've wondered why I've been inundated with German language e-mail this
> past week. I just uncovered a news story about the Sober virus in
> German language e-mail. Anyone else getting these ALL DAY LONG?
>
> http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594
>
>
>
> Dave

DH

Dave Hinz

in reply to David on 18/05/2005 1:07 PM

18/05/2005 8:41 PM

On Wed, 18 May 2005 13:07:27 -0700, David <[email protected]> wrote:
> I've wondered why I've been inundated with German language e-mail this
> past week. I just uncovered a news story about the Sober virus in
> German language e-mail. Anyone else getting these ALL DAY LONG?

Yup. Varient of the Sober virus. Standard "forge from as one person in
addressbook, send to another person in addressbook" technique. As
usual, the fix has been out for a while, but un-patched systems...well,
you know the drill...

DH

Dave Hinz

in reply to David on 18/05/2005 1:07 PM

19/05/2005 4:00 PM

On Wed, 18 May 2005 20:39:28 -0400, Buddy Matlosz <[email protected]> wrote:
> Visit any unusual websites lately? Some months ago I looked up some info on
> Brazil nuts just out of curiosity, and have been getting Portuguese spam on
> a daily basis ever since.

Probably unrelated. Run an adaware scan (lavasoft.com) to see what
spyware you've got (and to clean it); you can see if that shite shows up
in the found objects list.

DH

Dave Hinz

in reply to David on 18/05/2005 1:07 PM

19/05/2005 4:01 PM

On Wed, 18 May 2005 21:03:43 -0400, Lee Michaels <leemichaels*nadaspam*@comcast.net> wrote:
>
> "Buddy Matlosz" <[email protected]> wrote in message
> news:[email protected]...
>> Visit any unusual websites lately? Some months ago I looked up some info
>> on
>> Brazil nuts just out of curiosity, and have been getting Portuguese spam
>> on
>> a daily basis ever since.
>>
>
> One way to handle that is to use a spam filter that allows you to imput "bad
> words". Put in some Portuguese words. This will cut down a lot of spam. I
> put in the obvious "non words" associated with pirated software and penis
> pills. This has reduced this crap considerably.
>
> http://www.bluesquirrel.com/products/spamsleuth/
>
> I am evaluating it now for a couple of businesses. It looks good. You have
> to tinker with it and fine tune it. But you quickly learn how to do that.
> I have been using it for about two weeks and it catches about 85 % to 90 %
> of the spam.

zaep is another product that works very well (zaep.com or
rhinosoft.com), does a whitelist in an unobtrusive way. Unless one of
your friends suddently becomes a spammer, it should be 100%. If I was
still running Windows, I'd still be using it.

DH

Dave Hinz

in reply to David on 18/05/2005 1:07 PM

20/05/2005 6:39 PM

On Fri, 20 May 2005 07:02:08 -0700, jmac <[email protected]> wrote:
> On Thu, 19 May 2005 10:10:44 -0700, mac davis
><[email protected]> wrote:
>>yeah.. only for one day, but there were maybe 30 of them.. all different but all
>>pointing to the same URL..
>>the worst part was that a few days later, I got a bunch of notices that "my"
>>emails bounced... it was the same German thing, sent out with my return
>>address..
>
>>mac
>
> Someone having your email address in their address book got hit with
> the new variation of a common virus. Then you were infected and your
> computer started spewing. I believe it's called the W32 sober virus
> by Symantec. It can be removed by updating and running your
> anti-virus software.

Close, but wrong. They're infected, and sending out messages claiming
to be from people in the infected system's address book, to other people
in that same address book. If it claims to be from you, the only
thing you know is that it _isn't_ from you.

> The URL mentioned in a previous posting is a neo-nazi web site.

Lovely. neo-nazi spammers virus writers. What's not to hate about
that?

md

mac davis

in reply to David on 18/05/2005 1:07 PM

20/05/2005 9:08 AM

On Thu, 19 May 2005 21:40:14 -0700, Mark & Juanita <[email protected]> wrote:


> Caught one the other night from First Trust Bank. The spam e-mail itself
>was really pitiful, it was obviously a phishing scam from some person for
>whom English wasn't even a third language. The website however was *very*
>scary -- they had ripped off all the appropriate logos, including Verisign;
>it looked very believable. The casual observer could easily have been
>duped into giving away plenty of personal information. The web site
>address was close enough that even someone being reasonably careful could
>have been fooled it was "frsttrust" rather than "firsttrust" -- very
>deceptive. [Nope, I don't have a first trust account, something about this
>particular spam just caught my eye and I decided to investigate further.
>Doesn't do any good to complain to the banks, they ignore e-mails from
>regular peons]
>
some business sites take this stuff seriously..
3 that I know of, Ebay, PayPal and Comcast, request copies of the email
forwarded to spoofs@...


mac

Please remove splinters before emailing

BM

"Buddy Matlosz"

in reply to David on 18/05/2005 1:07 PM

18/05/2005 8:39 PM

Visit any unusual websites lately? Some months ago I looked up some info on
Brazil nuts just out of curiosity, and have been getting Portuguese spam on
a daily basis ever since.

B.

"David" <[email protected]> wrote in message
news:[email protected]...
> I've wondered why I've been inundated with German language e-mail this
> past week. I just uncovered a news story about the Sober virus in
> German language e-mail. Anyone else getting these ALL DAY LONG?
>
>
http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594
>
>
> Dave

MJ

Mark & Juanita

in reply to David on 18/05/2005 1:07 PM

19/05/2005 9:40 PM

On Fri, 20 May 2005 04:19:35 GMT, justme <[email protected]> wrote:

>In article <[email protected]>,
>[email protected] says...
>>
>> "David" <[email protected]> wrote in message
>> news:[email protected]...
>> > I've wondered why I've been inundated with German language e-mail this
>> > past week. I just uncovered a news story about the Sober virus in German
>> > language e-mail. Anyone else getting these ALL DAY LONG?
>> >
>> > http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594
>> >
>> >
>> > Dave
>>
>> yes, to my phone of all things. i had to change my email address because my
>> phone became unusable.
>>
>>
>>
>
>Not only that, but someone is using email addresses from this newsgroup
>to do a little eBay phishing. Obviously, with my return address set to
>what it is, they are caught fairly easily, but I'll have to admit that
>some of them have been pretty convincing.

Caught one the other night from First Trust Bank. The spam e-mail itself
was really pitiful, it was obviously a phishing scam from some person for
whom English wasn't even a third language. The website however was *very*
scary -- they had ripped off all the appropriate logos, including Verisign;
it looked very believable. The casual observer could easily have been
duped into giving away plenty of personal information. The web site
address was close enough that even someone being reasonably careful could
have been fooled it was "frsttrust" rather than "firsttrust" -- very
deceptive. [Nope, I don't have a first trust account, something about this
particular spam just caught my eye and I decided to investigate further.
Doesn't do any good to complain to the banks, they ignore e-mails from
regular peons]




+--------------------------------------------------------------------------------+

If you're gonna be dumb, you better be tough

+--------------------------------------------------------------------------------+

jj

jmac

in reply to David on 18/05/2005 1:07 PM

20/05/2005 7:02 AM

On Thu, 19 May 2005 10:10:44 -0700, mac davis
<[email protected]> wrote:
>yeah.. only for one day, but there were maybe 30 of them.. all different but all
>pointing to the same URL..
>the worst part was that a few days later, I got a bunch of notices that "my"
>emails bounced... it was the same German thing, sent out with my return
>address..

>mac

Someone having your email address in their address book got hit with
the new variation of a common virus. Then you were infected and your
computer started spewing. I believe it's called the W32 sober virus
by Symantec. It can be removed by updating and running your
anti-virus software.

The URL mentioned in a previous posting is a neo-nazi web site.

jmac

LM

"Lee Michaels"

in reply to David on 18/05/2005 1:07 PM

18/05/2005 9:03 PM


"Buddy Matlosz" <[email protected]> wrote in message
news:[email protected]...
> Visit any unusual websites lately? Some months ago I looked up some info
> on
> Brazil nuts just out of curiosity, and have been getting Portuguese spam
> on
> a daily basis ever since.
>

One way to handle that is to use a spam filter that allows you to imput "bad
words". Put in some Portuguese words. This will cut down a lot of spam. I
put in the obvious "non words" associated with pirated software and penis
pills. This has reduced this crap considerably.

http://www.bluesquirrel.com/products/spamsleuth/

I am evaluating it now for a couple of businesses. It looks good. You have
to tinker with it and fine tune it. But you quickly learn how to do that.
I have been using it for about two weeks and it catches about 85 % to 90 %
of the spam.


DD

David

in reply to David on 18/05/2005 1:07 PM

18/05/2005 6:10 PM

Today I started inputting some of the German words into the Filters
section to put future mails in the trash so they don't clog up the Bulk
folder. I always scrutinize the e-mail in the bulk folder because some
business e-mail end up there. That's why it's so annoying to have all
these extra ones popping up every few minutes in the Bulk folder. They
make my scanning for legit e-mail more onerous.

Dave

Lee Michaels wrote:

> "Buddy Matlosz" <[email protected]> wrote in message
> news:[email protected]...
>
>>Visit any unusual websites lately? Some months ago I looked up some info
>>on
>>Brazil nuts just out of curiosity, and have been getting Portuguese spam
>>on
>>a daily basis ever since.
>>
>
>
> One way to handle that is to use a spam filter that allows you to imput "bad
> words". Put in some Portuguese words. This will cut down a lot of spam. I
> put in the obvious "non words" associated with pirated software and penis
> pills. This has reduced this crap considerably.
>
> http://www.bluesquirrel.com/products/spamsleuth/
>
> I am evaluating it now for a couple of businesses. It looks good. You have
> to tinker with it and fine tune it. But you quickly learn how to do that.
> I have been using it for about two weeks and it catches about 85 % to 90 %
> of the spam.
>
>
>

jn

justme

in reply to David on 18/05/2005 1:07 PM

20/05/2005 4:19 AM

In article <[email protected]>,
[email protected] says...
>
> "David" <[email protected]> wrote in message
> news:[email protected]...
> > I've wondered why I've been inundated with German language e-mail this
> > past week. I just uncovered a news story about the Sober virus in German
> > language e-mail. Anyone else getting these ALL DAY LONG?
> >
> > http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594
> >
> >
> > Dave
>
> yes, to my phone of all things. i had to change my email address because my
> phone became unusable.
>
>
>

Not only that, but someone is using email addresses from this newsgroup
to do a little eBay phishing. Obviously, with my return address set to
what it is, they are caught fairly easily, but I'll have to admit that
some of them have been pretty convincing.

CS

"Charles Spitzer"

in reply to David on 18/05/2005 1:07 PM

18/05/2005 1:26 PM


"David" <[email protected]> wrote in message
news:[email protected]...
> I've wondered why I've been inundated with German language e-mail this
> past week. I just uncovered a news story about the Sober virus in German
> language e-mail. Anyone else getting these ALL DAY LONG?
>
> http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594
>
>
> Dave

yes, to my phone of all things. i had to change my email address because my
phone became unusable.

ND

"Norman D. Crow"

in reply to David on 18/05/2005 1:07 PM

20/05/2005 5:45 AM


"Mark & Juanita" <[email protected]> wrote in message
news:[email protected]...
> On Fri, 20 May 2005 04:19:35 GMT, justme <[email protected]> wrote:
>
>>In article <[email protected]>,
>>[email protected] says...
>>>
>>> "David" <[email protected]> wrote in message
>>> news:[email protected]...
>>> > I've wondered why I've been inundated with German language e-mail this
>>> > past week. I just uncovered a news story about the Sober virus in
>>> > German
>>> > language e-mail. Anyone else getting these ALL DAY LONG?
>>> >


Sure am glad my local ISP is so good. Started with them, stayed a long time,
tried cable for 3 mo., went back. They use a program called Vircom to
firewall the spam and stop the viruses. Does an excellent job, as I'll get
*maybe* one or two spam in a two week period. If I go to the ISP and check
the quarantine folder, it'll be crammed full, using FIFO to dump oldest into
bit bucket, making room for new junk.

--
Nahmie
The greatest headaches are those we cause ourselves.

LJ

Larry Jaques

in reply to David on 18/05/2005 1:07 PM

18/05/2005 6:21 PM

On Wed, 18 May 2005 13:07:27 -0700, the inscrutable David
<[email protected]> spake:

>I've wondered why I've been inundated with German language e-mail this
>past week. I just uncovered a news story about the Sober virus in
>German language e-mail. Anyone else getting these ALL DAY LONG?
>
>http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594

Mine started coming in last Sunday, on the 15th. The batch before that
started on the 5th of May. Let's all lobby Congress to make it legal
to draw and quarter spammers.


------------------------------------------
Do the voices in my head bother you?
------------------------------------------
http://diversify.com Full-Service Web Development

BM

"Buddy Matlosz"

in reply to David on 18/05/2005 1:07 PM

30/05/2005 10:47 PM



>
> A better way is to configure your browser so it does not give your
> email address out to web sites.
>
How's that done in OE?

B.

md

mac davis

in reply to David on 18/05/2005 1:07 PM

19/05/2005 10:10 AM

On Wed, 18 May 2005 13:07:27 -0700, David <[email protected]> wrote:

>I've wondered why I've been inundated with German language e-mail this
>past week. I just uncovered a news story about the Sober virus in
>German language e-mail. Anyone else getting these ALL DAY LONG?
>
>http://www.eweek.com/article2/0,1759,1816192,00.asp?kc=EWRSS03119TX1K0000594
>
>
>Dave

yeah.. only for one day, but there were maybe 30 of them.. all different but all
pointing to the same URL..
the worst part was that a few days later, I got a bunch of notices that "my"
emails bounced... it was the same German thing, sent out with my return
address..


mac

Please remove splinters before emailing


You’ve reached the end of replies