« Internet Explorer Exploit | Main | Bit Torrent joins the Dark Side »

November 23, 2005

A sobering thought

We've seen a ton of infected file messages over the past 24 hours, as the Fastmail anti-virus checker cuts virus-laden email off at the pass - all of them associated with the new variant of the Sober worm. We can't remember seeing this many for years. It takes us back to the bad old days, when people would believe anything, and click on anything.

What's depressing is that all these messages are coming from people who have clicked on an attachment to a message that purports to be from the CIA or the FBI. In terms of social engineering, it's mind-boggling. What possesses these people, in this day and age, that they really believe that the CIA or the FBI is going to send them a personal email ?

Posted by cw at November 23, 2005 07:26 PM

Comments

this dump of infected posts started reaching me..early hours Monday morning and thank goodness for Mailwasher..At the latest count, its collared over a thousand since then. ISPs are complaining net traffic is going thru the roof...and I see the CIA FBI IRS and other american institutions are copping the blame. My work has been copping up to 15 posts a minute and our Admin is worried. Just where is this stuff coming from??? :(

Posted by: Ian Smith at November 23, 2005 09:11 PM

Charles, I file the infection notices to Junk Mail, since I don't generally want to see them. If you want to do the same, click Options->Define Rules, and add a new rule to the 'Mailing lists/File into folders' with Look In: Advanced, and in 'For text matching' type:

header :is "subject" "Infected file rejected"

Finally, in 'File into folder' select 'Junk Mail'.

Posted by: Jeremy Howard at November 24, 2005 09:49 AM

You ask
"What possesses these people, in this day and age, that they really believe that the CIA or the FBI is going to send them a personal email?"

Three words - War on terror. The propaganda blitz for four years, plus the out-pourings from the military-industrial-entertainment complex, have obviously succeeded in inducing at least some of the population to identify with this fantasy world. More than a few judging by election results.

Me, I'm not clicking the attachment until I get something from Osama personally. The Sober Bin Laden worm, I'd like to see that.

Posted by: tflip at November 24, 2005 10:35 AM

Jeremy,

Would it be possible to add an X-Virus-Detected header? That way I could see the actual email.

cheers, Stuart

Posted by: stu at November 25, 2005 11:18 AM

Post a comment




Remember Me?



(you may use HTML tags for style)