瀏覽單個文章
線材王
Major Member
 
線材王的大頭照
 

加入日期: Sep 2001
文章: 156
Netsky 駭蟲第十、十一代再現,使用者須小心 *.pif 信件附加檔案

Netsky 駭蟲目前在網路上有蔓延狀態,提醒使用者對於.exe, .scr, .pif, .com, .bat, .lnk 之信件附加檔案都要小心提防,Netsky 駭蟲信件不含漏洞,除非使用者執行附加檔案才有中毒可能。

金帥提醒使用者,近期內收到英文主旨、英文內文以及.exe, .scr, .pif, .com, .bat, .lnk的附加檔案,切勿直接開啟,將可大大降低中毒機會。

Netsky 網路天空 第十代變種駭蟲信件:
主旨:
Your product
Your letter
Re: corrected homework
Re: I've found your document
Re: Your bill
Re: hello again
Re: hi again
Re: part 3
Re: important document part 2
Re: important
Re: Your data
Re: Your application
Re: your music
Re: excel document
Re: Re: Re: word document
Re: Your details
Re: My details
Re: Your requested file
Re: Read it immediately
Re: Approved
Re: Your software
Re: my memberlist
Re: Your document
Re: Your file
Re: Your important document
www.%s.tripod.com
Hi Mr. %s
Moi %s
He %s
Yours faithfully, %s
Message to %s
Hi Mrs. %s
Is %s.doc yours?
Is %s.xls yours?
Whats up %s
www.paypal.com/%s
Na %s
Best %s
Love %s
Good morning %s
Have a good day %s
Dear %s
To %s , it's me
Welcome %s
Moin %s
Hello %s
Your account %s is expired!
Hey %s
Hi %s
www.%s.freepage.com, your website
Hi %s, your product
Hello %s, your letter
Re: Hi %s, your archive
Re: %s, your text
Re: Hello %s, your bill
Re: Hi %s, your details
Re: Hello %s, my details
Re: Hi %s, your word file
Re: Hello %s, your excel file
Re: Hi %s, details
Re: Hello %s, Approved
Re: Hello %s, your software
Re: Hi %s, your music
Re: Dear %s, Here
Re: Re: Re: Hello %s, your document
Re: Hi %s
Re: Dear %s, Hi
Re: Re: Hi %s, your message
Re: Here %s, your picture
Re: Hi %s, here is the document
Re: Hello %s, your document
Re: %s, thanks!
Re: Re: %s, thanks!
Re: Re: Hi %s, document
Re: Hello %s, document

註:%s可能顯示為您的email帳號名稱

內文:
My details are in the attached file.
I have corrected your document.
Please do not forget to read the important document.
I have an interesting document about you.
The sample is attached.
Your personal document is attached.
Your file is attached to this mail.
Note that I have attached your file.
The important document is attached.
Please read the document. It's important.
Your document is attached to this mail.
See the attachment for further details.
Your file is attached. Use this password for the file: %i.
Please read the attached file. Password for the file is %i.
Please have a look at the attached file. Password for decrypting is %i.
See the attached file for details. Password is %i.
Here is the file. My password is %i.
Your document is attached. Your password is %i.

附加檔案:*.pif(檔案大小 27468位元組)

Netsky 網路天空 第十代變種駭蟲行為:
1.大量發送駭蟲信件。
2.執行駭蟲後,會將駭蟲本身複製到 Windows\Avpguard.exe(NT/2000/XP系統為 WinNT\Avpguard.exe)。
3.修改登錄檔,使開機即啟動駭蟲。
4.嘗試刪除 Mydoom 駭蟲所寫入的登錄檔案,如此Mydoom駭蟲即不會啟動。


Netsky 網路天空 第十一代變種駭蟲信件:
主旨:
Re: Your website
Re: Your product
Re: Your letter
Re: Your archive
Re: Your text
Re: Your bill
Re: Your details
Re: My details
Re: Word file
Re: Excel file
Re: Details
Re: Approved
Re: Your software
Re: Your music
Re: Here
Re: Re: Re: Your document
Re: Hello
Re: Hi
Re: Re: Message
Re: Your picture
Re: Here is the document
Re: Your document
Re: Thanks!
Re: Re: Thanks!
Re: Re: Document
Re: Document

內文:
Your file is attached.
Please read the attached file.
Please have a look at the attached file.
See the attached file for details.
Here is the file.
Your document is attached.

附加檔案:*.pif (檔案大小 22016位元組)

Netsky 網路天空 第十 一代變種駭蟲行為:
1.大量發送駭蟲信件。
2.執行駭蟲後,會將駭蟲本身複製到 Windows\WINLOGON.EXE (NT/2000/XP系統為 WinNT\WINLOGON.EXE )。
3.修改登錄檔,使開機即啟動駭蟲。
4.嘗試刪除 Mydoom 駭蟲所寫入的登錄檔案,如此Mydoom駭蟲即不會啟動。
 
__________________
kingCable
舊 2004-03-27, 01:43 PM #22
回應時引用此文章
線材王離線中