Did you get this email?

I did, too. — You Have Recieved A Hallmark E-card

Something about it was suspicious. Probably it was the mis-spelling of “received” that tipped me off. I before e except after c, and all.

I deleted it, along with several dozen others that managed to slip by the spam filter.

Tim Fehlman did some investigating. The results are found in his post at DCoT: “Anatomy of a Virus.”

This file gave all of the users under the [users] section elevated privileges on the system. It also automatically connected to several different servers and joined some channels.

While I was not able to completely determine what this would have done due to time constraints, I firmly believe that this would have given certain people the ability to remotely execute some commands on my machine.

Great work. Thanks, Tim.

One Response

  1. Nope.
    I don’t allow other users or sharing anyway.
    Still, I’m always suspicious when I get something from someone I don’t know.

Comments are closed.

Follow

Get every new post delivered to your Inbox.

Join 142 other followers