We are pushing out an update with a number of rules to catch this bug. I did not find any references to the content on google - so it might be new. The contents of the message (modified) are below. Do not follow the link - I have obscured it with spaces for safety. There may be (probably will be) variants.

The content at the end of the link appears to be an encrypted html using the objec data exploit.

You will probably want to take some steps to prevent your users/customers from following the link. The message was sourced to us with very specific addressing using a machine listed in CBL.

Hope this helps.
_M

--- Dangerous content follows ---

Received: from mnr1.microneil.com [216.88.36.96] by MicroNeil.com with ESMTP
  (SMTPD32-6.05) id A80711F7002A; Fri, 23 Apr 2004 09:20:07 -0400
Received: by mnr1.microneil.com (Postfix, from userid 93)
        id 1301029C170; Fri, 23 Apr 2004 09:19:46 -0400 (EDT)
Received: from 216.88.36.96 (unknown [66.98.252.37])
        by mnr1.microneil.com (Postfix) with SMTP
        id 911DB29C037; Fri, 23 Apr 2004 09:19:45 -0400 (EDT)
Received: from 8.82.83.82 by ; Fri, 23 Apr 2004 10:18:17 -0400
Message-ID: <[EMAIL PROTECTED]>
From: "Boyd Wise" <[EMAIL PROTECTED]>
Reply-To: "Boyd Wise" <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED], [EMAIL PROTECTED]
Subject: Osama Bin Laden Captured.
Date: Fri, 23 Apr 2004 15:20:17 +0100
MIME-Version: 1.0
Content-Type: multipart/alternative;
        boundary="--59654854181797364"
X-Priority: 3
X-IP: 162.164.96.180
X-Declude-Spoolname: D180702a.SMD
X-RCPT-TO: <[EMAIL PROTECTED]>
X-UIDL: 382729173
Status: U

Content-Type: text/html;

Just got this from CNN Osama Bin Laden has just been captured! A video and some pictures have been released. Goto the link below for pictures, I will update the page with the video as soon as I can:
http:/ / 220 . 95 . 231 . 54 /pics/ God Bless America!



This E-Mail came from the Message Sniffer mailing list. For information and (un)subscription instructions go to http://www.sortmonster.com/MessageSniffer/Help/Help.html

Reply via email to