(keitai-l) Re: w32.sobig

From: Jonas Petersson <zap_at_xms.se>
Date: 08/25/03
Message-ID: <3F4A154B.25227064@xms.se>
Hi Greg,

Pretty good sender domain...

Greg Conquest  <conquest@spamcop.net> wrote:
> From: "Jonas Petersson" <zap@xms.se>
> > Yup, same here. It's pretty obvious that it is a member of this list.=

> > In my case the offending IP address is client4.shecom.co.jp
> > (218.44.132.46).
> =

> I haven't received any (I'm fairly sure.) No blocked messages due to
> attachements either. So, you guys are sure its coming from a member of =
this
> list?

Well, I've only received about 10 yet (all during the night MET-1DST)
plus two of the bouncing kind, so it's quite possible that it was
strangled quickly. Still, it would have to be a Windows user in Japan
with letter from me in his inbox, and I can't really see how that could
happen unless it came from this list... (Yes, I'm on a few more lists,
but they are rather non-jap and/or non-Windows...) I wouldn't have
bothered to mention it if it had only happened to me, but since I wasn't
alone I had to do the "Me Too!" ;-)

> Wouldn't we all get the messages, or does SoBig is send messages only
> to some addresses it finds on the host system's hard drive?

I haven't dissected it myself (I don't use Windows in my work so I'm not
really bothered), but I would assume that in order to stay off the radar
it can't really send to EVERYONE continously (it's a 100KB message), but
just picks a few at a time from the inbox so if you haven't posted
recently you may be lucky...

				/ Jonas
-- =

Jonas Petersson  |  XMS Penvision  |  mailto:Jonas.Petersson@xms.se
Box 3294, V=E4stg=F6tegatan 13, S-600 03 Norrk=F6ping | http://www.xms.se=
/
Tel: +46 11 400 13 00 | Dir: +46 11 400 13 05 | Fax: +46 11 10 30 50
Received on Mon Aug 25 17:02:27 2003