Digg this story   Add to del.icio.us  
FBI Tracking LoveLetter Worm
Kevin Poulsen, SecurityFocus 2000-05-04

A new Melissa-style email virus is spreading globally, and it loves you not.

The FBI's National Infrastructure Protection Center (NIPC) this morning issued an advisory on a new virus that's rapidly spreading through email messages with the subject "ILOVEYOU," and the body "kindly check the attached LOVELETTER coming from me."

The "love letter" is an attachment titled LOVE-LETTER-FOR-YOU.TXT.vbs. It is a decidedly unromantic Visual Basic script, which, if executed, sends a single copy of itself to every email address in the victim's Microsoft Outlook address book -- the same tactic used with devastating success by the Melissa virus in March, 1999.

The program also attempts to propagate over Internet Relay Chat, and it writes itself over other programs on a victim's hard drive, while replacing files with common point-and-click extension like .mp3 with deceptively named decoy copies of itself, according to analysis by vendors and computer security experts.

Dow Jones News Wire reported this morning that the virus has hit PR firms and investment banks in Asia particularly hard. Various reports say the virus has been spotted in Europe, the U.S. and Canada. Anti-virus software vendor Symantec reports hundreds of thousands of machines infected worldwide, and an advisory from the U.S. Defense Department's Computer Emergency Response Team said the program has already affected U.S. Army mail servers.

The Washington-based NIPC issued an alert at 11:00 a.m. Eastern time. "We are currently assessing the impact that the virus is having nationally and worldwide," said FBI spokesperson Debbie Weierman. "That's all I can say at this time."

Within the virus code the author identifies his or herself as "spyder" from Manila, Philippines, with an email address of ispyder@mail.com. The author dates the code March, 2000. Another comment in the program reads, "i hate go to school." Spyder did not immediately answer an email inquiry Thursday morning.

In addition to spreading virulently, the worm also attempts to download and execute another program from any one of four web accounts hosted by Sky Internet, a Philippine ISP. "We're aware of that, and our network security people are taking the necessary actions of disabling the URLs that are sent by email," said Ronald Elciario, Network Administrator at Sky Internet.

"Our service was used as a gateway for the virus to spread out over the net," said Elciario. "We've been receiving calls from all over the world, mostly from the USA."

    Digg this story   Add to del.icio.us  
Comments Mode:
Outlook Express sucks 2000-05-04
Anonymous (5 replies)
Outlook Express sucks 2000-05-04
Anonymous (2 replies)
Outlook Express sucks 2000-05-05
Anonymous
Outlook Express sucks 2000-05-06
Anonymous
Outlook Express sucks 2000-05-04
Anonymous
Responsibility is with IT managers and ISPs 2000-05-04
Anonymous (5 replies)
no 2000-05-04
Anonymous
Responsibility is with IT managers and ISPs 2000-05-04
Duane Verzone <dverzone (at) tampabay.rr (dot) com [email concealed]> (2 replies)
Outlook Express sucks 2000-05-04
Anonymous (1 replies)
Outlook Express sucks 2000-05-05
Anonymous
R.E. Outlook Express sucks 2000-05-05
Anonymous
Save your self!!! 2000-05-04
Anonymous
re: I love you VBS 2000-05-04
Anonymous
Re: 2000-05-04
Anonymous
Love bug is that simple it's impressive 2000-05-04
Anonymous (3 replies)
100% Right ! 2000-05-04
Anonymous
- could someone post code ?? 2000-05-06
Anonymous
Outlook Express "Message Rules" 2000-05-04
Anonymous (1 replies)
Outlook Express 2000-05-05
Anonymous
kill more trees 2000-05-04
Anonymous
starved of love... 2000-05-04
Anonymous
Re : IMMUNITY TO ViRUS 2000-05-05
Anonymous (1 replies)
Re : IMMUNITY TO ViRUS 2000-05-05
Anonymous
i love you 2000-05-05
Anonymous
Lotus Notes 2000-05-05
Anonymous (1 replies)
Lotus Notes 2000-05-05
Anonymous
Virus hits Europe very hard, too! 2000-05-05
Anonymous
Where is the problem ? 2000-05-05
Joe Dauncey <toothbrushhead (at) yahoo (dot) com [email concealed]> (2 replies)
Where is the problem ? 2000-05-05
Anonymous (2 replies)
Where is the problem ? 2000-05-05
Anonymous
Where is the problem ? 2000-05-05
Anonymous (1 replies)
Where is the problem ? 2000-05-05
Anonymous
Where is the problem ? 2000-05-06
Anonymous
Something to think about. 2000-05-05
Anonymous (1 replies)
Something to think about. 2000-05-05
Anonymous (1 replies)
Something to think about. 2000-05-08
Trey <mr_spaz (at) juno (dot) com [email concealed]>
Just don't use the vunerable products. 2000-05-05
Anonymous (1 replies)
This is just the first of many new ways. 2000-05-05
Anonymous (1 replies)
Modifacations are endless 2000-05-08
Anonymous
Suspect found: Bill Gates 2000-05-08
Anonymous (2 replies)
Suspect found: Bill Gates 2000-05-08
Anonymous
Virus 2000-05-11
Anonymous
Question 2000-05-12
Anonymous


 

Privacy Statement
Copyright 2010, SecurityFocus