# Flood of "returned mails": WTF?

**URL:** <https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361>\
**Category:** Factual Questions\
**Created:** [August 20, 2003, 3:50am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361 "2003-08-20T03:50:16Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![El\_Kabong](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/el_kabong/32/496_2.png) [@El\_Kabong](https://boards.straightdope.com/u/El_Kabong)\
**Post date:** [August 20, 2003, 3:50am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/1 "2003-08-20T03:50:16Z")

</div>

OK, I’m a bit spooked. In the past 24 hours every E-mail account to which I am currently subscribed has begun filling up with messages from random other accounts, stating that they are returning messages rejected because they contain a virus or worm.

The majority of the ‘returns’ quote one of the following subjects lines:

Thank You!  
Approved  
Details  
Your Application

Most say they were delivered to the recipients with a file attached, the most common file name is:

document\_all.pif

The truly weird thing is that these are coming in via all four of the completely unrelated accounts to which I have subscriptions, and of which only one uses Outlook, AFAIK the most common virus remailer target, as an E-mail client. The accounts affected including a Hotmail account, a Compuserve account, my company E-mail, and another company E-mail account in which my name does not appear. According to their headers the rejected messages originated from my accounts.

Anyone have a clue what the hell is going on?

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [August 20, 2003, 4:18am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/2 "2003-08-20T04:18:27Z")

</div>

It’s most likely the klez worm virus or a variant of it trying to spread itself. It tries to spoof your email address and sends it to harvested email addresses. I get a bunch of these too.

---

<div class="post-metadata">

**Author:** ![biqu](https://avatars.discourse-cdn.com/v4/letter/b/7feea3/32.png) [@biqu](https://boards.straightdope.com/u/biqu)\
**Post date:** [August 20, 2003, 4:32am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/3 "2003-08-20T04:32:25Z")

</div>

[relevant slashdot article](http://slashdot.org/articles/03/08/19/1748206.shtml?tid=109&tid=111&tid=126&tid=128&tid=187)

The headers on the trojan-carrying messages were probably spoofed. If your username is pretty common, it can happen with greater frequency than most people experience.

Mail servers are incredibly naive, believing the header information despite the fact that most spammers and malware authors do not use their real return addresses when sending their junk. So they’ll bounce a message back to you even if you did not in fact send it, just because your address was listed as the return address. The other option is for the mail server to delete the message without bouncing, but the risk of false positives is sometimes too great to warrant deletion without notification as the default behavior.

---

<div class="post-metadata">

**Author:** ![SmackFu](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@SmackFu](https://boards.straightdope.com/u/SmackFu)\
**Post date:** [August 20, 2003, 4:47am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/4 "2003-08-20T04:47:53Z")

</div>

I had to talk my officemate down for this problem this morning. He was freaking out, man.

So as far as I can tell, it pulls the forged From address header from your address book. So someone who’s mailed you has the virus, not you. For four different accounts, it could be four different people infected.

It is, to put it mildly, rather aggravating.

---

<div class="post-metadata">

**Author:** ![Larry\_Mudd](https://avatars.discourse-cdn.com/v4/letter/l/f14d63/32.png) [@Larry\_Mudd](https://boards.straightdope.com/u/Larry_Mudd)\
**Post date:** [August 20, 2003, 5:44am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/5 "2003-08-20T05:44:24Z")

</div>

The trick is to pay attention to where the messages are being bounced _from_, and ask yourself “who do I know that also knows these people?”

Then make sure the person is alerted to the problem. This [happened to me](http://boards.straightdope.com/sdmb/showthread.php?s=&threadid=189945), and I was eventually able to work out who had the bug by the types of mailing-lists they were on, and send them an e-mail with removal instructions.

It sounds to me like Sobig.f is the likely culprit in your case.  
[Info here](http://www.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html)

[Removal Tool here](http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.f@mm.removal.tool.html)

---

<div class="post-metadata">

**Author:** ![El\_Kabong](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/el_kabong/32/496_2.png) [@El\_Kabong](https://boards.straightdope.com/u/El_Kabong)\
**Post date:** [August 20, 2003, 11:13am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/6 "2003-08-20T11:13:53Z")

</div>

OK, got it. Checked Symantec’s site and it is in fact SOBIG.F. Thanks for the comments.

---

<div class="post-metadata">

**Author:** ![jjimm](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jjimm](https://boards.straightdope.com/u/jjimm)\
**Post date:** [August 20, 2003, 11:16am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/7 "2003-08-20T11:16:34Z")

</div>

This happened to me this morning. Not our fault, and I can’t track down who’s actually got the bug (since it’s my company’s info@ address that’s being referenced, and thousands of people have that). It’s a bit embarrassing for our company, though.

---

<div class="post-metadata">

**Author:** ![Charlie\_Tan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/charlie_tan/32/12582_2.png) [@Charlie\_Tan](https://boards.straightdope.com/u/Charlie_Tan)\
**Post date:** [August 20, 2003, 12:32pm UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/8 "2003-08-20T12:32:27Z")

</div>

Happening here too, with one of my accounts. Problem is, all the messages are **big**. Between 100kb and 350kb. There is one new, every five minutes.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [August 20, 2003, 12:59pm UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/9 "2003-08-20T12:59:34Z")

</div>

I checked my e-mail at work on the web. I got a ton of those messages, which I deleted without opening. I don’t get them at home because they are filtered out by my spam blocker. (I still get too much spam, though.)

I have been running Norton Anti-Virus for a long time. I have Live Update, so it stays current. It ran every Sunday. Yesterday I manually downloaded the latest code (i.e., I manually ran Live Update) and changed my virus checker scheduler to run every day.

Question: Will Norton catch these? (I heard that some viruses are hidden in ZIP files that virus checkers don’t catch. FWIW, I don’t open attachments.)

---

<div class="post-metadata">

**Author:** ![Capt\_B.Phart](https://avatars.discourse-cdn.com/v4/letter/c/9fc29f/32.png) [@Capt\_B.Phart](https://boards.straightdope.com/u/Capt_B.Phart)\
**Post date:** [August 20, 2003, 1:09pm UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/10 "2003-08-20T13:09:24Z")

</div>

Just checking, - you are running a Firewall aren’t you? (if you’re not behind a company one)  
[Zone Alarm](http://www.zonelabs.com/store/content/home.jsp) is free and stops untrusted programs emailing out or acting as servers.  
Won’t help if the virus is on someone else’s box and your address is being spoofed of course.

Sorry if this is a Granny/Egg-sucking thing but the [Blaster RPC Worm](http://boards.straightdope.com/sdmb/showthread.php?threadid=204058) shows that a lot of people **still** aren’t behind firewalls

---

<div class="post-metadata">

**Author:** ![CurtC](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@CurtC](https://boards.straightdope.com/u/CurtC)\
**Post date:** [August 20, 2003, 1:27pm UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/11 "2003-08-20T13:27:17Z")

</div>

I’ve received about 350 of these messages since yesterday evening at my personal e-mail address. I checked the Symantec site first thing I saw them last night, and it tells you what the Sobig worm puts on your system - a file in the Windows folder, and an entry in the registry. My computer had neither of these, so I think I’m not to blame for any of it.

Interestingly, not one of the messages I received had an attachment - they were all just one line of text, saying something like “Please look at the attached file.” I guess my mail server stripped the attachment.

And no, Norton AV probably won’t help you avoid these, because they come out so quickly. You just need to be very careful not to run e-mail attachments.

---

<div class="post-metadata">

**Author:** ![Lsura](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lsura](https://boards.straightdope.com/u/Lsura)\
**Post date:** [August 20, 2003, 1:29pm UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/12 "2003-08-20T13:29:22Z")

</div>

> [@](#):
>
> \*Originally posted by Capt B. Phart \*  
> \*\*Just checking, - you are running a Firewall aren’t you? (if you’re not behind a company one)  
> \*\*

We’ve been getting them here through the school e-mail (web based) as well, since yesterday. I do run a firewall, I’ve updated Norton last night, ran a scan and it found nothing.

There are fewer so far this morning, but it still concerns me that my e-mail address is being used somehow. After my first class (starts in half an hour), I’m going to pop over to the computer center on campus and see what they can tell me - just to make sure that it’s not my computer.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [August 21, 2003, 3:39am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/13 "2003-08-21T03:39:28Z")

</div>

The sobig.f worm has exploded over the last two days, and has even made the major news services. I had been resisting use of a filter, but when the number of bad emails sent to me reached 55 per hour (and at 80KB per, that’s over 4MB!) I felt I had to activate the virus filter.

_But the tools the ISPs use are one step behind the virus writers._ The virus filter mine uses, “postini,” lets all “returned mail” messages through, and a spoofed returned mail is just one of the sobig’s tricks.

Also, even tho many ISPs scan email sent to/from their customers, the scanners return the bad mail TO THE ADDRESS IN THE HEADER, which in 100% of these cases, IS NOT THE ADDRESS IT CAME FROM!!

So the filters are responsible for perpetuating the mess. You can’t win.

---

<div class="post-metadata">

**Author:** ![Brad\_Amundsen](https://avatars.discourse-cdn.com/v4/letter/b/dbc845/32.png) [@Brad\_Amundsen](https://boards.straightdope.com/u/Brad_Amundsen)\
**Post date:** [August 21, 2003, 3:48am UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/14 "2003-08-21T03:48:26Z")

</div>

IT IS ABSOLUTELY “SOBIG” GO TO [SYMATEC.COM](http://SYMATEC.COM) THEY SHOW YOU HOW TO REMOVE IT!! IF YOU HAVE OPENED ANY OF THESE EMAILS YOU’VE GOT IT

---

<div class="post-metadata">

**Author:** ![CurtC](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@CurtC](https://boards.straightdope.com/u/CurtC)\
**Post date:** [August 21, 2003, 1:09pm UTC](https://boards.straightdope.com/t/flood-of-returned-mails-wtf/196361/15 "2003-08-21T13:09:30Z")

</div>

The first several hundred of these that I got were just one line, something like “Please see the attached file,” with no attachment, so they downloaded quickly and I could delete them easily. Then last night, they suddenly started coming in with a 70-odd Kbyte attachment on each one. It took a couple of hours to download my e-mail because of that (I had 200 more last night).

What could explain that? It would seem that a filter used by my ISP’s mail server might let the first ones through, then delete the attachment from later ones, not the other way around. The first one that came through with an actual attachment was probably number 400 that I received.
