極楽せきゅあブログ

ときどきセキュリティ

コンフリッカー対策ソフトウエアというのがマイクロソフトさんから来た

もちろん、そんなわけはなくて(笑)。
文面はこんな感じ。

Subject:Conflicker.B Infection Alert

Dear Microsoft Customer,

Starting 12/11/2009 the 舛onficker・worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.

To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division

ヘッダはこんな感じ。

Return-Path: 
X-Spam-Checker-Version: SpamAssassin 3.1.9 (2007-02-13) on ns.tuplet.jp
X-Spam-Level: ***********
X-Spam-Status: No, score=11.6 required=13.0 tests=AFRINIC,BAYES_99, CONTENT_TYPE_PRESENT,UNPARSEABLERELAY99,UNPARSEABLE_RELAY,X_MAILER_PRESENT autolearn=no version=3.1.9
X-Original-To: ほげ
Delivered-To: ふが
Received: from XHTPIPS (unknown [41.252.7.179])
 by ほげほげ (Postfix)
 with ESMTP id 1A10440048;
 Thu, 18 Feb 2010 02:10:31 +0900 (JST)
Received: from 41.252.7.179
 by mail.route254.com;
 Wed, 17 Feb 2010 19:09:38 +0200
Message-ID: <000d01caaff3$fcba4520$6400a8c0@mellifluous475>
From: "Microsoft Team" <ふがふが>
To: <ふがふが>
Subject: Conflicker.B Infection Alert
Date: Wed, 17 Feb 2010 19:09:38 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_0006_01CAAFF3.FCBA4520"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180

ほげやらふがやらはあっし側のメールアドレス。
添付ファイルの解析結果はこちら。見事ウイルスでした。
今どき珍しくもないけど、いちおうブログに晒しておこうと思って。