Skip to Main Content

UW home

Sidebar Site Navigation

Information Technology Hot Pages


Up-to-Date System Information:

Virus email bombardment

posted 2/24/2016 11:40:14 AM
closed 2/25/2016 7:54 AM

Who is affected?

Any user with email should not open any messages they receive with a subject of 'Scanned image' from an email address that starts with the name of 'southlands'

Problem:

Virus email bombardment

Systems Involved:

Other

Details:

For the past hour the Administrative Systems and Enterprise Systems teams have been monitoring a large number of messages coming in with the subject 'Scanned image' and a sender address of the form 'southlandsxyz@uwyo.edu', where xyz is a number.  These messages are currently being quarantined by the Sophos appliance, and those that make it through because the user has opted-out of Sophos quarantining have been caught by virus detection on Office 365.

As of the last check there were 67 IP addresses around the world sending these messages to UW users.  So far over 300 UW users have been targeted.

Our virus protection systems are working and mitigating this threat, but there is the possibility a message may slip through if the virus payload changes.

Updates:

2/25/2016 7:55:02 AM:
The email barrage stopped yesterday afternoon.

2/24/2016 3:10:54 PM:
This incident is still on going.

Problem Resolution: 

IT personnel are investigating the problem. No estimated time for correction of the problem is currently available.

Information Technology apologizes for any inconvenience this may cause you. Please contact your departmental consultant, call the Help Desk at 766-HELP (4357), option 1, or send an email to the Help Desk (userhelp@uwyo.edu) if you have any questions.

 

Priority Levels:

High -- (affects a majority of campus and/or applications used by a majority of campus) – updated hourly

Medium -- (affects a substantial portion of campus and/or applications used by them) – Updated every 2 hours

Low -- (affects or minimal portion of campus and/or has minimal impact on applications used on campus) – Updated every 4 hours

None -- (minimal to no urgency associated with resolving the incident/event) – Will update when resolved.

Footer Navigation

University of Wyoming
 
1000 E. University Ave. Laramie, WY 82071 // UW Operators (307) 766-1121 // Contact Us