Skip to main content

The Melissa Virus (week 6)

In 1999, David L. Smith released the macro virus known as W97M/Melissa.A@mm, aka the Melissa virus. This virus infected thousands of computers that utilized Microsoft Outlook. The virus was spread through email with a word attachment. The email had a format that looked like the text below. (We Live Security, 2016)



The document used a name of an exotic dancer, which Smith says was a bit of social engineering to get people to open the attachment. Once the user had downloaded the attachment and opened it, the virus went to work. It disabled the program’s macro security, slowed the processes of Outlook significantly, infected documents on the machine, and then sent itself to up to 50 addresses in the users email address list. Using these addresses, it would send itself to new victims under the guise of the previous victim. This got more people to open the attachment since it was from someone they trusted. (We Live Security, 2016)

The damage caused by the virus were more substantial than expected. Damages and loss of productivity brought the total costs to be around 80 million dollars. The FBI believes that this could have been substantially higher if Smith was not apprehended. At his trial, Smith admitted that he was not aware that the virus would spread so quickly or cause so much damage. He initially intended for the virus to be a practical joke. Smith pleaded guilty, sentenced to 20 months in prison, fined $5,000, and ordered to “not be involved with computer networks, the internet, or internet bulletin boards unless authorized by the court”. (We Live Security, 2016)

 


We Live Security. (2016, July 15). Flashback Friday: The Melissa Virus. Retrieved from We Live Security: https://www.welivesecurity.com/2016/07/15/flashback-friday-melissa-virus/

Comments