Topics
General News
Antivirus Reviews
Network Defense
Spyware
Anti-Spam
Phishing Scams
Virus Alerts
Security Forums
Desktop Security
Malware Removal Help
Spam Blocking
Patches and Hotfixes

Network Security
Firewalls and Routers
Intrusion Detection
Web Proxies

Antivirus Support
Symantec
McAfee
Trend Micro
Other Antivirus
Quick Resources
About Antisource
Malware Threats Triangle
Free Virus Scan
Virus Map
 

Sober at it again

Thursday, May 05, 2005
Author: Richard S. Westmoreland
Permalink: sober-worm
Virus Alerts
Email Article to a Colleague Printer-Friendly Version Author's Profile


It still amazes me that email worms continue to be such a prolific menace to mail systems worldwide. Their avenue of replication typically depends on user intervention. The receiver of the email opens the attachments which infects their system. That infected system then sends out copies of the worm to all of the recipients in his/her address book. The point is that the virus is not spread through some flaw in the operating system - it is people's curiosity and lack of caution that starts outbreaks.

The newest worm is designated as Sober.O by Symantec, Sober-N by Sophos, and Sober.P by Mcafee and F-Secure. Trend Micro has jumped ahead a few letters to name it WORM_SOBER.S.

ZDNet reports that this newest variant spread rapidly to consist of 77% of all viruses as detected by Sophos. The emails are generated either in English or in German. Sophos reports that some of the message bodies aim to entice World Cup fans.

F-Secure provides a good description of Sober. The email will use one of the subjects:

Re: Your Password
Re: Registration Confirmation
Re: Your email was blocked
Re: mailing error
FwD: Ihr Passwort
FwD: Ihre E-Mail wurde verweigert
FwD: Ich bin's, was zum lachen ;)
FwD: Glueckwunsch: Ihr WM Ticket
FwD: WM Ticket Verlosung
FwD: WM-Ticket-Auslosung

And the message body will contain:

Account and Password Information are attached!
Visit: http://www.[collected_url].com

This is an automatically generated E-Mail Delivery Status Notification.
Mail-Header, Mail-Body and Error Description are attached
Attachment-Scanner: Status OK,AntiVirus: No Virus found,Server-AntiVirus: No Virus (Clean)


[collected_url] will be replaced by a domain Sober has recorded. The attached file is a zip file containing a 52kb exe. Once run, a fake prompt will display "Error: CRC not complete". It then creates the following files: services.exe, csrss.exe, smss.exe, packed1.sbr, packed2.sbr, and packed3.sbr.  



Comment about Sober at it again | 1 comments |

The following comments are owned by whomever posted them. This site is not responsible for what they say.

Sober at it again
Authored by: mechBgon on Thursday, May 05, 2005



Some people are completely clueless that there is a threat in the first place. I got a call from a friend of my boss asking for help with his home network. So I went over there, and if it could be wrong, it WAS wrong.

Wireless LAN. Security: Off. It is some piece-of-junk ActionTec gateway where the "firewall" settings are "basic, low, medium, high," whatever that means.

Computers had not been patched since 2001, only one system had antivirus software, there was adware, spyware, viruses, Trojans and dialers on the son's computer, and adware/spyware on the others. The son's computer quit connecting to the Internet, and that's what got Dad to call me, as it turned out.

So it was just a wake-up call at how much I've been assuming people know, versus how much the average homeowner really does know. I could see these people opening ANYTHING in their email. :P


Reply to This