Channel News and Analysis - Channel Insider
 
 

New Sober Worm on the Loose


Article Rating:starstarstarstarstar / 0

Rate This Article:
Add This Article To:
A new version of the Sober worm is having quite a bit of success infecting users in Europe through the use of social engineering.

A new version of the Sober worm appeared on the Internet early Friday morning and already it is having quite a bit of success infecting users in Europe through the use of social engineering.

Sober.J arrives in an e-mail message that appears to be a returned-mail error message, telling the user that an e-mail sent earlier has bounced. The message typically contains a .zip, .bat, .com, .scr or .pif attachment and a body text that is some variation on the following:

This mail was generated automatically.More info about --YAHOO-- under: http://www.yahoo.com-------
Occured_Errors:178.218.194.86_
does_not_like_recipient.# 185:
MAILBOX NOT FOUND# 144:
Giving_up_on_178.218.194.86.# 533:
This_account_has_been_discontinued_
[#413].End-------
The original mail is attached.Auto_Mail.System: [yahoo]

The subject line of the e-mail message varies, but often indicates that the message is a warning about a bounced e-mail, such as:

Delivery_failure_notice
Faulty_mail delivery
Mail_delivery failed

When the recipient opens the attachment, the worm displays a fake error message saying that a portion of the WinZip software is missing. The worm then copies itself to the Windows System folder in two separate locations, using filenames that it constructs dynamically from a small set of common strings, including sys, spool, crypt, host, dir, service, win, run, 32, data, and a few others, according to an analysis by McAfee Inc., based in Santa Clara, Calif. The filename always ends in "exe."

Sober.J then creates several registry keys to ensure it will be run on startup and searches for e-mail addresses on the infected machine. It then begins mailing itself to all of the addresses it finds.

Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.



Discuss New Sober Worm on the Loose
 
>>> Be the FIRST to comment on this article!
 

 
 
>>> More Channel News and Analysis Articles          >>> More By Dennis Fisher
 


 

Vizard: IBM Gets Principled About the Channel
Big Blue looks to improve its reputation with a Principles of Engagement document governing how internal salespeople deal with the channel.

CHANNEL DEEP DIVES
CareersLinux and Unix
Computer NetworkingPrinters
SecuritySMB Partner
StorageSurveys
Solution BuilderMessaging/Collaboration
Dell ResellersMicrosoft Partners

SIGN UP FOR CHANNEL INSIDER NEWSLETTERS
Reliable, timely information on the business of technology. Sign up now.


 

CHANNEL RESOURCE CENTER
HP StorageWorks Scalable NAS is highly available, scalable network-attached storage for any industry solution. To learn how you can take full advantage of fault-tolerant NAS that seamlessly scales capacity and performance, visit: http://www.hp.com/go/scalablenas


Feature Video: What Can Green Do For You?
There are many ways that systems can be run faster or more efficiently, using less energy and thereby reducing costs. Watch now!
Microsoft-hosted solution offers you advanced customer relationship management capabilities without a major investment in IT and staffing.
Try It for free for 30 days!