virus
virus
R E L A T E D   C O N T E N T
ADVERTISEMENT

Sober.c more toxic than first thought

McAfee upgrades status of bilingual worm

Robert Jaques, vnunet.com 22 Dec 2003
ADVERTISEMENT

The McAfee Anti-Virus Emergency Response Team (Avert) has today increased its original low-risk threat assessment of the 'moderately prevalent' Sober.c worm to 'medium risk' status.

Sober.c contains its own SMTP engine and targets email addresses which it harvests from the victims' machines.

Once activated, it emails itself to the user's Microsoft Outlook address book with outgoing messages constructed using its SMTP engine. The messages may be written in either English or German, and the attachment filename can vary.

Users should immediately delete any email containing the following:

Subject:

  • Betr: Klassentreffen
  • Testen Sie ihren IQ
  • Bankverbindungs- Daten
  • Neuer Dialer Patch!
  • Ermittlungsverfahren wurde eingeleitet
  • Ihre IP wurde geloggt
  • Sie sind ein Raubkopierer
  • Sie tauschen illegal Dateien aus
  • Ich hasse dich
  • Ich zeige sie an!
  • Sie Drohen mir
  • you are an idiot
  • why me?
  • I hate you
  • Preliminary investigation were started
  • Your IP was logged
  • You use illegal File Sharing ...
Attachment:
  • www.iq4you-german-test.com
  • www.freewantiv.com
  • www.free4manga.com
  • www.free4share4you.com
  • www.tagespolitik-umfragen.com
  • www.onlinegamerspro-worm.com
  • www.freegames4you-gzone.com
  • www.boards4all-terror432.com
  • www.anime4allfree.com
  • www.animepage43252.com
  • yourmail
  • alledigis
  • aktenz

Attachments may end in any one of the following extensions and be preceded with .txt or .doc, and/or a random number:

  • com
  • bat
  • cmd
  • pif
  • scr
  • exe

After being executed, Sober.c extracts target email addresses from the victim's machine and writes them to the file SAVESYSS.DLL in the SysDir.

Two other copies of the worm are then dropped into SysDir, with varying filenames. For example, 'SysDir\ONDMONSTR.EXE' and 'SysDir\DATMSCRYPT.EXE'.

Avert warned in an advisory: "These two latter files are responsible for monitoring and maintaining that the worm stays resident in memory.

"Upon termination of one worm processes, another copy will restart the terminated process very quickly.

"Two processes run on the victim machine in order to ensure the worm stays memory resident."

More information on the Sober.c worm can be found here.

See also:

Sober, Swen and MiMail continue to wreak havoc  04 Dec 2003
Multi-lingual W32/Sober-A worm causes most problems in November  02 Dec 2003
virusVirus firms warn of new email attachment-based malware  27 Oct 2003

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities