W32.Sober-K-mm on the loose
W32.Sober-K-mm on the loose
R E L A T E D   C O N T E N T
ADVERTISEMENT

Mutant Sober worm spreading fast

Security firm intercepts 1,400 copies of latest mass-mailer variant

Steve Ranger, vnunet.com 21 Feb 2005
ADVERTISEMENT

A newly discovered variant of the mass-mailing Sober email worm is spreading rapidly and has already been spotted in the UK, according to MessageLabs.

The email security company said that it has intercepted 1,400 copies of W32.Sober-K-mm since 5am GMT this morning in Germany, France, the US and the UK.

Sober-K-mm sends itself as an attachment and creates random subject lines and body texts in either English or German, depending on the email addresses harvested by the worm.

It can also show a fake notice from antivirus vendors warning about a new version of the virus, and attempts to dupe users into clicking on the attachment which contains the worm by claiming that it contains a software patch.

But computer users who activate the file attached in the email invoke the virus, which harvests email addresses from the computer's hard drive.

Subject lines in the email may include 'Alert! New Sober worm', 'Paris Hilton Sex Videos', 'You visit illegal websites' and 'Your new Password'.

Once activated, Sober.K-mm drops several copies of executable files onto an infected computer with 'filenamescsrss.exe', 'winlogon.exe' and 'smss.exe'.

The worm modifies the registry key Software\Microsoft\Windows\CurrentVersion\Run so that it executes on startup. It then displays the contents of the file (systemdrive%/windows/temp/doc_data-text.txt) in notepad.

See also:

Infected email appears to come from FifaPromise of World Cup tickets hides deadly payload  03 May 2005
You've got mail, but be careful  19 Apr 2005
Trojan-based attacks on the wane as mass-mailers increaseThe advice remains the same: do not click on attachments  02 Mar 2005
Top 10 viruses in February 2005But Bagle and Sober will be the ones to watch  01 Mar 2005
Emails claim to contain adult footage of society heiressAdult footage used as social engineering hook  21 Feb 2005
Virus displays nationalist sloganMalicious code infects executable files  16 Feb 2005
Email contains a spoofed 'from' addressBitDefender dismisses infection as work of Romanian student  21 Jan 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities