Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Sober worm makes a comeback
ZD Net News ^ | April 19, 2005 | Dan Ilett

Posted on 04/19/2005 1:52:01 PM PDT by infocats

Virus writers have resurrected the Sober worm with a new variant that is spreading quickly over the Internet.

Security experts said Tuesday that the worm, dubbed Sober.M, reports e-mail addresses of victims back to its anonymous author--a technique known as harvesting. Spammers typically buy these fresh addresses to add to their lists of e-mail recipients.

The e-mail containing the worm is written in bad English with the subject line: "I've got your e-mail on my account."

"It looks like the virus writer is deliberately using broken English to (convince) people the e-mail is not a virus," Graham Cluley, senior technology consultant at antivirus company Sophos, said in a statement.

Sophos said that the new Sober variant was the fifth most reported virus over the last 24 hours, closely followed by versions of Zafi and Netsky. It's thought that all the major antivirus companies are now offering protection against the worm, so users should update their virus protection.

Sober.M is a mass e-mailing virus that spreads as a .zip file attachment and affects systems running Microsoft Windows. The e-mail containing the worm sends itself in German or English language. The English version of the e-mail is below.

Subject line: I've_got your E-mail on my_account!

Message text:

Hello,
First, Very Sorry for my bad English.
Someone is sending your private e-mails on my address.
It's probably an e-mail provider error!
At time, I've got over 10 mails on my account, but the recipient are you.
I have copied all the mail text in the windows text-editor for you & zipped then.
Make sure, that this mails don't come in my mail-box again.
bye

Attached file: your_text.zip


TOPICS: Business/Economy; Crime/Corruption; Culture/Society; Technical
KEYWORDS: exploit; lookoutexpress; lowqualitycrap; patch; securityflaw; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-25 next last

1 posted on 04/19/2005 1:52:02 PM PDT by infocats
[ Post Reply | Private Reply | View Replies]

To: infocats

I just keep getting mail from MY Email address but from a different provider....ie I am let say Vaquero@Yahoo.com and I get mail from Vaquero@hotmail.com...well as it turns out there is and attachment which is a virus.....I have never opened it, but I have forwarded it to my work email address and boy did it send off bells and whistles.....anyway thats how I check for viruses....the IT guy wanted to know who sent me the virus and I said "I did, I didnt know what it was so I sent it here figuring if it was evil you guy would figure it out".


2 posted on 04/19/2005 1:58:57 PM PDT by Vaquero ("an armed society is a polite society "( Robert Heinlien).)
[ Post Reply | Private Reply | To 1 | View Replies]

To: infocats
I have received two of this worm today it's not currently being caught by the virus scan.

But since my IQ exceeds that of a flying squirrel, I delete these, without opening the attachments.

If everyone would do the same the problem would go away.

3 posted on 04/19/2005 2:01:45 PM PDT by Voltage
[ Post Reply | Private Reply | To 1 | View Replies]

To: Vaquero

I've have yet to see an spam email, virus, or any other nefarious item from the internet that was NOT in anything but broken english.


4 posted on 04/19/2005 2:03:06 PM PDT by ruiner
[ Post Reply | Private Reply | To 2 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

Protect yourselves!

5 posted on 04/19/2005 2:03:09 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Vaquero
"I have never opened it, but I have forwarded it to my work email address and boy did it send off bells and whistles.....anyway thats how I check for viruses....the IT guy wanted to know who sent me the virus and I said "I did, I didnt know what it was so I sent it here figuring if it was evil you guy would figure it out"."

And you're still gainfully employed?

6 posted on 04/19/2005 2:08:35 PM PDT by avg_freeper (Gunga galunga. Gunga, gunga galunga)
[ Post Reply | Private Reply | To 2 | View Replies]

To: infocats

Maybe someone can help me with a quick question.

I just installed new anti-virus software (McFee VirusScan Enterprise 8.0.0). Is there any way to tell if it's working okay on my computer? Is there any way to make sure it's turned "on"?


7 posted on 04/19/2005 2:12:45 PM PDT by 68skylark
[ Post Reply | Private Reply | To 1 | View Replies]

To: 68skylark

Are you asking someone to mail you a virus to test it? I'm sorry but I laughed at that image.


8 posted on 04/19/2005 2:14:04 PM PDT by Ingtar (Understanding is a three-edged sword : your side, my side, and the truth in between ." -- Kosh)
[ Post Reply | Private Reply | To 7 | View Replies]

To: avg_freeper
sure, my company employs IT guys and is not run by them....besides, they're too busy away from their posts, attempting to "fix the equipment" of the the nicer looking woman in the cubes.....I always know where to find them when something goes haywire.........
9 posted on 04/19/2005 2:14:54 PM PDT by Vaquero ("an armed society is a polite society "( Robert Heinlien).)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Ingtar
Are you asking someone to mail you a virus to test it?

That's wasn't what I had in mind. I was hoping there'd be a web page I could visit to test my computer or something -- maybe they have a benign or "dead" virus they could send me as a test.

10 posted on 04/19/2005 2:21:55 PM PDT by 68skylark
[ Post Reply | Private Reply | To 8 | View Replies]

To: 68skylark

There used to be a "test virus," but I can't remember the name. It was a line of text typed (looked like gibberish) but wasn't active, and was saved in a .txt file. The scanner would pick up on the text and alert the user.


11 posted on 04/19/2005 2:43:10 PM PDT by Tennessee_Bob (This tagline is Bush's fault.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Tennessee_Bob

It's called Eicars


12 posted on 04/19/2005 2:45:25 PM PDT by G32
[ Post Reply | Private Reply | To 11 | View Replies]

To: G32

Thanks - I hate getting old.


13 posted on 04/19/2005 2:53:52 PM PDT by Tennessee_Bob (This tagline is Bush's fault.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Vaquero
I just keep getting mail from MY Email address but from a different provider....ie I am let say Vaquero@Yahoo.com and I get mail from Vaquero@hotmail.com...well as it turns out there is and attachment which is a virus.....I have never opened it, but I have forwarded it to my work email address and boy did it send off bells and whistles.....anyway thats how I check for viruses....the IT guy wanted to know who sent me the virus and I said "I did, I didnt know what it was so I sent it here figuring if it was evil you guy would figure it out".

We don't figure out viruses at my company. We don't have time to play patty-cake like you play with your IT staff. We just delete the message and let the executive figure out why he didn't receive it.

On those rare occasions when the executive finally does chase us down and asks us why he didn't get a particular message, we shrug our shoulders or we tell the executive that the sender has a virus and we blocked all mail coming from him and tell the executive to tell the sender to clean up his computer otherwise his mail won't ever get through and go back to helping the pretty girl.

At least with her, there's a chance for a pay-off. When you help an executive, all you get is more stupid questions and idiotic behavior.

14 posted on 04/19/2005 3:50:01 PM PDT by Ol' Dan Tucker
[ Post Reply | Private Reply | To 2 | View Replies]

To: 68skylark
I just installed new anti-virus software (McFee VirusScan Enterprise 8.0.0). Is there any way to tell if it's working okay on my computer? Is there any way to make sure it's turned "on"?

Yes. Would you like for me to send you a copy of the worm described in this article? I've gotten a few today, and am perfectly willing to share. Since this virus only works against people who use windows, it was kinda wasted on me.

15 posted on 04/19/2005 5:49:51 PM PDT by zeugma (Come to the Dark Side...... We have cookies! (Made from the finest girlscouts!))
[ Post Reply | Private Reply | To 7 | View Replies]

To: infocats

I got email today from NAVMSE with subject line: Norton AntiVirus detected and quarantined a virus in a message you sent. The body of email said following: "Recipient of the infected attachment: SBS, First Storage Group\Mailbox Store (SBS), Patty Pierce/Inbox
Subject of the message: [spamcatcher] report
One or more attachments were quarantined.
Attachment secrets_attachment.doc.exe was Quarantined for the following reasons:
Virus W32.Netsky.C@mm was found."
DO YOU THINK THIS IS LEGIT? I can't find virus anywhere. Thanks


16 posted on 04/19/2005 5:54:54 PM PDT by ncpatriot
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Protect yourselves!

Done. Microsoft platforms and tools are never used for e-mail around here.

17 posted on 04/19/2005 6:13:07 PM PDT by TechJunkYard
[ Post Reply | Private Reply | To 5 | View Replies]

To: ncpatriot
Attachment secrets_attachment.doc.exe

Ummm.... yeah.

18 posted on 04/19/2005 6:14:55 PM PDT by TechJunkYard
[ Post Reply | Private Reply | To 16 | View Replies]

To: infocats
I've received a couple of these. The first one yesterday was not detected by Norton's I sent a sample in and heard back this morning. No I didn't open the thing.
19 posted on 04/19/2005 6:15:35 PM PDT by armymarinemom (My sons freed Iraqi and Afghanistan Honor Roll students.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 68skylark
Here's a link to the test file. eicar. It is possible that your antivirus program won't even let you download the webpage linked above. If it alerts on it, then at least you know it works. Otherwise, the page describes how to create a file that will test your anti-virus program.
20 posted on 04/19/2005 8:32:00 PM PDT by zeugma (Come to the Dark Side...... We have cookies! (Made from the finest girlscouts!))
[ Post Reply | Private Reply | To 10 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-25 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson