Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New VIRUS threat Sober.p (4% of emails contain .zip files-DO NOT OPEN!)
http://vil.nai.com/vil/content/v_133409.htm ^ | May 4 2005 | Self

Posted on 05/04/2005 5:16:08 PM PDT by Las Vegas Dave

Virus Name Risk Assessment W32/Sober.p@MM Corporate User : Low-Profiled Home User : Medium

Virus Information Discovery Date: 05/02/2005 Origin: Unknown Length: 53,727 bytes (zip) 53,554 bytes (executable) Type: Virus SubType: E-mail Minimum DAT: 4443 (03/09/2005) Updated DAT: 4482 (05/02/2005) Minimum Engine: 4.3.20 Description Added: 05/02/2005 Description Modified: 05/02/2005 3:59 PM (PT) Description Menu Virus Characteristics Symptoms Method Of Infection Removal Instructions Variants / Aliases Rate This page Print This Page Email This Page Legend

Virus Characteristics: -- Update 2nd May 13:00 PST -- Due to increased prevalence, this threat has had its risk assessment raised to MEDIUM for Home Users.

If you think that you may be infected with Sober.p, and are unsure how to check your system, you may download the Stinger tool to scan your system and remove the virus if present. This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).

Note: Receiving an email alert stating that the virus came from your email address is not an indication that you are infected as the virus often forges the from address.

This threat is proactively detected with the 4443 DAT files, or newer, as W32/Sober.gen@MM.

This threat arrives in an email message with one of the following attachment names:

account_info.zip autoemail-text.zip LOL.zip Fifa_Info-Text.zip mail_info.zip okTicket-info.zip our_secret.zip _PassWort-Info.zip Inside the ZIP archive is a file named winzipped-text_data.txt .pif

Like many Sober variants, this variant uses several different email messages randomly, in either English or German depending on the version of Windows. One such German message states that the recipient has won tickets to the worldcup:

Subject : WM-Ticket-Auslosung Body: Herzlichen Glueckwunsch,

beim Run auf die begehrten Tickets für die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei.

Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang.

Ihr "ok2006" Team St. Rainer Gellhaus

--- FIFA-Pressekontakt: --- Pressesprecher Jens Grittner und Gerd Graus --- FIFA Fussball-Weltmeisterschaft 2006 --- Organisationskomitee Deutschland --- Tel. 069 / 2006 - 2600 --- Jens.Grittner@ok2006.de --- Gerd.Graus@ok2006.de

An example of a randomly generated English message is as follows:

Subject: Your Password Body: Account and Password Information are attached!

Visit: http://www. {sender's domain}

*** AntiVirus: No Virus found *** "{recipient's domain} " Anti-Virus *** http://www. {recipient's domain}


TOPICS: Miscellaneous
KEYWORDS: exploit; getamac; internetexploiter; lookoutexpress; lowqualitycrap; microsoft; patch; securityflaw; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-96 next last

1 posted on 05/04/2005 5:16:09 PM PDT by Las Vegas Dave
[ Post Reply | Private Reply | View Replies]

To: Las Vegas Dave

I received email today from BLUECROSS with a .zip file attached, I immediately deleted it!


2 posted on 05/04/2005 5:17:01 PM PDT by Las Vegas Dave
[ Post Reply | Private Reply | To 1 | View Replies]

To: Las Vegas Dave

I've received about 5 of these today.


3 posted on 05/04/2005 5:17:38 PM PDT by Aggie Mama
[ Post Reply | Private Reply | To 1 | View Replies]

To: Las Vegas Dave

I wonder if Sober will run under WINE.


4 posted on 05/04/2005 5:17:43 PM PDT by Redcloak (But what do I know? I'm just a right-wing nut in his PJs whackin' on a keyboard..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Redcloak

ROTFL


5 posted on 05/04/2005 5:18:12 PM PDT by explodingspleen (http://mish-mash.info/)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Aggie Mama

I got about 150 - or so my server tells me. clamav is my friend.


6 posted on 05/04/2005 5:18:48 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Aggie Mama

Trend Micro notified me of virus and did scan and sys update last week. Trend Micro has a free version at their website.

It seems more user friendly to me then Norton.


7 posted on 05/04/2005 5:19:33 PM PDT by edcoil (Reality doesn't say much - doesn't need too)
[ Post Reply | Private Reply | To 3 | View Replies]

To: explodingspleen

Would you believe that one nut actually tried to get several "popular" worms to run under WINE? IIRC, 4 of 5 failed to do anything. The 5th got half credit for causing WINE to freeze.


8 posted on 05/04/2005 5:20:31 PM PDT by Redcloak (But what do I know? I'm just a right-wing nut in his PJs whackin' on a keyboard..)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Las Vegas Dave

The thing I hate most about these viruses is... no cross-platform compatibility! They only attack Windows!

I'll be darned if I'm going to fork over a couple hundred bucks to microsoft just so I can enjoy the experience of viruses and worms.

Somebody needs to write a Linux patch so that my operating system is no longer virus-deficient!


9 posted on 05/04/2005 5:20:54 PM PDT by explodingspleen (http://mish-mash.info/)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Spktyr

150? I only received 70. I feel so deprived.


10 posted on 05/04/2005 5:21:19 PM PDT by Blue Champagne
[ Post Reply | Private Reply | To 6 | View Replies]

To: edcoil

It is, IMHO, but Trend had a little hoo-hah last week when they released a signature file that locked their clients' machines solid. They corrected it right away, but it sort of hurt my sales program here at work to switch from Symantec.


11 posted on 05/04/2005 5:22:02 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 7 | View Replies]

To: Las Vegas Dave

... and here I thought Sober p. kept you out of trouble.


12 posted on 05/04/2005 5:23:02 PM PDT by fat city (Julius Rosenberg's soviet code name was "Liberal")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Las Vegas Dave
I received email today from BLUECROSS with a .zip file attached, I immediately deleted it!

I recieved one of these at my work email.

I'm very surprised it made it through.

Most of these things are caught real early and deleted before they ever reach my inbox.

Anyone who still gets infected by opening attatchments is just plain stupid.

13 posted on 05/04/2005 5:23:23 PM PDT by PFKEY
[ Post Reply | Private Reply | To 2 | View Replies]

To: Las Vegas Dave

I've received approximately 30 spam emails with sober virus in attached files over the past two days. Most of them had a fake message saying that Postmaster of some website was returning my mail--but I hadn't sent any mail to those addresses, and the addresses were suspicious.

Depressing. I was just thinking it had been quite a while since the last time I started getting a lot of virus attacks.

Norton AV works fine at blocking and deleting this virus, and I presume the other AV programs will as well, provided they are kept up to date. You all may want to check with your providers.


14 posted on 05/04/2005 5:24:37 PM PDT by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: explodingspleen
Somebody needs to write a Linux patch so that my operating system is no longer virus-deficient!

Keep eggin' them on... they'll get to all ya Linux folk soon enough ;~D

15 posted on 05/04/2005 5:25:10 PM PDT by HairOfTheDog (This horse has been milked to death.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Las Vegas Dave

I left my computer on and left for a while, and when I cam eback in the Norton screen was up telling me it had blocked this virus. Good to know it works..


16 posted on 05/04/2005 5:25:31 PM PDT by cardinal4 (George W Bush-Bringing a new democracy every term..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Billthedrill

I'm not a big fan of Trend Micro's stuff. Tried Grisoft's software?


17 posted on 05/04/2005 5:26:03 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Las Vegas Dave
I received about a dozen emails yesterday (that went to my "junk mail" from various addys that claimed they were "administrators" "hosts" etc. for a server and were alerting me to the fact that "Your email did not go through, " or "Your email was blocked, " etc. I looked at one wondering what email I sent that was blocked. I saw it contained a link to my own email server, and an attachment that was a .zip file. I deleated it and all the others. Only received one today.

Has anyone had this type of email come in?

18 posted on 05/04/2005 5:26:20 PM PDT by CitizenM ("An excuse is worse than an lie, because an excuse is a lie hidden." Pope John Paul, II)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Las Vegas Dave

I'm getting more of these today than porn spam.


That's a lot!!!


19 posted on 05/04/2005 5:27:14 PM PDT by socal_parrot (Turn the beat around!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CitizenM

For some odd reason, I got about 6-700 of those this morning between the hours of 4 and 5 am. I just set them to autodelete and redirected a copy to Grisoft and SARC.


20 posted on 05/04/2005 5:28:30 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 18 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-8081-96 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson