Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New VIRUS threat Sober.p (4% of emails contain .zip files-DO NOT OPEN!)
http://vil.nai.com/vil/content/v_133409.htm ^ | May 4 2005 | Self

Posted on 05/04/2005 5:16:08 PM PDT by Las Vegas Dave

Virus Name Risk Assessment W32/Sober.p@MM Corporate User : Low-Profiled Home User : Medium

Virus Information Discovery Date: 05/02/2005 Origin: Unknown Length: 53,727 bytes (zip) 53,554 bytes (executable) Type: Virus SubType: E-mail Minimum DAT: 4443 (03/09/2005) Updated DAT: 4482 (05/02/2005) Minimum Engine: 4.3.20 Description Added: 05/02/2005 Description Modified: 05/02/2005 3:59 PM (PT) Description Menu Virus Characteristics Symptoms Method Of Infection Removal Instructions Variants / Aliases Rate This page Print This Page Email This Page Legend

Virus Characteristics: -- Update 2nd May 13:00 PST -- Due to increased prevalence, this threat has had its risk assessment raised to MEDIUM for Home Users.

If you think that you may be infected with Sober.p, and are unsure how to check your system, you may download the Stinger tool to scan your system and remove the virus if present. This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).

Note: Receiving an email alert stating that the virus came from your email address is not an indication that you are infected as the virus often forges the from address.

This threat is proactively detected with the 4443 DAT files, or newer, as W32/Sober.gen@MM.

This threat arrives in an email message with one of the following attachment names:

account_info.zip autoemail-text.zip LOL.zip Fifa_Info-Text.zip mail_info.zip okTicket-info.zip our_secret.zip _PassWort-Info.zip Inside the ZIP archive is a file named winzipped-text_data.txt .pif

Like many Sober variants, this variant uses several different email messages randomly, in either English or German depending on the version of Windows. One such German message states that the recipient has won tickets to the worldcup:

Subject : WM-Ticket-Auslosung Body: Herzlichen Glueckwunsch,

beim Run auf die begehrten Tickets für die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei.

Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang.

Ihr "ok2006" Team St. Rainer Gellhaus

--- FIFA-Pressekontakt: --- Pressesprecher Jens Grittner und Gerd Graus --- FIFA Fussball-Weltmeisterschaft 2006 --- Organisationskomitee Deutschland --- Tel. 069 / 2006 - 2600 --- Jens.Grittner@ok2006.de --- Gerd.Graus@ok2006.de

An example of a randomly generated English message is as follows:

Subject: Your Password Body: Account and Password Information are attached!

Visit: http://www. {sender's domain}

*** AntiVirus: No Virus found *** "{recipient's domain} " Anti-Virus *** http://www. {recipient's domain}


TOPICS: Miscellaneous
KEYWORDS: exploit; getamac; internetexploiter; lookoutexpress; lowqualitycrap; microsoft; patch; securityflaw; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-96 next last
To: Las Vegas Dave
My server has sent me 20+ emails about intercepting email w/virus just today!

(I hope all virus-mongers and spyware iceholes rot in hell.)

21 posted on 05/04/2005 5:29:01 PM PDT by Tuba Guy (~ Only YOU Can Prevent Hillareah !! ~)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Redcloak
Maybe - maybe not - but if you had a real operating system, you wouldn't have to wonder.

:P

22 posted on 05/04/2005 5:29:28 PM PDT by Tennessee_Bob (The Crew Chief's Toolbox: A roll around cabinet full of specialists.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Cicero

can anyone explain this to me... I received about 20 of these in the last 48 hours and I never, never get spam.


23 posted on 05/04/2005 5:29:40 PM PDT by Oystir
[ Post Reply | Private Reply | To 14 | View Replies]

To: Tuba Guy

I can't complain too much about them; between them and my idiot users (who despite all warnings and some beatings continue to open unexpected attachments and follow links to websites blindly), they keep me in business.

Microsoft Windows and the virus/adware/spyware writers - the IT Industry's Full Employment Act.

(Of course, I use Mac OS X at home, on my laptop, and on my personal servers, so I don't have to worry about that when I get home.) :)


24 posted on 05/04/2005 5:31:46 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: CitizenM
Has anyone had this type of email come in?

Not this time, but all that means is that it was spoofing the sender from lists found on your friends' machines, and your name and addy won the lottery.

25 posted on 05/04/2005 5:31:49 PM PDT by HairOfTheDog (This horse has been milked to death.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: fat city

Only drugfree p. can keep you out of trouble.


26 posted on 05/04/2005 5:32:51 PM PDT by Arkie2
[ Post Reply | Private Reply | To 12 | View Replies]

To: Aggie Mama

My daughter in law in Canada told me she got several of these today. She didn't open them.


27 posted on 05/04/2005 5:33:58 PM PDT by janetgreen (Minutman Project - American patriotism!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Tennessee_Bob

If I wanted to look at that, I could have stayed with the old Apple IIE we had in high school.


28 posted on 05/04/2005 5:34:17 PM PDT by HairOfTheDog (This horse has been milked to death.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: Tennessee_Bob

[snif] Brings back memories of that old Kaypro I used in college. [sigh]


29 posted on 05/04/2005 5:34:20 PM PDT by Ramius
[ Post Reply | Private Reply | To 22 | View Replies]

To: Tennessee_Bob

That refreshes my memory for the old days of MS-DOS without Windows. Long ago I use to write my own Autoexec.bat and now I am scared that my skills have faded away by the influence of GUI. :)


30 posted on 05/04/2005 5:36:47 PM PDT by Wiz
[ Post Reply | Private Reply | To 22 | View Replies]

To: Blue Champagne

Ah, the bliss of using a MAC...


31 posted on 05/04/2005 5:37:01 PM PDT by Conservatrix (He who stands for nothing will fall for anything.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: HairOfTheDog

LOL!


32 posted on 05/04/2005 5:37:13 PM PDT by Wiz
[ Post Reply | Private Reply | To 28 | View Replies]

To: HairOfTheDog

Sshhhh... there is balance in all things. I like listening to cocky mac and *nix folk. No habits of update and patch. No antivirus running on nearly any system.

Someday... the same worm will take 'em all down at once, and we can be there to lick the delicious tears of sadness. /cartman. :-)


33 posted on 05/04/2005 5:37:33 PM PDT by Ramius
[ Post Reply | Private Reply | To 15 | View Replies]

To: Spktyr
"I'm not a big fan of Trend Micro's stuff. Tried Grisoft's software?"

Serious question. Would you mind explaining wy that is? I have recommended TM corporate products and if there is something better then I'd like to educate myself. Thanks in advance.
34 posted on 05/04/2005 5:37:34 PM PDT by Texas_Jarhead (To hell with Mexico, its policies, and its leaders)
[ Post Reply | Private Reply | To 17 | View Replies]

To: CitizenM
< snip >"administrators" "hosts" etc. for a server and were alerting me to the fact that "Your email did not go through, " or "Your email was blocked < snip >

That is approximately what my email from BLUECROSS(es?) said!

35 posted on 05/04/2005 5:37:52 PM PDT by Las Vegas Dave
[ Post Reply | Private Reply | To 18 | View Replies]

To: Redcloak
Would you believe that one nut actually tried to get several "popular" worms to run under WINE?

Wow. If Monsieur is that desperate for abuse, may I suggest ze Windows? It is particularly tender this evening.

36 posted on 05/04/2005 5:40:56 PM PDT by LTCJ
[ Post Reply | Private Reply | To 8 | View Replies]

To: HairOfTheDog; Redcloak
I dunno... they have a really long way to go.

Most of the time, I can't even get the virus/spyware detectors to even cooperate with my browser/Linux combination to let me know if I have a problem.

Linux variants may not be completely bullet proof, but they are so superior to Windows variants in the way networked information is handled that it almost requires personal keyboard access with supervisor privileges to infect a machine. Post#8 above that describes failed attempts to infect LINUX machine by running various viruses on WINE (the WINdows Emulator available on most LINUX distributions) --- that is, giving the virus advantages that it does not naturally have in LINUX to begin with --- are pretty indicative of the difficulty.
37 posted on 05/04/2005 5:43:10 PM PDT by AFPhys ((.Praying for President Bush, our troops, their families, and all my American neighbors..))
[ Post Reply | Private Reply | To 15 | View Replies]

To: Spktyr
Tried Grisoft's software?

No - may have to check that out. I'm dealing with about 20 servers under Micro$oft and a half-dozen Netware boxes. Symantec was the choice because Somebody liked the central console interface. That's the basis under which I'm trying to sell Trend to the boss...

38 posted on 05/04/2005 5:43:35 PM PDT by Billthedrill
[ Post Reply | Private Reply | To 17 | View Replies]

To: AFPhys

I've never had a virus myself using Windows, and I don't have to know how to build all the software in order to run it.

I'm a driver, not a mechanic, but whatever makes you happy.


39 posted on 05/04/2005 5:48:25 PM PDT by HairOfTheDog (This horse has been milked to death.)
[ Post Reply | Private Reply | To 37 | View Replies]

To: Texas_Jarhead

I've seen some *very* weird things happen with Trend Micro corporate antivirus stuff - strange incompatibilities, crashes, that sort of thing; not all that common, but it's happened to my clients enough times to make me leery. I'd still take TM over Symantec over McAfee, though.

Check out Grisoft's offerings - www.grisoft.com. Their stuff is less user-friendly than Symantec, but it takes a lot less horsepower to run, has a much better automatic update and detection system, and the automatic scheduled system scan can run in the background on more powerful machines without much of a speed hit.


40 posted on 05/04/2005 5:50:57 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 34 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-96 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson