Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New VIRUS threat Sober.p (4% of emails contain .zip files-DO NOT OPEN!)
http://vil.nai.com/vil/content/v_133409.htm ^ | May 4 2005 | Self

Posted on 05/04/2005 5:16:08 PM PDT by Las Vegas Dave

Virus Name Risk Assessment W32/Sober.p@MM Corporate User : Low-Profiled Home User : Medium

Virus Information Discovery Date: 05/02/2005 Origin: Unknown Length: 53,727 bytes (zip) 53,554 bytes (executable) Type: Virus SubType: E-mail Minimum DAT: 4443 (03/09/2005) Updated DAT: 4482 (05/02/2005) Minimum Engine: 4.3.20 Description Added: 05/02/2005 Description Modified: 05/02/2005 3:59 PM (PT) Description Menu Virus Characteristics Symptoms Method Of Infection Removal Instructions Variants / Aliases Rate This page Print This Page Email This Page Legend

Virus Characteristics: -- Update 2nd May 13:00 PST -- Due to increased prevalence, this threat has had its risk assessment raised to MEDIUM for Home Users.

If you think that you may be infected with Sober.p, and are unsure how to check your system, you may download the Stinger tool to scan your system and remove the virus if present. This is not required for McAfee users as McAfee products are capable of detecting and removing the virus with the latest update. (see the removal instructions below for more information).

Note: Receiving an email alert stating that the virus came from your email address is not an indication that you are infected as the virus often forges the from address.

This threat is proactively detected with the 4443 DAT files, or newer, as W32/Sober.gen@MM.

This threat arrives in an email message with one of the following attachment names:

account_info.zip autoemail-text.zip LOL.zip Fifa_Info-Text.zip mail_info.zip okTicket-info.zip our_secret.zip _PassWort-Info.zip Inside the ZIP archive is a file named winzipped-text_data.txt .pif

Like many Sober variants, this variant uses several different email messages randomly, in either English or German depending on the version of Windows. One such German message states that the recipient has won tickets to the worldcup:

Subject : WM-Ticket-Auslosung Body: Herzlichen Glueckwunsch,

beim Run auf die begehrten Tickets für die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei.

Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang.

Ihr "ok2006" Team St. Rainer Gellhaus

--- FIFA-Pressekontakt: --- Pressesprecher Jens Grittner und Gerd Graus --- FIFA Fussball-Weltmeisterschaft 2006 --- Organisationskomitee Deutschland --- Tel. 069 / 2006 - 2600 --- Jens.Grittner@ok2006.de --- Gerd.Graus@ok2006.de

An example of a randomly generated English message is as follows:

Subject: Your Password Body: Account and Password Information are attached!

Visit: http://www. {sender's domain}

*** AntiVirus: No Virus found *** "{recipient's domain} " Anti-Virus *** http://www. {recipient's domain}


TOPICS: Miscellaneous
KEYWORDS: exploit; getamac; internetexploiter; lookoutexpress; lowqualitycrap; microsoft; patch; securityflaw; trojan; virus; windows; worm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-96 last
To: Texas_Jarhead

My "hunch" is that China is up to no good. Maybe, just maybe, they are using information warfare tactics. No way, the Clintons and Kerry and all their hangers-on said it can not be so! Just a hunch that China's behind some bad stuff. We should say... "That wasn't nice" ... Now, let's see, are there any snakes we can train to take them on also? They mess with the bull, they get the horns. Bulls don't like Red.

Check out these links when you have some spare time:

http://www.sinodefence.com/c4i/default.asp
http://www.sinodefence.com/c4i/ew/ew.asp
http://users.bigpond.net.au/pongrass/security/security.htm (SMH, 8/18/2001)
http://www.specialoperations.com/Foreign/China/IW.htm
http://www.ceip.org/programs/info/infowar.htm
http://www.sans.org/rr/whitepapers/warfare/896.php
http://www.global-defence.com/2000/pages/china.html
http://www.fas.org/irp/world/china/docs/iw_mg_wang.htm
http://www.taipeitimes.com/News/front/archives/2003/09/04/2003066387
http://www.gyre.org/news/related/Information+Warfare/China
http://www.rand.org/publications/CF/CF145/CF145.chap9.pdf
http://www.strategypage.com/fyeo/howtomakewar/default.asp?target=HTIW.HTM
http://www.herolibrary.org/p113.htm (Chinese, sic)
http://www.iwar.org.uk/iwar/resources/news/china-io-2003.htm
http://www.iwar.org.uk/iwar/resources/china/iw/chininfo.pdf
http://www.infowar-monitor.net/
http://www.carlisle.army.mil/ssi/pubs/display.cfm/hurl/PubID=62
http://www.fas.org/news/taiwan/1999/cn-08-17-99-11.htm (1999)
http://www.taiwansecurity.org/AP/2002/AP-072902.htm (AP 2002)
http://www.au.af.mil/au/awc/awcgate/ndu/chinview/chinacont.html
http://www.au.af.mil/au/awc/awcgate/awc-info.htm
http://library.nps.navy.mil/home/bibs/IWbooks.htm (IW resources)


81 posted on 05/04/2005 9:22:13 PM PDT by Bald Eagle777 (Property tax is eternal rent.)
[ Post Reply | Private Reply | To 76 | View Replies]

To: Bald Eagle777

Ref:

http://www.theatlantic.com/doc/prem/200506/kaplan (Atlantic - Kaplan - 05 - sic)
http://www.voanews.com/english/2005-03-23-voa76.cfm (VOA March 23, 2005)
http://www.jamestown.org/publications_details.php?volume_id=408&issue_id=3232&article_id=2369263 (Jamestown February 15, 2005)
http://www.csis.org/burke/hd/#reports (CSIS – resources)
http://fmso.leavenworth.army.mil/FMSOPUBS/ISSUES/china-internet.htm
http://www.sans.org/rr/whitepapers/warfare/ (SANS)
http://www.fofg.org/news/news_story.php?doc_id=782 (May 13, 2004)
http://armedservices.house.gov/issues/opeds/03-09-12tcs-china.html (HASC, 9/12/03)
http://www.space.com/news/china_dod_030801.html (August 1, 2003 – Space)
http://www.defenselink.mil/pubs/20030730chinaex.pdf (annual PRC report July 2003)
http://www.military-information-technology.com/article.cfm?DocID=51 (November 15, 2002)
http://www.cia.gov/nic/speeches_telecommunications.html (CIA – Gannon - April 2001)
http://www.spacedaily.com/news/china-01c.html (Space Daily Jan 2000)
http://www.heritage.org/Research/AsiaandthePacific/BG1340.cfm (Heritage - Wortzel - December 2, 1999)
http://www.ndu.edu/inss/siws/ch1.html (William Fast)
http://www.aracnet.com/~kea/Papers/threat_white_paper.shtml (Kent Anderson, 1998)
http://www.securityfocus.com/library?cat=132&offset=70 (Inf. Ops /IW 1996


82 posted on 05/04/2005 10:11:04 PM PDT by Bald Eagle777 (Property tax is eternal rent.)
[ Post Reply | Private Reply | To 81 | View Replies]

To: PFKEY

Yes, they will actually execute in the preview pane of most versions of Outlook or Outlook Express unless you tell the program not to allow it - or turn the preview pane off.


83 posted on 05/04/2005 11:41:06 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 51 | View Replies]

To: Bald Eagle777

Those are special cases. I recommend Sophos for those installations. This isn't the first time Trend has screwed up and killed machines with an update...


(kicks back and checks the status on his Cisco Pix firewall)


84 posted on 05/04/2005 11:44:16 PM PDT by Spktyr (Overwhelmingly superior firepower and the willingness to use it is the only proven peace solution.)
[ Post Reply | Private Reply | To 67 | View Replies]

To: Spktyr

I have never caught a virus from any email attachment and I always use the preview pane. I wonder if I have something set to not allow it? I don't recall ever being prompted to allow a program to execute. I keep my virus sw upto date on my laptop but have an old desktop that runs without any virus protection. Guess I'm lucky.


85 posted on 05/04/2005 11:48:15 PM PDT by PFKEY
[ Post Reply | Private Reply | To 83 | View Replies]

To: Bald Eagle777; Texas_Jarhead
I've seen a definite shift in my firewall log lately - China is absolutely at the top of the list. Tracing the source of rejected packets either reads like a tour list of Chinese cities or, increasingly, shows unregistered IP addresses with "Asian" super domains.

When I first entered the Army in '75, I elected Mandarin Chinese as my foreign language of choice figuring I was going to need it eventually. Looking back thirty years later, not a single thing has happened to make me change my mind.

If my instincts in real estate and the stock market had been 1/10th as good, this message would have been typed by my personal Freeping assistant.

86 posted on 05/05/2005 4:50:58 AM PDT by LTCJ
[ Post Reply | Private Reply | To 81 | View Replies]

To: VeniVidiVici
Just rename the extension to .txt and then back to .zip when the recipient receives it.

That shouldn't be necessary. If they are going to take the time to scan mime for zip files and/or executables, why not scan for viruses and pass uninfected items along.

This issue is another one of those things that makes defects in MSWindows platform affect everyone else adversely.

87 posted on 05/05/2005 6:34:56 AM PDT by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 61 | View Replies]

To: Ramius
...and I'm not a Windows bigot.

Didn't mean to imply that you were. Sorry if it came off that way. I was making more of a general statement than one directed directly at you. I should have clarified that.

88 posted on 05/05/2005 6:36:46 AM PDT by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 56 | View Replies]

To: Rickkimble
Sounds like Linux would work for you. If you're into a lot of gaming on your computer you'd need to keep a windows partition around. There is excellent Linux versions of 'office'-type software (Open Office, amonst others). For email and general internet access Linux is far superior to windows as viruses/worms/spyware are much less of a concern. I still strongly reccommend that you use a hardware firewall/router even if you only have one computer to give you that extra layer of protection from some of the evil types that roam the net.

Check out LinuxISO.org. They have links to many of the major distributions. If you need more information or general assistance with the migration, FreepMail me.

89 posted on 05/05/2005 6:44:38 AM PDT by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 60 | View Replies]

To: Ramius

You're one of the first mac people I've come across on this forum (or many other forums) that has said essentailly "who cares what OS you use, as long as it does what you need it to do."


90 posted on 05/05/2005 6:50:32 AM PDT by timtoews5292004
[ Post Reply | Private Reply | To 50 | View Replies]

To: Spktyr

Wow. I believe you, but something sounds out of place.

I have had experience w/Trend for years, as do many of the $95-$125/hr type IT guys that set up networks w/Trend and they have never reported any incidents to me. I'll ask around, but so far, no bad news.

Interesting, I will be on the Red Alert for ANY problems w/Trend and I'll try to post any anomalies in all honesty and objectivity.


91 posted on 05/05/2005 9:59:26 AM PDT by Bald Eagle777 (Property tax is eternal rent.)
[ Post Reply | Private Reply | To 84 | View Replies]

To: Las Vegas Dave

92 posted on 05/05/2005 10:05:41 AM PDT by Disambiguator (This tagline should only be taken under the advice of your doctor.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: LTCJ

Don't sell yourself short. You had the vision and foresight to opt for Mandarin in the 70s, now apply that skill set to the market!

Make a million $. Do it for the Gipper!

Yes, the ChiComs are being naughty, the rascals.


93 posted on 05/05/2005 10:26:10 AM PDT by Bald Eagle777 (Property tax is eternal rent.)
[ Post Reply | Private Reply | To 86 | View Replies]

To: timtoews5292004
You're one of the first mac people I've come across on this forum (or many other forums) that has said essentailly "who cares what OS you use, as long as it does what you need it to do."

Well, in the interest of full disclosure... I *was* a mac head. Now I'm pretty much immersed in Winders Server and XP. But... we do support lots of mac users around the company. I've only dabbled around with OS X. It's pretty, but I haven't owned one since system 7 (which *rocked* by the way). :-)

We also have a little linux, even some Sun and SGI gurgling along around here somewhere. And... I kid you not... I've got one remaining Alpha running VMS. Just can't get the damn thing to die, but I'm trying.

94 posted on 05/05/2005 8:10:38 PM PDT by Ramius
[ Post Reply | Private Reply | To 90 | View Replies]

To: Las Vegas Dave

Bump for tomorrow.


95 posted on 05/17/2005 1:04:23 AM PDT by Humidston (Pubbies - GROW SOME!!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Wiz; Tennessee_Bob
That refreshes my memory for the old days of MS-DOS without Windows. Long ago I use to write my own Autoexec.bat and now I am scared that my skills have faded away by the influence of GUI. :)

Yep, and config.sys as well. Still remember that feeling of triumph getting vdisk to run properly the first time...

Used to have DR-DOS around here somewhere... Jameco was giving away the discs with some hardware I bought years ago. Still have Windows 3.1 ( not 3.11 ) on the original IBM discs, in my "box of OS's for weird & obsolete iron." Salavaged them from a dumpster behind an office that was tossing out old stuff.

96 posted on 05/17/2005 3:16:48 AM PDT by backhoe (Just an Undocumented Keyboard Cowboy, ridin' the trackball into the Sunset...)
[ Post Reply | Private Reply | To 30 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-96 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson