Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Experts Say New Sobig Virus Could Strike Any Day
Yahoo! News ^ | August 25, 2K3 | Reuters

Posted on 08/25/2003 4:45:35 PM PDT by rdb3

Experts Say New Sobig Virus Could Strike Any Day
17 minutes ago
Add Technology - Reuters to My Yahoo!

SAN FRANCISCO (Reuters) - A new version of the Sobig.F e-mail virus that has plagued computers worldwide could arrive any day, even before the latest variant is timed to expire on Sept. 10, security experts said on Monday.

Related Quotes
SYMC
DJIA
NASDAQ
^SPC
54.30
9317.64
1764.31
993.71
-0.44
-31.23
-1.01
+0.65

delayed 20 mins - disclaimer
Quote Data provided by Reuters
 

"Another virus could be released any time," said Steve Trilling, research director with the Security Response Team at Symantec Corp. (Nasdaq:SYMC - news), a U.S.-based security company. "We can never be complacent when one threat seems to die down."

Mikko Hypponen, manager of anti-virus research at Finland-based F-Secure Corp, said one of the five prior versions of Sobig surfaced before the previous version expired. Sobig.E began circulating June 25, one week before Sobig.D was set to expire, he said.

The first version of Sobig arrived in January and had no expiration date. It was followed about four months later by Sobig.B. More sophisticated versions followed one week to three weeks after each preceding version, according to Hypponen.

The latest version, Sobig.F, first emerged a week ago and spread to hundreds of thousands of Windows-based computers, Hypponen said. Some 200 million e-mails have been sent over the Internet by infected computers, he estimated.

Sobig.F spreads when unsuspecting computer users open file attachments in e-mails with headings like "Thank You!," and "Re: Details." Once the file is opened, Sobig.F resends itself to e-mail addresses from the infected computer, using random names as the sender.

Sobig.F was programmed to send infected e-mails to one of 20 master computers to receive more instructions on Friday and Sunday, but both attacks failed when the 20 computers were taken off line by computer security specialists.

Infections have declined since last week, falling to a little under 100,000 affected computers by Monday, according to Tokyo-based anti-virus software maker Trend Micro Inc.

Authorities said Sobig.F was initially released on several Usenet news groups, which are Internet forums where people with similar interests can post messages and share photos.

Sobig.F was posted to news groups with names like alt.binaries.pictures.erotica and a few other adult-oriented news groups by someone using a stolen credit card, said Mike Minor, chief technology officer of Easynews.com.


TOPICS: Technical
KEYWORDS: virii; worm
Make sure your firewall is in place and you have all necessary patches.


1 posted on 08/25/2003 4:45:35 PM PDT by rdb3
[ Post Reply | Private Reply | View Replies]

To: rdb3
Will this affect MAC?
2 posted on 08/25/2003 4:47:22 PM PDT by cmsgop (If you Sprinkle When You Tinkle,...Be a Sweetie and Wipe the Seatie......)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3
I am much more concerned with Blaster/Welchia variants. Those two damn things are hard on equipment.
3 posted on 08/25/2003 4:51:42 PM PDT by Benrand
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
Sobig alert.
4 posted on 08/25/2003 4:56:12 PM PDT by MizSterious (Support whirled peas!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cmsgop
Will this affect MAC?

Other than clogging your inbox with unnecessary email, no.


5 posted on 08/25/2003 4:56:32 PM PDT by rdb3 (They've read all the books but they can't find the answers...)
[ Post Reply | Private Reply | To 2 | View Replies]

To: cmsgop
Other than receiving strange emails bearing attachments from people you don't know , clogging up the Internet in general, and making your mother worry about one more thing with you, no.
6 posted on 08/25/2003 4:57:52 PM PDT by Izzy Dunne (Hello, I'm a TAGLINE virus. Please help me spread by copying me into YOUR tag line.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rdb3
Sobig.F was posted to news groups with names like alt.binaries.pictures.erotica and a few other adult-oriented news groups by someone using a stolen credit card,

Wow. First time I ever heard of using a credit card to post to a newsgroup.

7 posted on 08/25/2003 5:03:17 PM PDT by Izzy Dunne (Hello, I'm a TAGLINE virus. Please help me spread by copying me into YOUR tag line.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3
Done and done...thank you.
8 posted on 08/25/2003 5:33:23 PM PDT by blackbart1
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3
They ought to up the penalties for writing these virsuses. Give them 20 to life!!! The monetary damage is huge for businesses.
9 posted on 08/25/2003 5:41:46 PM PDT by BunnySlippers (Why is the Left afraid of Arnold?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Izzy Dunne
Wow. First time I ever heard of using a credit card to post to a newsgroup.

Some are like that, especially if your ISP doesn't have access to a newsgroup you want. So you have to pay to hop sometimes.


10 posted on 08/25/2003 5:54:21 PM PDT by rdb3 (They've read all the books but they can't find the answers...)
[ Post Reply | Private Reply | To 7 | View Replies]

To: cmsgop
I don't know why the media just doesn't say "Yet Another Windows email virus".
11 posted on 08/25/2003 6:03:24 PM PDT by glorgau
[ Post Reply | Private Reply | To 2 | View Replies]

To: BellStar
ping
12 posted on 08/25/2003 11:10:53 PM PDT by anymouse
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
http://www.freerepublic.com/focus/f-news/969366/posts
Worm and Virus Wars- the August Edition
various FR links & posts | 08-23-03 | The Heavy Equipment Guy
13 posted on 08/26/2003 12:23:19 AM PDT by backhoe (I'm driving myself crazy-- want to come along for the ride?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3
Question: Does Administrator rights have any bearing on infections from viruses and worms? For some stupid reason, we give everyone admin rights.
14 posted on 08/28/2003 5:27:57 AM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: AppyPappy
Which version?


15 posted on 08/28/2003 5:58:50 AM PDT by rdb3 (They've read all the books but they can't find the answers...)
[ Post Reply | Private Reply | To 14 | View Replies]

To: rdb3
Win2k
16 posted on 08/28/2003 6:01:06 AM PDT by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 15 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson