On mySimon: Chuck Taylor All Star Sequins
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Mar 8, 2004 1:51:00 PM

The latest variant of the mass-mailing Sober worm, discovered on Monday, masquerades as an official Microsoft patch for the MyDoom worm.

Sober.D is technically similar to its previous incarnation as Sober.C, where it used its own SMTP engine to send copies of itself to e-mail addresses found on infected systems, but the latest version displays fake Microsoft warnings and error messages.

"It arrives in an e-mail that pretends to be a patch to protect against a version of MyDoom," said senior technology consultant Graham Cluley of antivirus company Sophos. "The e-mail appears to be a Microsoft patch so people will of course double-click on that attachment."

According to Finnish antivirus company F-Secure, Sober.D spreads either as an executable attachment or inside a password-protected Zip archive attached to an e-mail. Once a user clicks on the file, the worm scans the PC to see if it has already been infected. If the system is clean, a small box appears with the message: "This patch has been successfully installed." If the system is already infected with Sober.D, the message says: "This patch does not need to be installed on this system."

Sober.D also changes its language depending on where it is being sent. If the recipient's e-mail address has either a DE, CH, AT, LI, NL or BE extension, the text will be in German and the subject will read: "Microsoft Alarm: Bitte Lesen". Otherwise the subject line is in English and reads: "Microsoft Alert: Please Read!" Previous versions of Sober have also been biligual, said Sophos' Cluley.

This is not the first time that a worm has disguised itself as a Microsoft update. In January, the Xombe or Trojan.Xombe worm posed as a critical patch for Windows XP. This was believed to be a copycat of 2003's most successful worm, Swen, which is thought to be the first known worm to masquerade as a security warning from Microsoft.

Microsoft has always maintained that it does not e-mail patches to users, so they should ignore any such messages. Additional information on its prevention and removal.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 53 Talkback(s)
You haven't seen the latest trick !!!
Notice that the virus is delivered in a password protected .zip file and NOT an .exe? The worm even tells you the password to open the zip file. The zip compression also makes it difficult for a virus-checking program to find a signature in the attachment.... (Read the rest)
Posted by: RBrown72002 Posted on: 03/11/04 You are currently: a Guest | | Terms of Use
I 0nz ur Refriger3tor  Chad_z | 03/08/04
First article is from 2001?  jfrankcarr | 03/08/04
Wrong Distro.....  puckvader | 03/08/04
a upnp exploit?  ryusen | 03/08/04
One that was patched a long time ago.  jfrankcarr | 03/08/04
Here's an option for handling these things  John CarrollZDNet Moderator | 03/08/04
exe files in e-mail  Louis Ross Focke | 03/08/04
Admin Privileges  vferrara | 03/08/04
XP is admin by default  jfrankcarr | 03/08/04
re: XP is admin by default  B.O.F.H. | 03/08/04
XP and Administator Account  Gungnir | 03/08/04
It's still 'administrator'  jfrankcarr | 03/08/04
what you need to do is:  ryusen | 03/08/04
Good idea.  Immanuel Tranz-Mischen | 03/08/04
Can you say application software?  vferrara | 03/09/04
you don't understand  stephen732@... | 03/09/04
why?  ryusen | 03/09/04
scared?  stephen732@... | 03/09/04
re: sacred?  ryusen | 03/10/04
There is software to do this now  jfrankcarr | 03/09/04
longhorn...  ryusen | 03/09/04
ISPs need to just filter out EXE files....  wayne.p | 03/09/04
You haven't seen the latest trick !!!  RBrown72002 | 03/11/04
Please, IPSs do this!!!  middle of nowhere | 03/08/04
A better solution ...  George Jay | 03/08/04
Agreed, but...  vferrara | 03/08/04
The Commodity Test  Harry Bardal | 03/08/04
No, thanks.  Immanuel Tranz-Mischen | 03/08/04
Not necessarily via email  WendellB | 03/08/04
Dear John  idnew2011@... | 03/08/04
MS does NOT update by email, case closed  idnew2011@... | 03/08/04
The users will try it anyway  Nobeel | 03/08/04
Why Earthlink lost 2 business days (last week)?  Vily Clay | 03/08/04
They DO notify by email...  Jose Jimenez | 03/08/04
Re: They DO notify by email...  johngalt@... | 03/08/04
Like a paperclip in a light socket  moodytx | 03/08/04
I'm With Ya !!!  nikoli | 03/08/04
Why you should care  jfrankcarr | 03/08/04
Still Do NOT care in the least  nikoli | 03/08/04
Re: Why you should care  middle of nowhere | 03/08/04
Yes but it's not only the home users  bob@... | 03/08/04
See, Now You're Learning  nikoli | 03/08/04
That's why  michael-t | 03/08/04
Re: Like a paperclip in a light socket  middle of nowhere | 03/08/04
Crashes  nikoli | 03/09/04
Free Anti-Virus from a major software company  dgspencer | 03/08/04
Free AV  jonbjerke | 03/08/04
i use linux so .....  Iain_Peters | 03/08/04
Linux will in due time  WildArmX2 | 03/10/04
Free anti-virus from Computer Associates and Linux is NOT the answer  idnew2025@... | 03/08/04
Agreed  nikoli | 03/09/04
Tall heap of  michael-t | 03/08/04
Answer to "I use Linux"  Ed Lada | 03/11/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here