On mySimon: Vosges Haut-Chocolat
BNET Business Network:
BNET
TechRepublic
ZDNet

By Dan Ilett
Posted on ZDNet News: Nov 19, 2004 4:33:00 PM

A new version of the Sober mass-mailing worm was discovered Friday as it quickly spread through Europe and into the United States.

Tech security companies gave it a midlevel threat warning.

The W32.Sober.i worm, which sends itself as an e-mail attachment to English and German messages, is one of the more serious threats this fall, said security experts.

"It's probably one of the worst cases we've seen in a month or two," said Mikko Hypponen, antivirus research director for F-Secure, which rated the virus as a level 2 on a scale of 1 to 3. "For some reason, this fall has been relatively quiet. This is one of the biggest cases we've had this fall. But compared to the same time last year and earlier this year, it's not that bad."

Like the other Sober viruses, the new version uses its own SMTP engine to send copies of itself to e-mail addresses it finds on infected computers. The infected computers will then later serve as a channel to download programs to unsuspecting users.

The Sober.i virus, featuring an attachment claiming to be naked photos of a blond model, is beginning to spread rapidly around the Internet. A blond, 21-year-old go-go dancer is sending e-mails with naked photos of herself attached and asking for work as model--or so you are led to think by the latest mass-mailing Sober variant to hit the Web.

But unless you live in a German-speaking country, the e-mail is not nearly so exotic. Sober.i is programmed only to send itself with the go-go dancer message to German-language domains, such as those ending in .de (Germany) or .ch (Switzerland).

The virus is also programmed to launch itself at the English-speaking world, but under the subject header of "delivery failure" or "oh god" in the hopes that someone will open an attached .zip file, which unleashes the virus.

"The German version is really interesting," said Graham Cluley, senior technical consultant for tech security company Sophos. "They claim to come from a German 21-year-old go-go dancer with blond hair. She is seeking employment as a model and she says she has attached some naked photos of herself. But of course the photos are the worm."

"In the English version, they don’t seem to be using sex at all. Maybe (the virus writer) thinks that the English aren't as interested in sex as our German cousins," Cluley said. "Perhaps he is making a national judgment about the countries."

Sober.i affects systems running Windows XP, 2000, ME, 98, 95, NT and Server 2003.

CNET News.com's Dawn Kawamoto reported from San Francisco. Dan Ilett of ZDNet UK reported from London.

A new version of the Sober mass-mailing worm was discovered Friday as it quickly spread through Europe and into the United States.

Tech security companies gave it a midlevel threat warning.

The W32.Sober.i worm, which sends itself as an e-mail attachment to English and German messages, is one of the more serious threats this fall, said security experts.

"It's probably one of the worst cases we've seen in a month or two," said Mikko Hypponen, antivirus research director for F-Secure, which rated the virus as a level 2 on a scale of 1 to 3. "For some reason, this fall has been relatively quiet. This is one of the biggest cases we've had this fall. But compared to the same time last year and earlier this year, it's not that bad."

Like the other Sober viruses, the new version uses its own SMTP engine to send copies of itself to e-mail addresses it finds on infected computers. The infected computers will then later serve as a channel to download programs to unsuspecting users.

The Sober.i virus, featuring an attachment claiming to be naked photos of a blond model, is beginning to spread rapidly around the Internet. A blond, 21-year-old go-go dancer is sending e-mails with naked photos of herself attached and asking for work as model--or so you are led to think by the latest mass-mailing Sober variant to hit the Web.

But unless you live in a German-speaking country, the e-mail is not nearly so exotic. Sober.i is programmed only to send itself with the go-go dancer message to German-language domains, such as those ending in .de (Germany) or .ch (Switzerland).

The virus is also programmed to launch itself at the English-speaking world, but under the subject header of "delivery failure" or "oh god" in the hopes that someone will open an attached .zip file, which unleashes the virus.

"The German version is really interesting," said Graham Cluley, senior technical consultant for tech security company Sophos. "They claim to come from a German 21-year-old go-go dancer with blond hair. She is seeking employment as a model and she says she has attached some naked photos of herself. But of course the photos are the worm."

"In the English version, they don’t seem to be using sex at all. Maybe (the virus writer) thinks that the English aren't as interested in sex as our German cousins," Cluley said. "Perhaps he is making a national judgment about the countries."

Sober.i affects systems running Windows XP, 2000, ME, 98, 95, NT and Server 2003.

CNET News.com's Dawn Kawamoto reported from San Francisco. Dan Ilett of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 23 Talkback(s)
Window XP and 2000 allow that too
You have to configure the install that way but you can select the OS to always run as "Administrator" and many store bought systems are set up exactly this way. Less help calls and complaints this way.... (Read the rest)
Posted by: voska Posted on: 11/22/04 You are currently: a Guest | | Terms of Use
Well that explains it!  Linux User 147560 | 11/19/04
On average we work to late April to pay taxes.  Anton Philidor | 11/19/04
What Operating Systems Does It Affect Again?  itanalyst | 11/19/04
Idiotic Ballmer Quote Of The Week  itanalyst | 11/19/04
Idiotic itanalyst Quote Of The Week  NonZealot | 11/19/04
Considering ONLY Ms Operating Systems Are Involved  itanalyst | 11/19/04
Weak, very weak  NonZealot | 11/19/04
Wow, What a Novel Concept  itanalyst | 11/19/04
That was a comeback? (nt)  NonZealot | 11/19/04
Weak Very Weak...  eulagree | 11/19/04
Oops  NonZealot | 11/19/04
Brain Farts Happen A Lot To Microsoft People  itanalyst | 11/19/04
The hole is the design  Richard Flude | 11/19/04
Are you sure?  NonZealot | 11/19/04
Yes I'm sure  Richard Flude | 11/19/04
Glad to help  Immanuel Tranz-Mischen | 11/20/04
You still haven't done it, sorry  NonZealot | 11/20/04
I'll talk slower and use smaller words.  Immanuel Tranz-Mischen | 11/20/04
Window XP and 2000 allow that too  voska | 11/22/04
Unfornutely I Have To Use...  eulagree | 11/19/04
Same As Me (Add AVG as Anti-Vir)  BanjoPaterson | 11/20/04
Help me out here.  Immanuel Tranz-Mischen | 11/20/04
A Windows problem (as usual), compounded by a stupid user problem..  shawkins | 11/22/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More