News

New Sober Poses As Good Samaritan

InformationWeek
InformationWeek

Another version of the tenacious Sober mass-mailed worm blew onto the Internet as it tried to fool recipients into opening mail.

Another version of the tenacious Sober mass-mailed worm blew onto the Internet Tuesday as it tried to fool recipients into opening mail tagged as "I've_got your EMail on my_account!"

The worm, which spread quickly in the United Kingdom early Tuesday morning -- one security firm was reporting nearly 88,000 copies had hit U.K. businesses by 11 a.m. local time. Another listed it as the fifth-most common worm of the last 24 hours, beaten only by the even more pernicious Netsky and Zafi.


More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Like earlier Sober variants, this one -- dubbed Sober.m by some anti-virus vendors, Sober.n by others -- can appear in English or German, spreads by hijacking addresses from infected PCs, and bundles its payload in a compressed .zip file.

"Someone is sending your private e-mails on my address," Sober reads. "It's probably an e-mail provider error! I've got over 10 mails on my account, but the recipient are you. I have copied all the mail text in the windows text-editor for you & zipped then."

"The virus plays on people's desire to be a good net citizen," said Graham Cluley, a senior technology analyst with Sophos in a statement. "Anyone who receives a message like this may feel duty bound to open the attachment and investigate how their computer has been sending erroneous e-mail. But such good intentions could result in a nasty infection."

Sober.m/n also tries to disable Microsoft's AntiSpyware application, and its Malicious Software Removal Tool, which is an integral part of each month's security update from the Redmond, Wash.-based developer, and targets Sober among the malware it seeks out and destroys.

Most anti-virus firms listed the newest Sober as a medium, or lower, threat.

Related Reading


Informationweek Discussions

Start the Discussion


InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links