ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Thanksgiving will bring a Sober hangover

Tom Espiner ZDNet.co.uk

Published: 25 Nov 2005 17:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The latest outbreak of the Sober worm will accelerate as US computer users turns the PCs back on after the Thanksgiving holiday, security firm MessageLabs warned on Friday.

Business users will return from the break and open mail that has been sitting in their inbox since the first hours of the attack, which could include infected emails, MessageLabs warned.

Sober-Y spreads in emails that pretend to come from the FBI or which claim to contain video clips of celebrity heiress Paris Hilton. It is activated if the user runs an email attachment.

"Once this worm has been activated behind a firewall, it's very difficult to identify, as most firewalls don't inspect outbound data traffic." said Paul Wood, senior analyst at MessageLabs.

Businesses may also be suffer if their mail servers are swamped by email traffic caused by infected home users.

"Businesses may suffer collateral damage due to the volume of mail hitting people's mailservers. Even secure business servers may be affected, as spam still consumes bandwidth before it can be rejected," said Wood.

This week's Sober attack is the largest that MessageLabs has seen in 2005. "This is the biggest outbreak of a mass-mailing virus all year. It is a concern because we thought we'd seen the last of mass-mailers," said Wood.

Experts at antivirus company Sophos also see Sober-Y as a major threat. Globally, one in 18 emails are now infected by the Sober worm, Sophos said on Friday.

"The new Sober worm is spreading at such a rate that it now accounts for over 80 percent of all viruses reported. It is currently the most widespread computer virus in the world," said Graham Cluley, Sophos' senior technology analyst.

If activated, Sober-Y attempts to turn off security software on the user's computer. The zip file in the attachment contains a copy of the worm with the filename File-packed_dataInfo.exe. The worm then scans the user's hard drive for other email addresses, in its search for other computers to infect, Sophos said.

MessageLabs believes Sober-Y could continue to spread in large quantities for some time, as the auto switch-off function used in most mass-mailing malware hasn't been enabled.

"Normally you would see an auto switch-off function included in the code, because controllers don't want to draw too much attention to their botnets — so there's a cut-off date, and the outbreak stops. We haven't seen a cut-off date in this Trojan, so this outbreak could continue for some time," said Wood.

This outbreak is likely to be financially motivated. MessageLabs believes that cybercriminals may be trying to increase the number of compromised computers they have access to before Christmas, for financial gains.

"We believe botnet controllers are bolstering their botnets before Christmas, to sell access to spammers," said Wood.

The source code for Sober originated in Germany, but is now being used by Eastern European criminal gangs, said MessageLabs.

IT managers were advised to actively monitor their outbound email traffic for evidence that they have been infected by Sober-Y, and not just rely on a firewall. "It's certainly a challenge for organisations to control email traffic just by using a firewall. IT managers can manage this particular outbreak by protecting HTTP and SMTP traffic," said Wood.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
52 out of 143 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Risk Deals Desk Analyst London Oil Major

Alternatively you will have future options to more into an operational role or you could continue to specialise in a risk management function. Do you ...

Supplier Delivery Manager

Project Management Office (PMO) to forecast demand and requirements, and with UK Change to ensure that the requirements are defined adequately and ...

Are you a routing and swithing guru? Is installations what you do?

Take a lead role in problem determination and resolution when they do occur, with the provision of (paid) out-of-hours support and disaster recovery ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment