ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Third Sobig worm strikes, and more may follow

Matthew Broersma ZDNet.co.uk

Published: 02 Jun 2003 15:28 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A variant of the Sobig worm appeared over the weekend and is now spreading rapidly. This is the third Sobig variant to hit the Internet this year, and security experts believe more variants may already be in the pipeline.

Security analysts said the new version, W32/Sobig.C-mm, had already reached a "high level" outbreak status by mid-afternoon on Monday. Messagelabs, which offers email outsourcing to companies around the world, said it had stopped nearly 17,000 copies of the virus as of 14:00 British Summer Time, with 47 percent of those in the UK.

Because of the increasing spread of the virus, McAfee has upgraded its risk assessment of Sobig.C to medium.

To find out how to remove the Sobig.C worm from your system, click here.

The worm's main impact is to mass-mail itself to email addresses found in address books on the system, but such worms, when successful, can use large amounts of bandwidth. These can also be difficult to root out, because they spread via desktop PCs with minimal security.

Like its predecessor, Sobig.B, also known as Palyh or Mankx, the current worm also connects to the Internet and attempts to download hacking software onto the victim's computer.

The sites contacted by Sobig.C are not active, but Messagelabs said that the virus writer could activate them later. "He may just be playing possum," said Mark Toshack, a virus analyst with Messagelabs.

Toshack speculated that the virus writer might be purposefully releasing a series of short-term worms in order to improve his or her technique. Sobig.B appeared in mid-May and had a cut-off date of 30 May, and the current worm will not propagate on a computer whose clock reads 8 June or later; another variant may appear around that date, Toshack said. "He may be refining the virus."

Sobig.C on Monday rose to the No. 2 rank in Messagelabs' list of virus threats, although it is far behind the year-old W32/Yaha.E-mm, in the top spot, which infected about 63,000 emails over the past weekend alone. Sobig.A, dating from January, was in the No. 5 spot.

Sobig.C uses the same mass-mailing engine as its predecessors to propagate. Messages appear to come from bill@microsoft.com or another spoofed email address. The email can have one of several subject lines, such as "Approved" "Re: 45443-343556" or "Re: Application", while the body always reads: "Please see the attached file". The attachment is called "document.pif", "screensaver.scr" or another similar name, using a .pif, .txt or .scr extension.

However, the file is actually an executable. Besides spreading by email, it also copies itself to the "startup" directories on other computers on the network.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
60 out of 109 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Senior Medical Writer, 35,000 upwards - Cheshire

A leading healthcare communications company seeks an experienced Senior Medical Writer Cheshire An experienced Senior Medical Writer is required by a ...

SQL server Report Writer Required in the West Midlands

My West Midlands client is urgently looking for SQL report writer for a 3 month to start immediately. Market Rate. The suitable candidate should have ...

Content Editor / Writer - Central London

One of Huxley Associates media agencies are looking for a content editor/ writer to join them for a four month contract role starting as soon as ...

Discussions

David Long David Long

Defragging: Merits?

Thursday 24 July 2008, 10:30 AM

12 posts

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal