ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Seductive virus has Sobering consequence

Dan Ilet ZDNet.co.uk

Published: 19 Nov 2004 15:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A blonde, 21-year-old go-go dancer is sending emails with naked photos of herself attached and asking for work as model. Or so you are led to think by the latest mass-mailing Sober worm variant to hit the Web, Sober.I.

But unless you live in a German-speaking country, the email is not nearly so exotic. Sober.I is programmed only to send itself with the go-go dancer message to German-language domains - such as those ending in .de (Germany) or .ch (Switzerland), for example. The virus is also programmed to launch itself at the English-speaking world, but under the subject header of "delivery failure" or "oh god" in the hope that a user somehow opens an attached .zip file, which unleashes the virus.

"The German version is really interesting," said Graham Cluley, senior technical consultant for Sophos. "They claim to come from a German 21-year-old go-go dancer with blonde hair. She is seeking employment as a model and she says she has attached some naked photos of herself. But of course the photos are the worm."

"In the English version they don’t seem to be using sex at all," he added. "Maybe [the virus writer] thinks that the English aren't as interested in sex as our German cousins. Perhaps he is making a national judgement about the countries."

Antivirus firm F-Secure has given the virus a level 2 rating, the company's second highest rating for viruses. Many other companies, such as Panda Software and Trend Micro, have also reported that the virus is spreading rapidly, particularly through Germany.

The virus is a self-perpetuating program that sends itself to contacts stored in Microsoft Outlook. If executed, Sober.I copies itself to the registry to ensure it runs when the computer starts, and then begins to replicate itself. If the domain in an email address belongs to Switzerland (.ch), Germany (.de), Austria (.at) or Liechtenstein (.li), the worm executes the German version of itself from the 'blonde dancer'. If the domain is any other than those mentioned above the email is sent in English.

"It may have been written by a German," Cluley said. We've been given quite a number of reports across Europe. But that was true of earlier versions of it too."

Cluley added that people needed to keep their antivirus software updated as the best defence against the virus. He added that in most cases, companies should block executable code at the email gateway.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
101 out of 169 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

McAffee Anti Virus Rollout Engineer CRB Cleared

The role will require the following - - Experienced in field support - Windows 2000 / XP / Vista - Anti - Virus experience For an immediate telephone ...

Business Product Support Analyst - Spanish/German/French Speaking

Spanish, German or French. My client is a leading Software house who is seeking a talented Business product support analyst. Some of the activities ...

French/English- Web Project Manager- Reading- to 40,000 pa

Manager or Web Producer with fluent language skills in English and French. A leading Web Design Agency is currently looking to recruit a Project ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment