Advertisement
Promo

Security threats Toolkit

Sober worm makes a comeback

Dan Ilet ZDNet.co.uk

Published: 19 Apr 2005 17:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Virus writers have resurrected the Sober worm with a new variant that is spreading quickly over the Internet, according to security experts on Tuesday afternoon.

The worm, dubbed Sober.M, reports email addresses of victims back to its anonymous author — a technique known as harvesting. Spammers typically buy these fresh email addresses to add to their lists of email recipients.

The email containing the worm is written in bad English with the subject line: "I've got your email on my account."

"It looks like the virus writer is deliberately using broken English to [convince] people the email is not a virus," said Graham Cluley, senior technology consultant for antivirus firm Sophos.

Sophos said that the worm was fifth most reported virus over the last 24 hours, closely followed by versions of Zafi and Netsky. It's thought that all the major anti-virus companies are now offering protection against the worm, so users should updated their virus protection.

Sober.M is a mass emailing virus that spreads as a .zip file attachment. The email containing the worm sends itself in German or English language. The English version of the email is below.

Subject line: I've_got your EMail on my_account!

Message text:

Hello,
First, Very Sorry for my bad English.
Someone is sending your private e-mails on my address.
It's probably an e-mail provider error!
At time, I've got over 10 mails on my account, but the recipient are you. I have copied all the mail text in the windows text-editor for you & zipped then. Make sure, that this mails don't come in my mail-box again. bye

Attached file: your_text.zip

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
67 out of 176 people found this useful


Full Talkback thread

1 comment

  1. Fundamental design flaws in Windows make this poss... Olav Petri

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters