W32.Sober-K-mm on the loose
W32.Sober-K-mm on the loose
R E L A T E D   C O N T E N T
ADVERTISEMENT

Mutant Sober worm spreading fast

Security firm intercepts 1,400 copies of latest mass-mailer variant

Steve Ranger, vnunet.com 21 Feb 2005
ADVERTISEMENT

A newly discovered variant of the mass-mailing Sober email worm is spreading rapidly and has already been spotted in the UK, according to MessageLabs.

The email security company said that it has intercepted 1,400 copies of W32.Sober-K-mm since 5am GMT this morning in Germany, France, the US and the UK.

Sober-K-mm sends itself as an attachment and creates random subject lines and body texts in either English or German, depending on the email addresses harvested by the worm.

It can also show a fake notice from antivirus vendors warning about a new version of the virus, and attempts to dupe users into clicking on the attachment which contains the worm by claiming that it contains a software patch.

But computer users who activate the file attached in the email invoke the virus, which harvests email addresses from the computer's hard drive.

Subject lines in the email may include 'Alert! New Sober worm', 'Paris Hilton Sex Videos', 'You visit illegal websites' and 'Your new Password'.

Once activated, Sober.K-mm drops several copies of executable files onto an infected computer with 'filenamescsrss.exe', 'winlogon.exe' and 'smss.exe'.

The worm modifies the registry key Software\Microsoft\Windows\CurrentVersion\Run so that it executes on startup. It then displays the contents of the file (systemdrive%/windows/temp/doc_data-text.txt) in notepad.

See also:

Infected email appears to come from FifaPromise of World Cup tickets hides deadly payload  03 May 2005
You've got mail, but be careful  19 Apr 2005
Trojan-based attacks on the wane as mass-mailers increaseThe advice remains the same: do not click on attachments  02 Mar 2005
Top 10 viruses in February 2005But Bagle and Sober will be the ones to watch  01 Mar 2005
Emails claim to contain adult footage of society heiressAdult footage used as social engineering hook  21 Feb 2005
Virus displays nationalist sloganMalicious code infects executable files  16 Feb 2005
Email contains a spoofed 'from' addressBitDefender dismisses infection as work of Romanian student  21 Jan 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Software Test Engineer 6 Weeks Contract £ 35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements ... more >
| JAM Recruitment
Software Test Engineer 3 Months Contract £35 per hour Wiltshire We have an urgent need for a Software Test Engineer. Main Duties: ·Sound understanding of full software lifecycle ·Solid experience in requirements analysis ·Requirements based ... more >
| Aston Carter
Major Investment Bank requires a Business Analyst to work within reference data IT. The reference data IT function is responsible for the three internal systems. One of the systems is a strategic repository for Client ... more >
| JAM Recruitment
Job Ref: CY - 27021979 Package: £25 – 42,000 +Bens Location: YORKSHIRE Job type: Occupational Health Position type: Permanent Hours: Full time Contact name: Mr Colin Youle Contact Company: JAM HUMAN RESOURCES Are you a ... more >
More job opportunities