W32.Sober-K-mm on the loose
W32.Sober-K-mm on the loose
R E L A T E D   C O N T E N T
ADVERTISEMENT

Mutant Sober worm spreading fast

Security firm intercepts 1,400 copies of latest mass-mailer variant

Steve Ranger, vnunet.com 21 Feb 2005
ADVERTISEMENT

A newly discovered variant of the mass-mailing Sober email worm is spreading rapidly and has already been spotted in the UK, according to MessageLabs.

The email security company said that it has intercepted 1,400 copies of W32.Sober-K-mm since 5am GMT this morning in Germany, France, the US and the UK.

Sober-K-mm sends itself as an attachment and creates random subject lines and body texts in either English or German, depending on the email addresses harvested by the worm.

It can also show a fake notice from antivirus vendors warning about a new version of the virus, and attempts to dupe users into clicking on the attachment which contains the worm by claiming that it contains a software patch.

But computer users who activate the file attached in the email invoke the virus, which harvests email addresses from the computer's hard drive.

Subject lines in the email may include 'Alert! New Sober worm', 'Paris Hilton Sex Videos', 'You visit illegal websites' and 'Your new Password'.

Once activated, Sober.K-mm drops several copies of executable files onto an infected computer with 'filenamescsrss.exe', 'winlogon.exe' and 'smss.exe'.

The worm modifies the registry key Software\Microsoft\Windows\CurrentVersion\Run so that it executes on startup. It then displays the contents of the file (systemdrive%/windows/temp/doc_data-text.txt) in notepad.

See also:

Infected email appears to come from FifaPromise of World Cup tickets hides deadly payload  03 May 2005
You've got mail, but be careful  19 Apr 2005
Trojan-based attacks on the wane as mass-mailers increaseThe advice remains the same: do not click on attachments  02 Mar 2005
Top 10 viruses in February 2005But Bagle and Sober will be the ones to watch  01 Mar 2005
Emails claim to contain adult footage of society heiressAdult footage used as social engineering hook  21 Feb 2005
Virus displays nationalist sloganMalicious code infects executable files  16 Feb 2005
Email contains a spoofed 'from' addressBitDefender dismisses infection as work of Romanian student  21 Jan 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities