Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-19-2004, 08:54 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,574
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
WORM_SOBER.I
As of November 19, 2004, 1:31 AM (GMT - 08:00), TrendLabs has declared a Yellow Alert to control the spread of this malware, which is spreading via email in Germany, France, and Austria. Users are advised to be wary of email messages containing the following message body:

*-*-* Mail_Scanner: No Virus
*-*-* SKYNET- Anti_Virus Service
*-*-* http://www.skynet.be

It sends similar content in German to email addresses in Germany, Austria, Liechtenstein, Switzerland, and other areas (it checks target addresses for country-level domains):

*-*-* X-MS_Scanner: Kein Virus erkannt
*-*-* Attachment-Scanner: NO VIRUS
*-*-* Anti_Virus: Es wurde kein Virus gefunden

For additional information on the email that this worm sends out, please refer to the Technical Details section.

Users should note that the worm messages are spoofed and may appear to be sent by a familiar source.

Network administors who would like to block email messages associated with this worm can check for more email details in the Technical Details section. This worm may cause some increase in network traffic. Distribution, however, may not necessarily be localized, and the worm may not severely affect corporate mail servers since it obtains email targets from files instead of the global address book.

This worm arrives as an email attachment that executes and infects upon manual execution.

A good visual clue to spot this worm is the fake WinZip message box that it displays:


This message box is likely designed to tricked into thinking that the worm file is damaged and does not actually run. In contrast, this worm will have likely infected systems on which the message box has been displayed, especially machines with no antivirus protection.

This worm runs on Windows 95, 98, ME, NT, 2000, and XP.
Reply With Quote
Posted


Reply

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zotob Suspects Arrested Mobo News & Announcements 0 09-05-2005 09:30 PM
Mytob Worm LJM Master Security Alerts and vulnerabilities 0 03-31-2005 01:04 PM
W32/VBSun-A worm pmf45 Security Alerts and vulnerabilities 1 01-17-2005 11:54 AM
Cellery worm Mobo Security Alerts and vulnerabilities 0 01-13-2005 07:42 AM
Santy.a Worm Mobo Security Alerts and vulnerabilities 0 12-21-2004 12:07 PM



All times are GMT -5. The time now is 03:24 AM.


Firefox 2