All the latest UK technology news, reviews and analysis

Sober.c more toxic than first thought

by Robert Jaques

22 Dec 2003

Be the first to comment

  • Tweet this

The McAfee Anti-Virus Emergency Response Team (Avert) has today increased its original low-risk threat assessment of the 'moderately prevalent' Sober.c worm to 'medium risk' status.

Sober.c contains its own SMTP engine and targets email addresses which it harvests from the victims' machines.

Once activated, it emails itself to the user's Microsoft Outlook address book with outgoing messages constructed using its SMTP engine. The messages may be written in either English or German, and the attachment filename can vary.

Users should immediately delete any email containing the following:

Subject:

  • Betr: Klassentreffen
  • Testen Sie ihren IQ
  • Bankverbindungs- Daten
  • Neuer Dialer Patch!
  • Ermittlungsverfahren wurde eingeleitet
  • Ihre IP wurde geloggt
  • Sie sind ein Raubkopierer
  • Sie tauschen illegal Dateien aus
  • Ich hasse dich
  • Ich zeige sie an!
  • Sie Drohen mir
  • you are an idiot
  • why me?
  • I hate you
  • Preliminary investigation were started
  • Your IP was logged
  • You use illegal File Sharing ...
Attachment:
  • www.iq4you-german-test.com
  • www.freewantiv.com
  • www.free4manga.com
  • www.free4share4you.com
  • www.tagespolitik-umfragen.com
  • www.onlinegamerspro-worm.com
  • www.freegames4you-gzone.com
  • www.boards4all-terror432.com
  • www.anime4allfree.com
  • www.animepage43252.com
  • yourmail
  • alledigis
  • aktenz

Attachments may end in any one of the following extensions and be preceded with .txt or .doc, and/or a random number:

  • com
  • bat
  • cmd
  • pif
  • scr
  • exe

After being executed, Sober.c extracts target email addresses from the victim's machine and writes them to the file SAVESYSS.DLL in the SysDir.

Two other copies of the worm are then dropped into SysDir, with varying filenames. For example, 'SysDir\ONDMONSTR.EXE' and 'SysDir\DATMSCRYPT.EXE'.

Avert warned in an advisory: "These two latter files are responsible for monitoring and maintaining that the worm stays resident in memory.

"Upon termination of one worm processes, another copy will restart the terminated process very quickly.

"Two processes run on the victim machine in order to ensure the worm stays memory resident."

More information on the Sober.c worm can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

c# or asp.net Software Developer

Job Specification For: Software Developer...

Project Manager for UI Development

A global Investment Bank requires a Project Manager to...

Web Developer, .Net Software Developer - ASP.Net, C#, HTML, CSS

Web Developer, .Net Software Developer - ASP.Net, C...

Verint Voice Recording Support Engineer

Verint Voice Recording Support Engineer (Verint / Nice...

To send to more than one email address, simply separate each address with a comma.