All the latest UK technology news, reviews and analysis

Latest Sober mutant targets soccer fans

by Robert Jaques

03 May 2005

Be the first to comment

  • Tweet this

Security experts have warned of a newly discovered mutant of the Sober worm which attempts to lure users into opening infected attachments by promising World Cup football tickets.

McAfee's Avert antivirus division has branded the W32/Sober.p@MM worm, also known as Sober.p, as "prolific".

The mass-mailing threat contains its own SMTP engine to construct outgoing messages, which are written in German or English.

It harvests addresses from local files to send itself, producing emails with a spoofed 'From' address.

"The attachment comes in the form of a .zip file that contains an executable file named 'winzipped-text_data.txt.pif'," said the Avert warning.

"The filename contains a dual extension: the first is .txt, followed by many spaces then .pif. When the Zip archive is extracted and the .pif file is manually executed, the virus may display a fake error message."

However, Avert said that users would need to manually extract the executable from the .zip file and manually run the attachment in order to be infected.

The following German text, with the spoofed sender listed as Fifa, has been detected in versions of the infection currently spreading in the wild: "Tickets fur die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei."

An example of a randomly generated English message is as follows:

From: (address is spoofed)
Subject: Your Password
Body: Account and Password Information are attached!
Visit: http://www/.[sender's domain]
*** AntiVirus: No Virus found
*** "[recipient's domain] " Anti-Virus***
http://www/.[recipient's domain]

More information on Sober.p and how to remove it can be found at McAfee's website here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

11%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Systems Engineer

Lead/Project Engineer Microsoft VMware SAN Networking...

Application Tester

SENIOR APPLICATION TESTER. Assen, Netherlands. €1k-€1...

Project Manager - Trading Systems - up to £85'000

Project Manager - Trading Systems - up to £85'000...

SAS Senior Analyst- Direct Marketing Agency

SAS Senior Analyst- up to £55,000 Industry: Marketing...

To send to more than one email address, simply separate each address with a comma.