CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Experts Say New Sobig Virus Could Strike Any Day image
Worms
Experts Say New Sobig Virus Could Strike Any Day
Mon August 25, 2003 07:25 PM ET

SAN FRANCISCO (Reuters) - A new version of the Sobig.F e-mail virus that has plagued computers worldwide could arrive any day, even before the latest variant is timed to expire on Sept. 10, security experts said on Monday.

Another virus could be released any time, said Steve Trilling, research director with the Security Response Team at Symantec Corp. SYMC.O , a U.S.-based security company. We can never be complacent when one threat seems to die down.

Mikko Hypponen, manager of anti-virus research at Finland-based F-Secure Corp, said one of the five prior versions of Sobig surfaced before the previous version expired. Sobig.E began circulating June 25, one week before Sobig.D was set to expire, he said.

The first version of Sobig arrived in January and had no expiration date. It was followed about four months later by Sobig.B. More sophisticated versions followed one week to three weeks after each preceding version, according to Hypponen.

The latest version, Sobig.F, first emerged a week ago and spread to hundreds of thousands of Windows-based computers, Hypponen said. Some 200 million e-mails have been sent over the Internet by infected computers, he estimated.

Sobig.F spreads when unsuspecting computer users open file attachments in e-mails with headings like Thank You!, and Re: Details. Once the file is opened, Sobig.F resends itself to e-mail addresses from the infected computer, using random names as the sender.

Sobig.F was programmed to send infected e-mails to one of 20 master computers to receive more instructions on Friday and Sunday, but both attacks failed when the 20 computers were taken off line by computer security specialists.

Infections have declined since last week, falling to a little under 100,000 affected computers by Monday, according to Tokyo-based anti-virus software maker Trend Micro Inc.

Authorities said Sobig.F was initially released on several Usenet news groups, which are Internet forums where people with similar interests can post messages and share photos.

Sobig.F was posted to news groups with names like alt.binaries.pictures.erotica and a few other adult-oriented news groups by someone using a stolen credit card, said Mike Minor, chief technology officer of Easynews.com.

Reuters
Posted on Wednesday, 27 August 2003 @ 05:05:00 UTC by phoenix22 (727 reads)
[ Trackback ]
image

"Experts Say New Sobig Virus Could Strike Any Day" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· News.com
· Microsoft
· HotScripts
· W3 Consortium
· More about Worms
· News by phoenix22


Most read story about Worms:
Kama Sutra/Blackworm Worm Timebomb

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer