NameSilo

New Virus Spreading Worldwide - Could Be In Your Email Inbox

Spaceship Spaceship
Watch
Courtesy of C|NET - http://news.com.com/2100-1002_3-1020963.html?tag=fd_top

A new variant of the Sobig virus started spreading on Wednesday, raising the specter that spammers will have a host of new PCs to use as platforms for sending bulk e-mail.

Initial analysis by antivirus companies indicated that the mass-mailing computer worm, called Sobig.E, doesn't have a malicious payload. However, e-mail service provider MessageLabs believes spammers will use the virus's mail program on victims' computers to send anonymous messages.

"This is almost certainly being precipitated by a spammer that is trying to create more open relays to send spam," said Mark Sunner, chief technology officer for the U.K.-based company

An open relay is a computer that accepts e-mail bound for other destinations and then resends the messages anonymously. Using open relays allows spammers to hide the location from which they are sending bulk e-mail.

While there is no concrete proof that Sobig.E has been created and released by a spammer, Sunner said that many bulk e-mailers are already using computers infected with a previous variant of the computer virus to avoid leaving traces. Moreover, the fact that Sobig.E has an expiration date--it will stop spreading on July 14--suggests that the creator doesn't want its infection to turn into a full-blown epidemic, he said.

In reality, the program is spreading quite successfully as a Zip-compressed e-mail attachment. Copies of the worm have been seen in 16 countries--including the United States, the United Kingdom and the Netherlands--according to MessageLabs. The virus had produced less than 1,000 e-mail messages from infected computers in the first few hours, said Sunner. That's much smaller than Sobig.C, which was responsible for 32,000 e-mail messages containing the virus in its first 24 hours.

The virus appears in a recipient's in-box with the subject line "Re: Movie" or "Re: Application." The body of the message states, "Please see the attached zip file for details." The malicious program is contained in an 80KB attachment to the message. It infects any PC running a Microsoft Windows operating system when the attachment is opened.

Antivirus software maker Symantec planned to update its antivirus definitions midday on Wednesday to detect and remove Sobig.E. The company rated the virus a "2" on its five-point scale, with "5" being the largest threat. More than 30 of the Cupertino, Calif., company's clients had reported the virus to Symantec, said Sharon Ruckman, senior director of the company's security response team.

"That's pretty significant on the corporate side," she said.

To prevent infecting their computer, e-mail users shouldn't open attachments, even from people known to them, unless they specifically asked for the file first.
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Sobig.E Worm Email Clues

The subject of the email may contain the following:

Re: Application
Re: Movie
Re: Movies
Re: Submitted
Re: ScRe:ensaver
Re: Documents
Re: Re: Application ref 003644
Re: Re: Document
Your application
Application.pif
Applications.pif
movie.pif
Screensaver.scr
submited.pif
new document.pif
Re: document.pif
004448554.pif
Referer.pif

The attachment name(s), are as follows:

your_details.zip (contains details.pif)
application.zip (contains application.pif)
document.zip (contains document.pif)
screensaver.zip (contains sky.world.scr)
movie.zip (contains Movie.pif)

The message of the email, could also say: Please see the attached zip file for details.

If you see any of those clues listed above; delete that email immediately. Or just update your anti-virus software like the most of us are.

Clues, Courtesy of ZDNET: UK - http://news.zdnet.co.uk/story/0,,t269-s2136630,00.html
More Information, Courtesy of Symantec Security Response - http://securityresponse.symantec.com/avcenter/venc/data/[email protected]
 
Last edited:
0
•••
woah got it thank goodness you warned me (tho I wasn't gonna open it anyway!)
 
0
•••
Sobig.E Virus Email Clues Are Updated!

:kickass:
 
0
•••
Super post Sohil, here's a great place to have your computer screened for free, you just might be surprised what you have lurking around in your system. I highly recommend that everyone have their system checked here, they're top notch as far as I'm concerned, and it's free!


http://housecall.trendmicro.com
 
0
•••
I'm so glad I use Linux!
 
0
•••
I really don't understand why people insist on making new viruses. How would you get pleasure out of it?
 
0
•••
Got one. From some hardware supply co. Titled Re: Your application. your_details.zip Norton Quarantined it upon receiving it.
 
0
•••
i got that yesterday

but deleted it :)
 
0
•••
i didn't get it(thankfully)
 
0
•••
I Got 2 emails with that virus! D-:
 
0
•••
Thanks for the warning Sohil..
I'll watch for that...
 
0
•••
I get these things in batches...as many as 40 in a day between my 20+ email addresses.

So far I;ve had 5 of this one hit in the last 24 hours so it looks like it is just getting underway or it wont be as bad as the last one.
 
0
•••
I got another email today! D-:
 
0
•••
0
•••
5 in the last 2 hours....
 
0
•••
Originally posted by Larry
5 in the last 2 hours....

D-:

I only got 3 in last 2 days

D-:
 
0
•••
ahh I've gotten SO many of those e-mails! I'm glad I'm smart enough not to open them.. that's so scary.
 
0
•••
Whoa... I had the your_details.zip in an email called Movies. I opened it :notme: But the attachment was removed by Outlook, so... Erm... What do I do? LOL.
 
0
•••
Originally posted by Jenni Sedai
Whoa... I had the your_details.zip in an email called Movies. I opened it :notme: But the attachment was removed by Outlook, so... Erm... What do I do? LOL.

Scan your computer! :)
 
0
•••
It takes 14.5 hours to scan this computer -_-;; Stupid loads of files. I didn't open the attachment though but I shall anyways.
 
0
•••
lol just for safety.. where can I get a free virus scanner to make sure? :)
 
0
•••
Originally posted by Jenni Sedai
It takes 14.5 hours to scan this computer -_-;; Stupid loads of files. I didn't open the attachment though but I shall anyways.

If you didn't open any attachment, you are fine then. :)

:kickass:
 
0
•••
0
•••
it came. it saw. it got destroyed. hehe.
i got rid of that junk the instant it landed in my inbox.
 
0
•••
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back