SoBig.F Worm Floating Around: Warning!

Thread Tools
 
Search this Thread
 
Old 08-19-2003, 09:40 PM
  #1  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo
SoBig.F Worm Floating Around: Warning!

http://securityresponse.symantec.com...obig.f@mm.html

W32.Sobig.F@mm is a mass-mailing, network-aware worm that sends itself to all the email addresses it finds in the files with the following extensions:


.dbx
.eml
.hlp
.htm
.html
.mht
.wab
.txt

The worm uses its own SMTP engine to propagate and will attempt to create a copy of itself on accessible network shares.

Email Routine Details
The email message has the following characteristics:

From: Spoofed address (which means that the sender in the "From" field is most likely not the real sender).
The worm may use the address admin@internet.com as the sender.

Subject:
Re: Details
Re: Approved
Re: Re: My details
Re: Thank you!
Re: That movie
Re: Wicked screensaver
Re: Your application
Thank you!
Your details

Body:
See the attached file for details
Please see the attached file for details.

Attachment:
your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif

NOTE: The worm de-activates on September 10, 2003. The last day on which the worm will spread is September 9, 2003.

Symantec Security Response has developed a removal tool to clean the infections of W32.Sobig.F@mm.
This one has the potential to be BIG! It's already slowing down the 'net in a bunch of places (intranets in large companies are being hit especially hard).

As always, if you open up attachments that seem odd or are unexpected you are just playing with fire. Always keep your virus databases up to date and exercise common sense/caution.

My motto: If you get bit, it's a bit of your own fault.

Watch out, Peeps!

P.S. No posts in an hour? You guys are sad! Is this thing on? Helllloooo?
__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Old 08-19-2003, 09:41 PM
  #2  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo
Boom: 8 calls about it today - 1 infection (that user can NEVER leave attachments alone, DAMMIT!). Howzabout you?
__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Old 08-19-2003, 10:03 PM
  #4  
Registered User
iTrader: (4)
 
BoOm's Avatar
 
Join Date: Nov 2002
Location: Honolulu, HI
Posts: 3,462
Car Info: 2008 MB C350S Chip/Exhaust 268whp
none so far, my off day
BoOm is offline  
Old 08-19-2003, 10:09 PM
  #5  
Registered User
iTrader: (33)
 
iNfEk's Avatar
 
Join Date: Nov 2002
Location: Boostin' troubles away - 4EAT Memories 12.87@103.2
Posts: 10,455
Car Info: 51E LHD V7 STI (2.0)
yup... at work my exchange server encountered 10+ of these...

Jon
iNfEk is offline  
Old 08-20-2003, 01:23 PM
  #6  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo
http://www.msnbc.com/news/954470.asp?0cv=CB10

Aug. 20 — This week’s computer nuisance, the SoBig virus, continued its march around the Internet Wednesday, infecting thousands of computers and hundreds of corporations. Even innocent bystanders were also hit by SoBig’s fallout — on Wednesday, many inboxes were overloaded with stray e-mails created by the virus. The outbreak comes on the heels of last week’s MSBlaster worm, which may have infected over 1 millions computers.
__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Old 08-20-2003, 01:58 PM
  #7  
Registered User
iTrader: (4)
 
dropkick_muppet's Avatar
 
Join Date: May 2003
Location: your friendly neighborhood hairpin
Posts: 2,341
Car Info: '03 PSM Sedan
i've gottena bunch of these on my Mac OS X box which look like they're warnings from other mailservers. it's getting downright irritating.
dropkick_muppet is offline  
Old 08-20-2003, 01:59 PM
  #8  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo
I've received (automated blocking, but still getting the notification) of 200+ infected messages/bounces since 5pm yesterday. AMAZING!
__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Old 08-20-2003, 02:06 PM
  #10  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo


My Cloudmark Spamfilter automatically redirects these messages (and AVG deletes them). Good setup.

It's still irritating due to the fact that I IMAP into my work e-mail from home sometimes... ARGH!
__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Old 08-20-2003, 02:06 PM
  #11  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo
P.S. LC, can we do distance learning creds so I can get my Master's while you're on the green?
__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Old 08-20-2003, 02:52 PM
  #13  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo

__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Old 08-20-2003, 04:47 PM
  #14  
Pr0n King
Thread Starter
iTrader: (3)
 
IS2Scooby's Avatar
 
Join Date: Nov 2002
Location: The Land of Rocks
Posts: 26,618
Car Info: Turncoat Turbo
Sobig.F is Fastest Spreading Virus Yet
- August Becoming Epic Month for Worms

Several security companies declared that the Sobig.F mass-mailing
worm is the fastest spreading virus yet, surpassing the initial
infection rates of Klez, the LoveBug, Kournikova and other
infamous malware.
http://entmag.com/news/article.asp?EditorialsID=5921
__________________
Best Car Insurance | Auto Protection Today | FREE Trade-In Quote
IS2Scooby is offline  
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
bpang1
Hawaii
11
08-10-2006 12:16 AM
OakosAutomotive
Vendor Group Buys/Specials
5
11-24-2004 09:00 AM
dr3d1zzl3
Bay Area
2
02-24-2004 06:53 PM
kawshon1
Hawaii
5
08-31-2003 12:07 PM



Quick Reply: SoBig.F Worm Floating Around: Warning!



All times are GMT -7. The time now is 05:08 PM.