PC Review Forums Software Security, Spyware and Viruses New wave of Sober e-mails on Jan 5

Reply
 
Thread Tools Rate Thread
Old 08-12-2005, 12:10 PM   #1
muckshifter
Captain Crunchie, Retired
Super Moderator
 
muckshifter's Avatar
 
Join Date: Mar 2002
Location: In a Hovel
Posts: 17,435
Send a message via MSN to muckshifter
Trader Rating: (1)
Exclamation New wave of Sober e-mails on Jan 5

A new outbreak of Sober may be coming, security experts have warned, even as e-mail systems worldwide work to get rid of the last infestation of the mass-mailing worm.

The next attack is hard-coded in the version of Sober that hit the Net on Nov. 22, iDefense, part of VeriSign, said in a statement Wednesday. Infected machines are set to download instructions and potentially mail out a new wave of Sober e-mails on Jan. 5, the security company said.

That leaves Internet users with less than a month to shore up their defenses against Sober, which was the most prolific worm in 2005, security experts at iDefense said.

"The attack could have a significant detrimental effect on Internet traffic, as e-mail servers are flooded," iDefense said.

The possible outbreak could be stopped, said Mikko Hypponen, chief research officer at Finnish antivirus company F-Secure. The worm is set to download instructions from a number of sites hosted on the systems of free Web space providers. These are located mostly in Germany and Austria, he said.

"These free Web site hosters should be able to block those specific URLs this virus is trying to download from in January, so with any luck nothing will happen," Hypponen said. "There is plenty of time for the Internet service providers and the antivirus people to act."

The latest Sober variant is still causing headaches for e-mail users. Microsoft last week said the load of infected messages is causing an unspecified delay for mail sent to its Hotmail and MSN e-mail services. Sober accounted for almost 40 percent of all the viruses stopped by F-Secure on Wednesday, Hypponen said.

The Sober family of mass-mailing worms appears to be the work of a German speaker or group of German speakers, iDefense said. Nearly 30 variants of the worm have surfaced since October 2003, the company said.

Sober arrives as an e-mail with a malicious attachment. The text of the e-mail can vary and can be either in German or English. Some Sober e-mails have included Nazi propaganda, while others posed as messages from the FBI, the U.K.'s National High-Tech Crime Unit and the CIA.

iDefense believes a Jan. 5 attack may be spreading more Nazi propaganda. The date coincides with the 87th anniversary of the founding of the Nazi party.

http://news.zdnet.com/2100-1009_22-...tml?tag=nl.e589
__________________
I'm not grouchy by nature, it takes constant effort.



Flickr

Every day I beat my own previous record for number of consecutive days I've stayed alive.
muckshifter is offline   Reply With Quote
Old 08-12-2005, 02:01 PM   #2
gabriella
Sunflower Queen
 
gabriella's Avatar
 
Join Date: Jun 2004
Location: North of England
Posts: 1,340
Trader Rating: (3)
Default

Thanks for the warning Mucks!!!

Gabs xx
gabriella is offline   Reply With Quote
Old 08-12-2005, 02:20 PM   #3
PotGuy
Wholegrain Goodness
 
PotGuy's Avatar
 
Join Date: Sep 2005
Location: Keele Uni, Staffs
Posts: 1,825
Trader Rating: (1)
Default

how do you stop yourself becoming infected?
__________________



AMD Athlon 64 3700+ @ 2.66ghz | Zalman CNPS9500 | Asus A8N-SLi Premium | Asus GeForce GTX 275 | Corsair TX 650w PSU | 4 x 512mb Crucial Ballistix | 2 x 250gb Hitatchi Deskstar T7K250 | Creative X-Fi Gamer | Sony Floppy Drive | Logitech X-540 5.1 | Thermaltake Tsunami Dream VA3000BWA | Samsung SyncMaster 930BF 19" | Saitek Eclipse Keyboard | Logitech MX518 |
PotGuy is offline   Reply With Quote
Old 08-12-2005, 02:23 PM   #4
gabriella
Sunflower Queen
 
gabriella's Avatar
 
Join Date: Jun 2004
Location: North of England
Posts: 1,340
Trader Rating: (3)
Default

I think it's a question of just being extremely careful in relation to what you open - I have had absolutely loads of the current ones trying to get through via email. It takes a while for the various AV companies to provide cures.

Take care!

Gabs xx
gabriella is offline   Reply With Quote
Old 08-12-2005, 02:25 PM   #5
CITech
Crunchie Eater
 
CITech's Avatar
 
Join Date: Aug 2005
Location: Channel Islands
Posts: 909
Send a message via ICQ to CITech Send a message via AIM to CITech Send a message via MSN to CITech Send a message via Yahoo to CITech
Trader Rating: (0)
Default

I think I might leave my PC switched off on 5th January!

(Only kidding)
__________________
System Configuration:
Proc: AMD Athlon 64 X2 4800+ w/4x 1GB 3200 DDR400 RAM
Video: 2x nVidia GeForce 7800GTX 256MB driving 4x 20" @ 1600x1200
Storage: 2.6TB RAID

CITech is offline   Reply With Quote
Old 08-12-2005, 08:51 PM   #6
muckshifter
Captain Crunchie, Retired
Super Moderator
 
muckshifter's Avatar
 
Join Date: Mar 2002
Location: In a Hovel
Posts: 17,435
Send a message via MSN to muckshifter
Trader Rating: (1)
Cool

Quote:
Originally Posted by PotGuy
how do you stop yourself becoming infected?
Use Linux.



Quote:
"These free Web site hosters should be able to block those specific URLs this virus is trying to download from in January, so with any luck nothing will happen," Hypponen said. "There is plenty of time for the Internet service providers and the antivirus people to act."


__________________
I'm not grouchy by nature, it takes constant effort.



Flickr

Every day I beat my own previous record for number of consecutive days I've stayed alive.
muckshifter is offline   Reply With Quote
Old 08-12-2005, 09:31 PM   #7
gabriella
Sunflower Queen
 
gabriella's Avatar
 
Join Date: Jun 2004
Location: North of England
Posts: 1,340
Trader Rating: (3)
Default

Ah we know there's time yet BUT will they be ready and prepared???

Does Linux make you immune then Mucks?? Is it like a Harry Potter invisibility cloak???

Gabs xx
gabriella is offline   Reply With Quote
Old 08-12-2005, 09:47 PM   #8
muckshifter
Captain Crunchie, Retired
Super Moderator
 
muckshifter's Avatar
 
Join Date: Mar 2002
Location: In a Hovel
Posts: 17,435
Send a message via MSN to muckshifter
Trader Rating: (1)
Cool

Quote:
Originally Posted by gabriella
Ah we know there's time yet BUT will they be ready and prepared???

Does Linux make you immune then Mucks?? Is it like a Harry Potter invisibility cloak???

Gabs xx
Don't know about Mr Potter but I do have an invisible cloak ... I named it Firewall Fred.

Windows "nasties" cannot "run" on Linux ... I can house them for you and pass them on in an email, but I won't get infected. Had me jabs two weeks ago. Have a peek in the Linux forum Gabby, I have a nice thread on Linux viruses you may want to 'borrow' when you need it.

Oh, a Firewall will not protect you if you "click on an email" to open ...



Don't open any emails.
__________________
I'm not grouchy by nature, it takes constant effort.



Flickr

Every day I beat my own previous record for number of consecutive days I've stayed alive.
muckshifter is offline   Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off