This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

More Sober Variants

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=880
Last Updated: 2005-11-22 23:33:21 UTC
"We continue to receive reports about new Sober variants. Thanks to Chris M. for supplying a very comprehensive list of links (see below). the CME system assigned these variants the ID CME-681.

IMPORTANT: Antivirus software does not provide any reliable protection against current threats. Viruses like Sober tend to change every few hours well in advance of AV signature updates. The fact that an attachment did not get marked is no indication that it is harmless. We do receive reports of up to date versions of AV software missing some of the recent Sober variants.

Sober is now considered the "largest virus outbreak of the year" according to F-Secure…
…Please do not have your AV software reply to viruses. All commonly seen viruses use fake 'From:' headers. Rumor has it that fbi.gov is having a hard time keeping up with all the bounces in the first place…None of these does anything new or fancy. They all try to trick users into executing the attached ZIP file. The best defense at this point is probably to strip ZIP file attachments.
The subjects and the body text vary widely. Many of them suggest that the attachment was sent by some government authority (FBI, CIA) and requests that you open it in order to verify some charges brought against you. A version in German refers to the 'BKA' (German equivalent of FBI). Other versions claim to be sent by banks and ask you to open an attachment to verify account details.

List of Links:

Symantec (Level 3 risk) W32.Sober.X@mm
http://securityresponse.symantec.com/[removed]

McAfee (currently Low risk) W32/Sober@MM!M681
http://vil.nai.com/vil/content/v_137072.htm

Trend Micro (Medium risk) WORM_SOBER.AG
http://www.trendmicro.com/vinfo/virusencyc…RM%5FSOBER%2EAG

F-Secure (Radar Level 2) Sober.Y
http://www.f-secure.com/v-descs/sober_y.shtml

Sophos (low risk) W32/Sober-{X, Z}
http://www.sophos.com/virusinfo/analyses/w32soberx.html
http://www.sophos.com/virusinfo/analyses/w32soberz.html

Computer Associates (Medium risk) Win32.Sober.W
http://www3.ca.com/securityadvisor/virusin…s.aspx?id=49473

Panda Antivirus (Medium risk) Sober.Y
http://www.pandasoftware.com/virus_info/en…us=92673&sind;=0

———————————————–

- http://www.f-secure.com/weblog/
November 22, 2005
"We just took Sober.Y to a Radar Level 1 alert. Level 1 is the highest alert we have. And this is the first Level 1 alert we've done in months.
Several millions of infected emails have been seen by internet operators over the last hours.
One of the reasons why this email worm seems to be so successful in spreading is that some of the messages it sends are fake warnings from FBI, CIA or from the German Bundeskriminalamt (BKA). FBI has even put out a a public warning on the case…"
>>> http://www.fbi.gov/pressrel/pressrel05/emailscheme112205.htm

:ph34r:
FYI…

Sober, Bagles, and Mytobs ad nauseum…
- http://isc.sans.org/diary.php?storyid=894
Last Updated: 2005-11-25 21:04:50 UTC
"…Fortigate is showing W32/Sober.AD-mm 60% at of fortinets traffic over last 24 hours 43% of traffic over last 7 days.
- http://www.fortinet.com/FortiGuardCenter/g…reat_stats.html
Mail servers monitored by a fellow handler has caught over 46000 instances of Sober.y in the last 24 hours. The F-Secure blog was discussing seeing a few new bagles yesterday.
- http://securityresponse.symantec.com/[removed]

- http://www.f-secure.com/v-descs/mytob_do.shtml

:ph34r: :ph34r: