|
Sobig.F VIRUS
SUBJECT: Mass mailing worm,W32.SobigF@mm
OVERVIEW:
W32.SobigF@mm is a mass-mailing, network-aware worm which is spreading rapidly. This requires anti-virus signatures released today - make sure your AV software is current with all updates as of today.
SYSTEMS AFFECTED:
Windows 95/98/ME/NT/2000/XP
DESCRIPTION:
According to the Symantec description of this worm: Sobig.F sends copies using its own SMTP (Simple Mail Transfer Protocol) engine, as an attachment to email addresses it finds in files with the following extensions: .dbx, .eml, .hlp, .htm, .html, .mht, .wab, .txt on a victim's computer. The worm usually arrives in e-mails with the following characteristics:
From: The 'From:' field is filled with an address found from the infected system. If no address is found, it will use "admin@internet.com"
To: The 'To:' field is filled with an address found from the infected system. Subject, any from the list: Re: Thank you! Thank you! Your details Re: Details Re: Re: My details Re: Approved Re: Your application Re: Wicked screensaver Re: That movie
Body, it chooses one from the two following lines: See the attached file for details Please see the attached file for details. Attachment names can be any from: application.zip (contains application.pif) details.zip (contains details.pif) document_9446.zip (contains document_9446.pif) document_all.zip (contains document_all.pif) movie0045.zip (contains movie0045.pif) thank_you.zip (contains thank_you.pif) your_details.zip (contains your_details.pif) your_document.zip (contains your_document.pif) wicked_scr.zip (contains wicked_scr.scr)
MITIGATING FACTORS:
Make sure your virus definitions are current as of today. Filter out .pif and .scr attachments at your email gateway. Since this may also arrive in a zip file, you may want to consider temporarily isolating zip files.
REFERENCES:
McAfee: http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100561
Symantec: http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.f@mm.html
Sophos:http://www.sophos.com/virusinfo/analyses/w32sobigf.html
Trend Micro: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBIG.F
------------------------------------------------------------------
Microsoft Baseline Security Analyzer:
As part of Microsoft's Strategic Technology Protection Program, and in response to direct customer need for a streamlined method of identifying common security misconfigurations, Microsoft has developed the Microsoft Baseline Security Analyzer (MBSA).
MBSA Version 1.1.1 includes a graphical and command line interface that can perform local or remote scans of Windows systems. MBSA runs on Windows 2000, Windows XP, and Windows Server 2003 systems and will scan for common system misconfigurations in the following products: Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, Internet Information Server
(IIS) 4.0 and 5.0, SQL Server 7.0 and 2000, Internet Explorer (IE) 5.01 and later, and Office 2000 and 2002. MBSA will also scan for missing security updates for the following products: Windows NT 4.0, Windows 2000, Windows XP, Windows Server 2003, IIS 4.0 and 5.0, SQL Server 7.0 and 2000, IE 5.01 and later, Exchange 5.5 and 2000, and Windows Media Player 6.4 and later.
You may download the Microsoft Baseline Security Analyzer at www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/tools/mbsahome.asp
Back to Top
|