Infected email appears to come from Fifa
Infected email appears to come from Fifa
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Latest Sober mutant targets soccer fans

Promise of World Cup tickets hides deadly payload

Robert Jaques, vnunet.com 03 May 2005
ADVERTISEMENT

Security experts have warned of a newly discovered mutant of the Sober worm which attempts to lure users into opening infected attachments by promising World Cup football tickets.

McAfee's Avert antivirus division has branded the W32/Sober.p@MM worm, also known as Sober.p, as "prolific".

The mass-mailing threat contains its own SMTP engine to construct outgoing messages, which are written in German or English.

It harvests addresses from local files to send itself, producing emails with a spoofed 'From' address.

"The attachment comes in the form of a .zip file that contains an executable file named 'winzipped-text_data.txt.pif'," said the Avert warning.

"The filename contains a dual extension: the first is .txt, followed by many spaces then .pif. When the Zip archive is extracted and the .pif file is manually executed, the virus may display a fake error message."

However, Avert said that users would need to manually extract the executable from the .zip file and manually run the attachment in order to be infected.

The following German text, with the spoofed sender listed as Fifa, has been detected in versions of the infection currently spreading in the wild: "Tickets fur die 64 Spiele der Weltmeisterschaft 2006 in Deutschland sind Sie dabei."

An example of a randomly generated English message is as follows:

From: (address is spoofed)
Subject: Your Password
Body: Account and Password Information are attached!
Visit: http://www/.[sender's domain]
*** AntiVirus: No Virus found
*** "[recipient's domain] " Anti-Virus***
http://www/.[recipient's domain]

More information on Sober.p and how to remove it can be found at McAfee's website here.

See also:

Newly intercepted Sober.q spreading across EuropeVirus-infected Zombie PCs used to send offensive spam  16 May 2005
ISPs have a 'duty of care' to protect cusomersCable firm promises built-in security software from the summer  10 May 2005
Many systems remain unpatched against known vulnerabilitiesSecurity watchdog reports 600 new flaws in the past three months  04 May 2005
Sober.p is currently the most common malicious program found in email trafficLatest mutant breaking records for rate of propagation  04 May 2005
You've got mail, but be careful  19 Apr 2005
W32.Sober-K-mm on the looseSecurity firm intercepts 1,400 copies of latest mass-mailer variant  21 Feb 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Solihull, United Kingdom | Enzen Global Limited
Business Analyst - Trading - £30,000 to £35,000 per Annum - Solihull We are in need of a Business Analyst with strong analytical skills and a penchant for learning the domain knowledge of the Utilities ... more >
Solihull, United Kingdom | Enzen Global Limited
Business Analyst - £30,000 - £35000 - Solihull We are in need of a Business Analyst with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
Solihull, United Kingdom | Enzen Global Limited
Business Analyst - £30,000 to £35,000 - Solihull We are in need of a Business Analyst with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
More job opportunities