CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Date-triggered Outbreak Spammed out Two New Sober Versions image
Cyber Security
avira writes "AVIRA and AntiVir Get Fastest Reaction Time

November 15, 2005

AVIRA Antivirus experts issued a virus alert this morning, warning against the outbreak of yet two more Sober variants, W and X. Massive e-mail sending by these new worms was detected last night.

Sober.W arrives by e-mail, inside a tricky attachment, displaying the same bilingual craftiness that Sober has accustomed us to. There is only a small difference of approach: most of the prior versions sent e-mail messages with different contents in English and German. Sober.W sends the same message in both languages, the only detail worthy of attention being the different linguistic proficiency: while the German text looks native-level, the English message shows some poor grammar and it openly admits this: “sorry, because, my english is not the best!” When it sends itself, the worm filters the domains in order to reach German-speaking users separately: this means it will send the German message only to the e-mail addresses hosted on .de, .at, and .ch domains. Also, when executed, the worm displays a Windows error message, which should make it easier to identify.

The Sober.X version, on the other hand, spreads inside an English message, claiming to be a registration confirmation e-mail. The actual worm file is included inside a .zip archive, named reg_text.zip.

The intriguing detail is that Sober.W and X began spreading at the same time, by spam lists. In fact, this appears to be a date-triggered outbreak and it might be possible that the author could have deliberately planned a double outbreak to start at a specific date in order to reach more victims.

AVIRA and AntiVir® users are perfectly protected against these new cyber threats, as AntiVir® was the first AV to include detection for the new Sober variants.


________________________________________________

About AVIRA GmbH
AVIRA GmbH is a German security software producer, providing its international customers and partners with increased flexibility and ease of solution migration. To guarantee high quality products right from the beginning, AVIRA benefits from the well-known AntiVir® technology, developed by H+BEDV within more than 15 years of successful activity in the antivirus industry. Expanding its activity on the international market, AVIRA is represented by Distributors, Resellers and OEM Partners, on all the continents all around the globe.
Website:www.avira.com "
Posted on Wednesday, 16 November 2005 @ 20:15:29 UTC by Paul (2167 reads)
[ Trackback ]
image

"Date-triggered Outbreak Spammed out Two New Sober Versions" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· HotScripts
· W3 Consortium
· Spam Cop
· More about Cyber Security
· News by Paul


Most read story about Cyber Security:
Booby Trapped software!

block bottom
Article Rating
spacer
Average Score: 4
Votes: 3


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer