Sobig Worm turns PCs into Spam Factories

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Darth Fanboy
DUH! WINNING!
Posts: 11182
Joined: 2002-09-20 05:25am
Location: Mars, where I am a totally bitchin' rockstar.

Sobig Worm turns PCs into Spam Factories

Post by Darth Fanboy »

Sobig Worm Aims to Turn PCs Into Spam Machines
Wed August 20, 2003 09:46 PM ET
By Elinor Mills Abreu

SAN FRANCISCO (Reuters) - Several Internet worms that have besieged computers for over a week played havoc again on Wednesday, including one called Sobig.F whose aim was to turn PCs into spam machines and was believed to be the fastest growing virus ever, experts said.

Sobig.F drops software onto infected Windows computers that open them to be used later for distributing Internet spam -- unwanted e-mails and product promotions, experts said. It also represents a new trend in converging e-mail spamming and virus software writing, they said.

"We believe (Sobig.F) has been written by a spammer or spammers" looking for ways to get past spam filters, said Mikko Hypponen, manager of anti-virus research for Finnish security firm F-Secure. "For once, we have a clear motive for a virus -- money."

Security experts said it was difficult to ascertain how many computers had been infected by the Sobig.F worm. Worms are viruses that spread through networks.

Internet service America Online, however, said it blocked about 11.5 million copies while security firm MessageLabs stopped more than 1 million copies within the first 24 hours and dubbed Sobig.F the fastest growing e-mail virus ever.

Sobig.F hit the computing world as corporations were still recovering from several worms that spread through holes in Microsoft Corp.'s Windows operating systems, including the "Blaster" worm. Also called "LovSan," it has infected and crashed hundreds of thousands of computers since last week.

The "Welchia" or "Nachi" worm, which surfaced on Monday, infected 72,000 computers used by the U.S. Navy and Marine Corps and crippled Air Canada's reservation counters and call centers.

CSX Transportation said on Wednesday that a virus infection had slowed its dispatching and signal systems, forcing it to halt passenger and freight train traffic, including the morning commuter train service in Washington, D.C.

NEW TREND, SPAM-VIRUS CONVERGENCE

Sobig.F hit home users particularly hard, experts said. It arrives in an e-mail with an attachment that when opened infects the computer and sends itself on to other victims using a random e-mail address from the address book, making it difficult to trace the worm back to its source.

The Sobig family of worms represents a new trend in the convergence of worm and spam techniques for more widespread and faster deployment, experts said.

Virus writers are utilizing software that spammers employ to send bulk spam messages. Conversely, spammers are starting to use methods incorporated by virus writers to spread their messages and avoid detection, said Brian Czarny, marketing director at e-mail security company MessageLabs.

Previous Sobig versions loaded a program onto infected PCs that broadcast spam to other computers, thus turning the PCs into so-called "spam relays."

Sobig.F downloads a Trojan onto infected computers, which could later be remotely activated to send spam, experts said.

"There are computers scanning the Internet for open relays so spammers can jump from one machine to the next and be able to send millions of spam messages and have them not be traced back to them or be blocked," said Jimmy Kuo, research fellow at anti-virus vendor Network Associates Inc.

Sobig.F, which expires on Sept. 10, is spreading quickly because it sends multiple e-mails simultaneously and spreads to other computers on a shared network, said experts, who predict there will be another version in the near future. (Additional reporting by Bernhard Warner in London and Charles Grandmont in Montreal.)
"If it's true that our species is alone in the universe, then I'd have to say that the universe aimed rather low and settled for very little."
-George Carlin (1937-2008)

"Have some of you Americans actually seen Football? Of course there are 0-0 draws but that doesn't make them any less exciting."
-Dr Roberts, with quite possibly the dumbest thing ever said in 10 years of SDNet.
Thunderfire
Jedi Master
Posts: 1063
Joined: 2002-08-13 04:52am

Post by Thunderfire »

The big problem with this one is that many mail servers send a message
to the from address. Really usefull when the address is faked.
Embracer Of Darkness
Worthless Trolling Palm-Fucker
Posts: 1065
Joined: 2003-01-26 01:08pm
Location: paul.barlow@embracerofdarkness.co.uk

Post by Embracer Of Darkness »

*Fires up the firewalls and checks for uptdates.*

I'm getting sick of these worms.
User avatar
Darth Fanboy
DUH! WINNING!
Posts: 11182
Joined: 2002-09-20 05:25am
Location: Mars, where I am a totally bitchin' rockstar.

Post by Darth Fanboy »

threa bumped, if only to give concerned computer users one last peek if they want.
"If it's true that our species is alone in the universe, then I'd have to say that the universe aimed rather low and settled for very little."
-George Carlin (1937-2008)

"Have some of you Americans actually seen Football? Of course there are 0-0 draws but that doesn't make them any less exciting."
-Dr Roberts, with quite possibly the dumbest thing ever said in 10 years of SDNet.
Thunderfire
Jedi Master
Posts: 1063
Joined: 2002-08-13 04:52am

Post by Thunderfire »

Embracer Of Darkness wrote:*Fires up the firewalls and checks for uptdates.*

I'm getting sick of these worms.
This is a mail based Virus AFAIK. Getting a good Virus Scanner and Mail Filter is a
better idea.
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Post by Darth Wong »

Thunderfire wrote:
Embracer Of Darkness wrote:*Fires up the firewalls and checks for uptdates.*

I'm getting sick of these worms.
This is a mail based Virus AFAIK. Getting a good Virus Scanner and Mail Filter is a better idea.
That doesn't work on brand-new viruses, unless you're lucky enough not to get them until after the virus scanner companies identify the new infestation (note: this does not occur until many people have ALREADY been infected) and put out updates which you have already received and installed.

Best solution is not to use Windows for E-mail. Use it for games or video editing or other things, but Internet activities should be carried out on a *nix platform if you're genuinely worried about security. And if you must use Windows, then DON'T USE OUTLOOK EXPRESS, for fuck's sake.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
His Divine Shadow
Commence Primary Ignition
Posts: 12791
Joined: 2002-07-03 07:22am
Location: Finland, west coast

Post by His Divine Shadow »

My company's network escaped Sobig.F atleast, the installment of a virus scanner in the mailserver has greatly helped, also is nice when we have another layer of virus scanners on every workstation, and a draconian firewall.

There was a virus warning yesterday, when I was supposed to have the day off, apparently, a part of the nimda virus(only a part so it was inactive) had gotten left after the last sweep.

We did however get messages fom other mailservers that we had supposedly sent them Sobig.F, bullshit, I went through every computer with a program that was designed to find Sobig.F and remove it, every computer was clean.
Ofcourse Sobig.F can fake from headers so it wasn't really from us it came.
Those who beat their swords into plowshares will plow for those who did not.
User avatar
Glocksman
Emperor's Hand
Posts: 7233
Joined: 2002-09-03 06:43pm
Location: Mr. Five by Five

Post by Glocksman »

And if you must use Windows, then DON'T USE OUTLOOK EXPRESS, for fuck's sake.
You ain't lying there, hoss. :wink:

The email program that I use is called Calypso Email.

Not only does it handle multiple accounts easily, it lets you turn off the goddamn HTML and scripting in the preview pane. It converts HTML messages to attached files that you can then look through the source code before you open them.

HTML and scripting are the reasons why OE is a virus and trojan magnet.

Best of all, it's now free

Download it from here and try it .
"You say that it is your custom to burn widows. Very well. We also have a custom: when men burn a woman alive, we tie a rope around their necks and we hang them. Build your funeral pyre; beside it, my carpenters will build a gallows. You may follow your custom. And then we will follow ours."- General Sir Charles Napier

Oderint dum metuant
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

Glocksman wrote:HTML and scripting are the reasons why OE is a virus and trojan magnet.
Not really. The reason that Outlook Expres is a virus and trojan magnet is because Microsoft did not correctly implement the MIME standards. Then, in a flash of genius, they left scripting enabled by default.

Mozilla Mail (now Thunderbird) also supports HTML, but scripts are turned off by default, and it implemented MIME *correctly*.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
His Divine Shadow
Commence Primary Ignition
Posts: 12791
Joined: 2002-07-03 07:22am
Location: Finland, west coast

Post by His Divine Shadow »

Outlook - scripting + Norton = gave 100% protection against Sobig.F
Those who beat their swords into plowshares will plow for those who did not.
User avatar
Glocksman
Emperor's Hand
Posts: 7233
Joined: 2002-09-03 06:43pm
Location: Mr. Five by Five

Post by Glocksman »

Mozilla Mail (now Thunderbird) also supports HTML, but scripts are turned off by default, and it implemented MIME *correctly*
Interesting. The only reason I use Calypso (other than it's free) is because it allows me to turn all of that off.

One of my quirks is that I just don't like HTML email, and unless it's from someone I know, I delete it unread.
"You say that it is your custom to burn widows. Very well. We also have a custom: when men burn a woman alive, we tie a rope around their necks and we hang them. Build your funeral pyre; beside it, my carpenters will build a gallows. You may follow your custom. And then we will follow ours."- General Sir Charles Napier

Oderint dum metuant
User avatar
The Yosemite Bear
Mostly Harmless Nutcase (Requiescat in Pace)
Posts: 35211
Joined: 2002-07-21 02:38am
Location: Dave's Not Here Man

Post by The Yosemite Bear »

Got to love ASVS for one thing...

Teaching every last bleeping Noobe to turn their HTML off....
Image

The scariest folk song lyrics are "My Boy Grew up to be just like me" from cats in the cradle by Harry Chapin
User avatar
Alyeska
Federation Ambassador
Posts: 17496
Joined: 2002-08-11 07:28pm
Location: Montana, USA

Post by Alyeska »

Darth Wong wrote:Best solution is not to use Windows for E-mail. Use it for games or video editing or other things, but Internet activities should be carried out on a *nix platform if you're genuinely worried about security. And if you must use Windows, then DON'T USE OUTLOOK EXPRESS, for fuck's sake.
I use OE and my solution is simple. I delete ALL e-mail from people I don't know and if I recieve an attachment without prior warning of said attachment, I isolate the e-mail until I can contact the person.
"If the facts are on your side, pound on the facts. If the law is on your side, pound on the law. If neither is on your side, pound on the table."

"The captain claimed our people violated a 4,000 year old treaty forbidding us to develop hyperspace technology. Extermination of our planet was the consequence. The subject did not survive interrogation."
User avatar
TheFeniX
Sith Marauder
Posts: 4869
Joined: 2003-06-26 04:24pm
Location: Texas

Post by TheFeniX »

I use Outlook Express on three separate PC's (with a total of 5 e-mail addresses) and have not had an infection in well over two years.

Considering that most of the people who get infected with viruses are ignorant of even basic security and OS concepts: exactly how do you expect them to run a Linux distro? And if they do have this knowledge, they should already know how to keep viruses off their PCs.

I find Windows works just fine for me 99% of the time, and I can't really complain about the massive security flaws in MS products because they make us money (Hell, Blaster has created a huge amount of business for us).
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

OE had the autoexecute nonsense, but nowadays that's off by default. However, most users are fairly computer illiterate and will open attachments without considering what it might be. My dad got a couple Sobig.E e-mails but didn't open it (and uses NS Messenger 7 anyways).

I personally use Ximian Evolution 1.4, which lets you turn off image linking in HTML mail - quite nice. No fucking up the formatting of a message while also protecting you from spam-verification images.
Embracer Of Darkness
Worthless Trolling Palm-Fucker
Posts: 1065
Joined: 2003-01-26 01:08pm
Location: paul.barlow@embracerofdarkness.co.uk

Post by Embracer Of Darkness »

Thunderfire wrote:
Embracer Of Darkness wrote:*Fires up the firewalls and checks for uptdates.*

I'm getting sick of these worms.
This is a mail based Virus AFAIK. Getting a good Virus Scanner and Mail Filter is a
better idea.
Thanks for the heads-up. Further action is being taken. :)
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Kmail does not enable HTML. By default, it shows you the source, and allows you to render it after checking it's contents.

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
User avatar
Crayz9000
Sith Apprentice
Posts: 7329
Joined: 2002-07-03 06:39pm
Location: Improbably superpositioned
Contact:

Post by Crayz9000 »

phongn wrote:I personally use Ximian Evolution 1.4, which lets you turn off image linking in HTML mail - quite nice. No fucking up the formatting of a message while also protecting you from spam-verification images.
Mozilla Thunderbird (and the mail in version 1.3 and above) have the same feature.
A Tribute to Stupidity: The Robert Scott Anderson Archive (currently offline)
John Hansen - Slightly Insane Bounty Hunter - ASVS Vets' Assoc. Class of 2000
HAB Cryptanalyst | WG - Intergalactic Alliance and Spoof Author | BotM | Cybertron | SCEF
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

I wonder what Sobig.F's payload was - it went active at 1900 UCT today.
User avatar
haas mark
Official SD.Net Insomniac
Posts: 16533
Joined: 2002-09-11 04:29pm
Location: Wouldn't you like to know?
Contact:

Post by haas mark »

So is there a way to get rid of this?

~ver
Robert-Conway.com | lunar sun | TotalEnigma.net

Hot Pants à la Zaia | BotM Lord Monkey Mod OOK!
SDNC | WG | GDC | ACPATHNTDWATGODW | GALE | ISARMA | CotK: [mew]

Formerly verilon

R.I.P. Eddie Guerrero, 09 October 1967 - 13 November 2005


Image
User avatar
phongn
Rebel Leader
Posts: 18487
Joined: 2002-07-03 11:11pm

Post by phongn »

Yes. The best bet is to use your head and not run strange attachments. Otherwise, fire up the virus scanner.
Thunderfire
Jedi Master
Posts: 1063
Joined: 2002-08-13 04:52am

Post by Thunderfire »

Darth Wong wrote: That doesn't work on brand-new viruses, unless you're lucky enough not to get them until after the virus scanner companies identify the new infestation (note: this does not occur until many people have ALREADY been infected) and put out updates which you have already received and installed.
Filtering based on the suffix of the attachment should work against most
mail viruses.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

This folks, is why you should never use Outlook, and open attachments from strange e-mails, no matter who sent it. Hell, running a mail client that doesn't allow you to disable HTML rendering is just ASKING to get bit.

For those that don't already know, to kill HTML rendering in Mozilla Mail (aka Thunderbird) just do the following:

Click view, click on Message Body As, and select "Plain Text". Now all you'll get is the source code. (hell, I'm so anal that I delete any HTML e-mail on sight, no matter who sent it.)
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
Pu-239
Sith Marauder
Posts: 4727
Joined: 2002-10-21 08:44am
Location: Fake Virginia

Post by Pu-239 »

Even if the email is from someone you know, don't trust it. Many viruses read the victim's address book and mail from the victim's address.

ah.....the path to happiness is revision of dreams and not fulfillment... -SWPIGWANG
Sufficient Googling is indistinguishable from knowledge -somebody
Anything worth the cost of a missile, which can be located on the battlefield, will be shot at with missiles. If the US military is involved, then things, which are not worth the cost if a missile will also be shot at with missiles. -Sea Skimmer


George Bush makes freedom sound like a giant robot that breaks down a lot. -Darth Raptor
Post Reply