Welcome | Sign In
ECommerceTimes.com
Malware

New Virus Strain Spreads Swiftly Through E-Mail

Print Version
E-Mail Article
Reprints
New Virus Strain Spreads Swiftly Through E-Mail

One reason the worm spread so rapidly was it cloned a number of tried and true malware methods, according to Sam Curry, vice president for product management at Etrust Security Managment in Islandia, N.Y. "I find it ironic that the same worm can spoof the FBI and CIA on the one hand and use the old 'do you want to see pictures of ...' trick on the other," he said.


One in every 74 e-mail messages on the Internet yesterday carried a new strain of the Sober virus, estimates one security analyst.

"At the moment, this virus is accounting for 65 percent of all virus reports to us," Graham Cluley, a senior technology consultant for anti-virus software maker Sophos told TechNewsWorld. "That means, including legitimate mail, spam and everything else, one in 74 messages presently contain the Sober worm."

Although the new Sober variant spread quickly, security experts said that existing anti-virus programs should be able to scrub most infected messages because this virus strain shares characteristics with prior versions, characteristics that make it easy for the virus fighting programs to identify the malware and quarantine it.

"Most anti-virus vendors already protect their customers against this," Alfred Huger, senior director of engineering at Symantec (Nasdaq: SYMC) Security Response in Santa Monica, Calif., told TechNewsWorld.

Cocktail of Techniques

One reason the worm spread so rapidly was it cloned a number of tried and true malware methods, according to Sam Curry, vice president for product management at Etrust Security Managment in Islandia, N.Y.

"I find it ironic that the same worm can spoof the FBI and CIA on the one hand and use the old 'do you want to see pictures of ...' trick on the other," he told TechNewsWorld.

Among the several cover letters used by the worm to spread itself is one purporting to be from the FBI or CIA. According to Sophos, the FBI letter said:

    Dear Sir/Madam,

    We have logged your IP-address on more than 30 illegal Web sites. Important: Please answer our questions! The list of questions are attached.

    Yours faithfully,

    Steven Allison

    Federal Bureau of Investigation-FBI-

    935 Pennsylvania Avenue, NW , Room 3220

    Washington, DC 20535

    Phone: (202) 324-30000[cq]

Dual Language Propulsion

Another factor contributing to the spread of the virus was its ability to produce mischief in two languages, English and German, noted Huger.

"That opens up the general number of people who could read it, have access to it and might click on it," he said.

Curry explained that when the worm infects a machine, it starts accessing multiple outbound e-mail servers and runs three processes simultaneously.

It will pull a target off the hard disk of an infected computer, he continued, and send them multiple e-mails with different subject lines, attachment names and mailing routes.

"This variant, which comes on the heels of six others last week, is a lot more sophisticated -- not in terms of the techniques it uses -- but in the ways it mixes and matches them," Curry said.

Noose Tightening

In recent times, malware authors have narrowed the scope of the efforts, choosing stealth over noisy pandemics like yesterday's Sober outbreak. "This is an old-fashioned ploy to get attention," Curry observed. "The damage that it does is not that bad.

"But what worries me," he interjected, "we very often see an idea, or set or ideas, tried out in an innocuous format and if they succeed, we see them used for something not so innocuous."

While the origin of this latest Sober strain remains a mystery, some security experts believe law enforcement authorities are narrowing the noose around the perpetrators.

Jimmy Kuo, a senior fellow at McAfee AVERT in Beaverton, Ore. noted that prior to the rash of Sober outbreaks last week, police in Bavaria, Germany, predicted the development, presumably because they had cracked the ring of malcontents writing the viruses.

"This is probably a 'group of friends' scenario," he told TechNewsWorld. "The police will pick off one. Hopefully, he'll roll on the others, and we can pick off some more."

Cluley, of Sophos, added, "The police may not know who this virus writer is, but they're close on the trail. And the fact that he's goading the FBI and CIA means that there will be even greater resolve to capture this person.


Print Version E-Mail Article Reprints More by John P. Mello Jr.


More by John P. Mello Jr.

Tune-Up App Lets You Get More Intimate With Your Mac
February 08, 2010
Getting under the hood and really digging around with OS X's deepest settings can often be a little tricky, but Macware's MacTuneUp is designed to put those controls within arm's reach. Its latest version makes it more compatible with Snow Leopard, and it's ready to take on tasks like disc clean-up, boot disc creation, and Internet connection optimization.
TopXNotes: A Concierge for the Constant Scrivener
February 01, 2010
For serious note-takers, creating the notes themselves is the easy part -- the hard part is organizing it all. Tropical Software's TopXNotes, now in version 1.5, can organize, categorize, sort, sequence and sync as many missives as you can throw at it. TopXNotes also features an encryption utility and an enhanced drag-and-drop system.
3M Miniprojector Packs Lots of Versatility Into Small Package
January 25, 2010
The 3M MPro120 is a pocket-sized, lightweight projector that can cast video and images of up to 50 inches on just about any surface. Those videos and images can come from a wide range of gadgets and devices, and 3M pack in an ampe supply of connectors and adapters. Accompanying documentation is sparse, but the gizmo is easy enough to figure out without too much guesswork.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network