By Gene J. Koprowski TechNewsWorld Part of the ECT News Network
12/01/05 5:00 AM PT
This latest Sober worm typically arrives as a ".zip file" e-mail attachment in either German or English, or in a message that appears to be from either the Federal Bureau of Investigation or the Central Intelligence Agency, or even the Internal Revenue Service.
eMarketer Whitepaper: Optimizing the E-Commerce Experience
From the Web to the Contact Center, are you prepared to proactively engage and keep your savvy customers? Read how e-commerce leaders are optimizing their sites with ratings, reviews, live help, Web analytics, mobile and more.
A new briefing released yesterday by Postini, the messaging security company, based in San Carlos, Calif., indicates that the recently discovered "Sober" virus is the largest viral attack on the Internet ever recorded, twice as big as any other virus on record.
"We typically quarantine about 50 million virus-infected e-mails in a month. This Sober virus generated close to a 1,500 percent increase in virus-infected e-mail traffic in the past week," Scott Petry, founder and vice president of products and engineering at Postini, told TechNewsWorld.
Zip File Problems
This latest Sober worm typically arrives as a ".zip file" e-mail attachment in either German or English, or in a message that appears to be from either the Federal Bureau of Investigation or the Central Intelligence Agency, or even the Internal Revenue Service.
Postini said the Sober worm "hijacks" Windows-based computers, and forces them to send out continuous spam e-mails that overwhelm servers and reduce network performance. As with previous Sober variants, this worm can also disable antivirus programs.
Though computer users are often urged to use caution when opening attachments, many users opened the infected messages, due to the belief that it was from the government, enabling the Sober worm to spread rapidly, Postini said.
"Despite the virulence of the outbreak, our customers have not been affected by the Sober virus, and they experienced no message delivery latency issues or any degradation of service," said Petry. "We're blocking or quarantining all security threats before they reach our customers' networks."
As of yesterday afternoon, Postini said that during the previous 24 hours it had prevented more than 29 million copies of the Sober virus from reaching its worldwide customer base. Over the last week, Postini quarantined more than 218 million Sober-infected messages, making this outbreak twice as large as the largest previous attack on record, the company said.
Best Defense
Experts said the best defense against such a virus is multilayer anti-virus protection technology, which includes connection level threat analysis, heuristics-based content analysis and anti-virus scanning engines from vendors like McAfee and Authentium.
Although the new Sober variant spreads swiftly, security experts said that existing anti-virus software should be able to terminate most infected messages because this virus strain shares a number of characteristics with prior versions, making it easy for the virus zapping programs to identify and quarantine it.
According to anti-virus software vendor, Sophos, a number of cover letters are being used by scammers to spread the virus. Among the letters used by the worm to spread itself is one purporting to be from the FBI or CIA. Sophos said a typical letter looks like this:
Dear Sir/Madam,
We have logged your IP-address on more than 30 illegal Web sites. Important: Please answer our questions! The list of questions are attached.
Yours faithfully,
Steven Allison
Federal Bureau of Investigation-FBI-
935 Pennsylvania Avenue, NW , Room 3220
Washington, DC 20535
Phone: (202) 324-30000
Latest Threat
Meanwhile, experts at SophosLabs, the global network of virus, spyware and spam analysis centers, have warned Internet users of another phishing e-mail which aims to steal from American taxpayers by posing as notification of a refund from the Internal Revenue Service. The phishers are taking advantage of a an apparent security error on a real U.S. Government Web site that allows phishers to redirect visitors to a fake Web site.
In an brazen attempt to look more legitimate, the e-mail tells users to cut-and-paste the link into their Web browser rather than click directly on it. This is what security experts have cautioned users to do for years -- thus this attack can be quite insidious.
Though the link does use the real domain name of the real government Web site, a mistake in the way the Web site has been set up bounces surfers to a fake lookalike site run by the phishers.
"This phisher tells you that the IRS owes you several hundred dollars, and offers you a Web link from which you can allegedly claim your tax refund," said Graham Cluley, senior technology consultant at Sophos. "The link in the e-mail simply bounces you off a U.S. Government Web site onto a site owned by the criminals, who are ready and waiting to steal your credit card details, Social Security number and other personal information."
Cybercrime Profits Outpace Drug Trafficking November 29, 2005
The good news is cybercrimes targeting businesses are at their lowest level ever, according to the Computer Security Institute (CSI). The annual CSI/FBI Computer Crime and Security Survey noted that the average loss per cybercrime incident in 2005 was about US$250,000.
Related Stories
New Virus Strain Spreads Swiftly Through E-Mail November 23, 2005
One reason the worm spread so rapidly was it cloned a number of tried and true malware methods, according to Sam Curry, vice president for product management at Etrust Security Managment in Islandia, N.Y. "I find it ironic that the same worm can spoof the FBI and CIA on the one hand and use the old 'do you want to see pictures of ...' trick on the other," he said.
Sober Strikes Again, IE Flaw Dubbed 'Extremely Critical' November 22, 2005
"This variant of the Sober worm may catch out the unwary as they open their e-mail inbox this morning," said Graham Cluley, senior technology consultant at Sophos. "All users should be reminded to follow safe computing guidelines, and PCs should be kept automatically updated with the latest anti-virus protection."
Threat From Mobile Device Viruses a Sleeping Giant July 02, 2005
"Mobile viruses are more proof of concept now even though they have hit in Europe and Asia. Virus writers are cutting their teeth. It's a numbers game to them," said Todd Thieman, Trend Micro's director of device security marketing. He added that for now, the number of smartphone users is not profitable for virus writers.
Malware for Money: Zafi, Sober, Netsky Still Haunting Net July 01, 2005
Netsky-P, which was the hardest-hitting virus of 2004 and still ranks second on Sophos top 10 list, has enjoyed an extremely long reign near the top of the virus chart so far in 2005. German teenager Sven Jaschan, who admitted writing the Netsky and Sasser worms more than a year ago, will face trial next week.
Sober Overtakes Zafi as Viral King June 01, 2005
What worms like Sober do is make computer zombies. Gregg Mastoras, senior security analyst at Sophos, said the Sober-Q Trojan searched for computers infected with the Sober-N worm and attempted to secretly turn them into spamming machines, better known as zombies. A new entry, Mytob-AZ, is also gaining momentum.
Related News Alerts
More by Gene J. Koprowski
Mobile Phone Network Operators React to WiFi Threat September 09, 2006
"From a strategic and financial standpoint, the routing of traffic through the IP network significantly enhances network quality and capacity, and reduces the OPEX (operational expenditures) that carriers expend on backhaul," noted ABI Research analyst Stuart Carlaw.
Apple's 'Special Event' Has Rumor Mill Churning September 06, 2006
Apple surprised technology journalists and Wall Street analysts Tuesday with an e-mail saying there would be a "special event" next week. Embedded within the Apple invitation is an interesting image of spotlights shining upon the Apple logo with the words, "It's Showtime," printed beneath it. This is giving many analysts a Hollywood kind of feeling.
Restless IT Workers Looking for New Jobs September 04, 2006
"Tech workers who stayed put in their jobs over several years of uncertainty in our industry are clearly looking to move on now that we're in a period of growth," said Neill Hopkins, vice president, skills development, CompTIA.