December 9, 2005 9:48 AM PST

Sober code cracked

Antivirus companies say they have cracked an algorithm that was being used by the Sober worm to "communicate" with its author.

The latest variant of the Sober worm caused havoc in November by duping users into executing it by masking itself as e-mails from the FBI and CIA. Antivirus companies were aware that the worm somehow knew how to update itself via the Web. The worm's author programmed this functionality to control infected machines and, if required, change their behavior.

On Thursday, Finnish antivirus firm F-Secure revealed that it had cracked the algorithm used by the worm and could now calculate the exact URLs the worm would check on a particular day.

Mikko Hypponen, chief research officer at F-Secure, explained that the virus author has not used a constant URL because authorities would easily be able to block it.

"Sober has been using an algorithm to create pseudorandom URLs which will change based on dates. Ninety-nine percent of the URLs simply don't exist...However, the virus author can pre-calculate the URL for any date, and when he wants to run something on all the infected machines, he just registers the right URL, uploads his program and BANG! It's run globally on hundreds of thousands of machines," Hypponen wrote in his blog.

According to F-Secure's calculations, on Jan. 5, 2006, all computers infected with the latest variant of Sober will look for an updated file located in a list of domains, including:

http://people.freenet.de/gixcihnm/

http://scifi.pages.at/agzytvfbybn/

http://home.pages.at/bdalczxpctcb/

http://free.pages.at/ftvuefbumebug/

http://home.arcor.de/ijdsqkkxuwp/

Hypponen advised administrators to ensure any infected PCs can't upgrade automatically by blocking access to the domains.

Adam Biviano, premium services manager at Trend Micro, said that blocking the URLs could be beneficial, but the safest bet would be to ensure that PCs are safe.

"Blocking those URLs is not a bad idea but administrators need to make sure their machines are not infected in the first place," Biviano said.

Munir Kotadia of ZDNet Australia reported from Sydney.

See more CNET content tagged:
Sober worm, F-Secure Corp., worm, algorithm, antivirus

Add a Comment (Log in or register) 12 comments
So can they catch the guy who did it?
by R. U. Sirius December 9, 2005 11:01 AM PST
That would be nice. I had my inboxes flooded with the crap from the idiot, so please go catch him.
Reply to this comment View all 2 replies
Isn't that a violation of the DCMA?
by Leppard December 9, 2005 12:20 PM PST
I mean they decoded a program without permission.

Didn't they break the law?

Oh wait.. it was a Finnish company... I guess Finland doesn't have stupid laws like the DCMA (Digital Millennium Copyright Act)
Reply to this comment View reply
update the infected machines with disabled virus code
by dfc5000 December 12, 2005 5:52 AM PST
If the virus code has been cracked why not update the infected machines with disabled virus code?
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Samsung contemplating SanDisk acquisition

    South Korean consumer electronics giant is considering a buyout of the chipmaker to reduce its NAND flash memory costs, according to PaidContent.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • The Open Road

    Analysts as a lagging indicator of success

    Gartner, Forrester, and other analyst firms tend to be great predictors of the past, probably because that's where they get their money.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Start-up launches spectrum marketplace

    A new company called Spectrum Bridge has launched a Web site for buying and selling wireless spectrum licenses.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: Future Combat Systems, here and now

    The U.S. Army has ambitious plans for a widespread high-tech refresh of its vehicles and other soldier gear. It's also finding a way to make some parts happen sooner rather than later.

  • Crave

    Zune phone concept: Hot or not?

    Yanko Design has imagined a concept for a Microsoft Zune phone.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.