Version: 2008
  • On TechRepublic: Windows 7: Slower to boot than Vista?

November 22, 2005 12:37 PM PST

Sober worm offshoot trades on Paris Hilton, FBI

  • 5 comments
There is no Easter Bunny, and that's not a real Paris Hilton video in your e-mail box. Nor is the FBI likely to be e-mailing you to ask you questions about visiting illegal Web sites.

A new variant of the Sober worm made the network rounds Tuesday, attempting to entice people into clicking on attachments purporting to be threats from the law enforcement agency or video clips of the hotel heiress and her reality TV co-star Nicole Richie.

Antivirus companies said the worm gained some traction over the weekend and on Monday. It's a minor modification of the "Sober" virus that has flared up several times over the past year. But this latest variant, graded as a medium-level threat, appeared to be trailing off as security providers have responded.

"This one is virulent and will reproduce itself easily but does not have much of a payload," said David Perry, the global director of education at antivirus company Trend Micro. "For the time being, this particular strain is probably done."

Some antivirus companies said the worm was still spreading fast, however. In a blog posting, security company F-Secure said Internet companies have seen "several millions of infected emails" over the course of hours.

"The numbers we're now seeing...are just huge," wrote F-Secure Chief Research Officer Mikko Hypponen. "This is the largest email worm outbreak of the year, so far."

One version of the e-mail carrying the worm appears to be a letter from the FBI saying the agency has found evidence that the computer user has been visiting illegal Web sites. It asks the recipient to click on the attachment to answer questions.

The FBI released a warning on Tuesday saying it never sends unsolicited e-mails.

"The FBI takes this matter seriously and is investigating," the agency said in its statement. "Users are instructed to delete the e-mail without opening it."

Another version of the e-mail used a message purporting to be from the Central Intelligence Agency. A third, a German-language variant, contained a threatening message from a German law enforcement agency.

A separate version purports to offer a download manager for "video clips, pictures and more" of Hilton and Richie. All operate the same way, once the attachment is activated, however.

If activated, the worm drops several files onto a computer and searches for e-mail addresses stored in address books or elsewhere in memory and sends copies of itself to those destinations. If it finds Microsoft's anti-spyware and antivirus software running, it turns the protections off.

Several other variants of a different virus, dubbed "Mytob," are also making the rounds. The e-mails carrying them purport to be a message from an e-mail service provider or from support staff providing notification about a changed password or suspended account.

Antivirus companies rate the danger of this worm as "low," but as always, advise against clicking on unknown attachments to e-mails.

See more CNET content tagged:
Sober worm, Paris, variant, antivirus company, attachment

Add a Comment (Log in or register) (5 Comments)
  • prev
  • 1
  • next
windows must die
by November 22, 2005 2:46 PM PST
...so that i can receive less of this crap in my inbox.
Reply to this comment
Or
by Mr. Network November 22, 2005 2:52 PM PST
you can simply buy a sonicwall and bounce them back at the firewall level......

It's not rocket science people.
View reply
Just received two and one being CIA
by appletoys November 22, 2005 7:26 PM PST
Just deleted two emails.
One addressed as admin@hotmail.com titiled: paris hilton and (I forget her name already) lol
Second addressed as admin@cia.gov titiled: you've been visting illegal sites.
file size = 75k
So be careful of any government emails.
Reply to this comment
How stupid do you have to be...
by Sec tech November 25, 2005 9:21 AM PST
After all this time, to click on a link in an unsolicited e-mail. People that do this should be fined and their computers taken away. For the safety of the rest of us that USE our brains.
Reply to this comment
(5 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Dow Jones Industrials (0.24%) 24.94 10,271.91
S&P 500 (0.29%) 3.18 1,096.19
NASDAQ (0.43%) 9.29 2,160.37
CNET TECH (0.26%) 4.08 1,575.66
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right