| New Variant of the Sober worm strikes again |
|
|
|
A new variant of the Sober email worm also know as (W32.Sober.I@mm - Win32.Sober.I - WORM_SOBER.I - I-Worm.Sober.i - W32/Sober.j@MM - W32/Sober-I) is spreading very quickly today on the Internet using its own SMTP engine. The New Sober worm writen in visual Basic, is a mass mailing worm which sends itself to email addresses harvested from an infected computer. It uses variety of subject lines example "HEY,, I've a new Mail-Address!!!", file attachment names example "mailtext_doc.zip" and message bodies, both in English and in German. This worm only infect Microsfot Windows Computer running as version of Windows 2000, 9x, Me, NT, Server 2003, XP (home, pro) To infect your computer you must double clicks on an infected attachment. The worm does not exploit any system vulnerabilities to execute the attachment without user-interaction. Sober, Sasser and other similar worm date as far back as summer 2003 and we have seen since that over 160 variance and new relase of this very effective worm. The email sender address is Spoofed/forged it is important that the user understand that all worm/virus nowdays used spoofed/forged sender email address. Email spoofing may occur in different forms, but all have a similar result: a user receives email that appears to have originated from one trusted source when it actually was sent from another source. Email spoofing is often an attempt to trick the user into opening an infect attachment to release the worm/virus/trojan on the user computer memory |

