Announcement

Collapse

Advertising Inquiries

See more
See less

More news about SoBig.F Virus

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • More news about SoBig.F Virus

    Massive virus attack expected
    MSNBC News Services
    Computer security experts Friday were frantically racing to find and switch off 20 home computers thought to be targeted by a massive attack of the Sobig.F virus, which has already wreaked havoc with users by becoming the fastest e-mail outbreak ever seen.
    A FRANTIC GLOBAL hunt was under way from the United States to South Korea to find and switch off 20 home computers with high-speed broadband connections that were due to be targeted by hundreds of thousands of computers infected by Sobig.F at 3:00 p.m. ET Friday.
    Security experts discovered only late Thursday that the Sobig.F virus, which has sown panic since Monday by infecting Windows systems and using them to send a deluge of junk mail, was harboring a sinister secret.
    Hidden within the virus is an instruction to the infected machines to make contact at 3:00 p.m. ET with the 20 computers, which host an unidentified program.
    "The problem is we don't know what that program is. It could mean a smiley face dances across your screen or it could be something massive," said Carole Theriault, anti-virus consultant at Sophos Anti-Virus. "It's still under the control of the virus writer."
    Even if the mystery program is a harmless gag, the sheer volume of Internet data converging on the 20 computer targets could slow the Internet to a crawl.
    The time trigger is set to be activated again at the same time on Sunday, August 24.
    The search for the owners of the 20 machines -- to get them to disconnect before the deadline -- has had some success.
    "We've taken more than half offline," said Mikko Hypponen, anti-virus research manager at Finland's F-Secure. "But if one is left standing, there will be an attack."

  • #2
    Sobig.F Mass-Email Worm - Trojan Horse Functionality

    Synopsis:

    The latest variant in the "Sobig" family, Sobig.F is propagating
    aggressively across the Internet. Sobig.F is propagating via email only,
    and it is not related to the recent spate of Internet worms. Sobig.F
    employs some new techniques to attempt to evade anti-virus software, and
    infected computers may be controlled by external third-parties. It
    contains hidden functionality that attempts to download and execute a file
    at a specific time.

    Impact:

    Aggressive propagation of mass-email worms have been known to cause
    localized email outages due to the load placed on email servers. Sobig.F
    contains backdoor code which may allow the author or originator of the worm
    to control infected computers. This may allow the author to steal
    information, run specific Trojan horse programs, or install unsolicited
    email (Spam) relays. The new file payload is currently unknown as the virus
    receives a URL to the new file at a certain time (3:00pm EDT).

    For the complete ISS X-Force Security Alert, please visit:
    http://xforce.iss.net/xforce/alerts/id/151

    Comment

    Working...
    X