News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

Sober worm offshoot lurks behind class photo

By Ina Fried
Staff Writer, CNET News.com
Published: October 6, 2005, 12:41 PM PDT

Now that's a really bad high-school photo.

A new variant of the Sober e-mail worm has started spreading as an attachment that claims to be an old class photo sent by a schoolmate. But if recipients open the file, they don't see a picture of themselves in braces. Instead, a worm tries to steal their information and then mail itself to others.

Antivirus software maker Sophos said the Sober variant is now the second most commonly reported virus, accounting for approximately 10 percent of all reports in the last 12 hours.

"Playing off of flattery, nostalgia and the success of Web sites (like Friends Reunited and Classmates Online), this dangerous virus has only one aim: to steal information from as many victims as it can," Gregg Mastoras, a senior security analyst at Sophos, said in a statement.

But others downplayed the risk. Symantec, for example, rated the bug a "2" on its scale of 1 to 5, with 5 being the most threatening.

"We're seeing a number of submissions--but not anything overwhelming," said Eric Chien, principal software engineer at Symantec Security Response. "It's not going to be a Blaster," he added, referring to the MSBlast worm outbreak.

Chien said there are two reasons for this. First, both companies and individuals are becoming more sophisticated in their awareness of threats. Businesses are blocking e-mail attachments that carry executable files, even those that are compressed, while individuals are treating unsolicited attachments with more suspicion, even if they recognize the sender.

"I think people are definitely more tuned in to your classic e-mail worm," Chien said.

Second, virus writers are increasingly putting their energy toward more targeted attacks, often those aimed at quietly making money through theft rather than attracting infamy through a mass outbreak. That said, Chien said he doesn't see the classic mass-mailing worm going away.

"We'll still have them," he said. "They will sort of be that background noise."

Sober variants, in particular, have topped the ranks this year, with one version spewing hate messages and another offering free World Cup tickets. Although it is making a comeback this year, the bug has been around since 2003.

As is typical, the virus is getting different names from different companies. Sophos is calling it Sober-O, Secunia is calling it Sober.R, and Symantec is calling it W32.SoberQ@mm. But under a new identifier system designed avoid name confusion, it is known by all as CME-151.

"It's less sexy of a name, but at least it provides a cross-reference for vendors and customers," Chien said.

Read more on this story's topics and companies

 4 comments
Post a comment

TalkBack

Email Viruses.

Oscar Rat   Oct 6, 2005, 2:00 PM PDT

advertisement

Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 7:18 AM PST
View as:
A Firefox for music? Taking on QWERTY's illogic Bidding adieu to Pentium M New spyware claim against Sony BMG 'High' risk in Symantec antivirus software flaw Microsoft looks beyond AOL Banned by Google? Digital TV switch set for early 2009 iTunes and QuickTime flaw detailed Microsoft settles with Google over executive hire France may sanction unfettered P2P downloads Police blotter: Judge lets Feds track cell phones Boy joins a sordid online world through his Webcam How to find the perfect telescope U.S. vs. the world on file-sharing
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Top picks from News.com readers

Readers who read Sober worm offshoot lurks behind class photo also read...

More Info

Daily spotlight

Music start-up hears call of Firefox

High Impact The Pioneers of the Inevitable take aim at iTunes, with open-source music software called Songbird.

Year in review: Browsers get their second wind

The Web offers a fresh lease on life, with healthy competition and dramatic changes in usage.

Bidding adieu to Pentium M

Intel's familiar chip label is about to give way to Duo and Solo, sources say.
Kicking off 2006 with Yonah

New spyware claim against Sony BMG

Software used to thwart illegal copying was downloaded even if users rejected license agreement, according to latest charge.

Your TV will soon be all-digital

High Impact Congress approves a bill that sets a 2009 deadline for when television stations must end analog broadcasts.

IBM sits out Office document standards effort

Big Blue won't participate in an international committee that is standardizing Microsoft Office document formats.

Japan may create its own search engine

A consortium of tech companies and universities will consider whether to take on today's search powerhouses.

Year in review: The transformation of the telephone

Bells and cable companies battled it out in 2005, and Net calling and wireless services came to the fore.

PartyGaming looks to fuel poker explosion

With interest in Net poker growing outside the U.S., company tries to capture the market.

Playing favorites on the Net?

High Impact A proposal in Congress could tip the scales toward some services and create a two-tiered Internet.

Scammers jingle all the way

The Grinch has company as cyberscams take on a holiday flavor and credit card fraud experiences a snowball effect.
Images: Holiday phishing

Santa IM worm hits AOL, MSN and Yahoo

IM.GiftCom.All tries to trick instant-messaging users into clicking on a link that delivers malicious software to PCs.


CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use