News.com Mobile
for PDA or phone
Login: Forgot password? | Sign up

Sober worm offshoot trades on Paris Hilton, FBI

By John Borland
Staff Writer, CNET News.com
Published: November 22, 2005, 12:37 PM PST

There is no Easter Bunny, and that's not a real Paris Hilton video in your e-mail box. Nor is the FBI likely to be e-mailing you to ask you questions about visiting illegal Web sites.

A new variant of the Sober worm made the network rounds Tuesday, attempting to entice people into clicking on attachments purporting to be threats from the law enforcement agency or video clips of the hotel heiress and her reality TV co-star Nicole Richie.

Antivirus companies said the worm gained some traction over the weekend and on Monday. It's a minor modification of the "Sober" virus that has flared up several times over the past year. But this latest variant, graded as a medium-level threat, appeared to be trailing off as security providers have responded.

"This one is virulent and will reproduce itself easily but does not have much of a payload," said David Perry, the global director of education at antivirus company Trend Micro. "For the time being, this particular strain is probably done."

Some antivirus companies said the worm was still spreading fast, however. In a blog posting, security company F-Secure said Internet companies have seen "several millions of infected emails" over the course of hours.

"The numbers we're now seeing...are just huge," wrote F-Secure Chief Research Officer Mikko Hypponen. "This is the largest email worm outbreak of the year, so far."

One version of the e-mail carrying the worm appears to be a letter from the FBI saying the agency has found evidence that the computer user has been visiting illegal Web sites. It asks the recipient to click on the attachment to answer questions.

The FBI released a warning on Tuesday saying it never sends unsolicited e-mails.

"The FBI takes this matter seriously and is investigating," the agency said in its statement. "Users are instructed to delete the e-mail without opening it."

Another version of the e-mail used a message purporting to be from the Central Intelligence Agency. A third, a German-language variant, contained a threatening message from a German law enforcement agency.

A separate version purports to offer a download manager for "video clips, pictures and more" of Hilton and Richie. All operate the same way, once the attachment is activated, however.

If activated, the worm drops several files onto a computer and searches for e-mail addresses stored in address books or elsewhere in memory and sends copies of itself to those destinations. If it finds Microsoft's anti-spyware and antivirus software running, it turns the protections off.

Several other variants of a different virus, dubbed "Mytob," are also making the rounds. The e-mails carrying them purport to be a message from an e-mail service provider or from support staff providing notification about a changed password or suspended account.

Antivirus companies rate the danger of this worm as "low," but as always, advise against clicking on unknown attachments to e-mails.

 5 comments
Post a comment

TalkBack

How stupid do you have to be...

Jeff Dennis   Nov 25, 2005, 9:21 AM PST

Just received two and one being CIA

Guy Jones   Nov 22, 2005, 7:26 PM PST

windows must die

Jesus   Nov 22, 2005, 2:46 PM PST


Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 8:30 AM PST
View as:
Power could cost more than servers, Google warns Intel calls MIT's $100 laptop a 'gadget' Sober code cracked Prize in Indian talent search: A year on Bill Gates' team Creative wants to make Apple pay Garages hold mythic power in Silicon Valley Police blotter: Nude 'profile' yields Yahoo suit Gartner: IT managers should use Xbox Clogger of P2P networks to shut down Former software chief admits stealing trade secrets NTP says payment would end RIM dispute Photos: Legendary HP garage gets makeover  Scientific quests: Better bananas, nicer mosquitoes BET promotes ring tone sales with video pop-ups A camera that has it all? Well, almost
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Top picks from News.com readers

Readers who read Sober worm offshoot trades on Paris Hilton, FBI also read...

More Info

Daily spotlight

Video: A video slam-dunk

Here's a look at the tech behind those TV and online highlights of pro basketball games, in a narrated video produced by the NBA and Silicon Graphics Inc.

Photos: Gizmos made in Japan

Japan is still a leader in product design and innovation. Here are some new and notable gadgets.

Video: "The power to organize" online

Meetup.com founder and CEO Scott Heiferman says Meetup is spreading beyond America. The service, Heiferman says, is helping "make the world a friendlier place."

Innovations battle natural calamities

Scientists hope integrating cutting-edge technology projects will help predict and mitigate natural disasters.

Debating Wikipedia's open-source label

High Impact The online encyclopedia is a broadly communal effort, but it's not run the same way as open-source software.

Police blotter: Nude 'profile' yields Yahoo suit

Woman says ex-boyfriend posted nude photos and her phone number in a Yahoo Personals profile. She sued for $3 million.

High-tech animation in indies' grasp

Competing with digital toon powerhouses like Pixar isn't easy. But cheaper tech, outsourcing are making it possible.

Ogre to slay? Outsource it to China

Affluent online gamers are paying workers at Chinese game-playing factories to play games' early rounds for them.

Video: The incredible, shrinking glaciers

This NASA-produced video is a dramatic and colorful look at our planet from high above, and the changes that are taking place.

Image: AOL searches for the stars

TMZ.com, AOL's new online magazine promises inside scoops on Hollywood's hottest stars.

Clock's ticking on new Sober onslaught

Mass-mailing worm is programmed to download new instructions in January, which could indicate a new outbreak.

Photos: New animal discovered in Borneo

A creature that looks like a cross between a cat and a fox is photographed in the rainforest.

advertisement
CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use