SOBER Worm using FBI & CIA

Status
Not open for further replies.

brady

S e c u r e d
Messages
3,760
Location
Somewhere Sunny
Fake CIA, FBI E-Mails Power Sober Worm
Several new versions of the "Sober" e-mail worm have been mass-spammed to millions of e-mail boxes of the last 72 hours, posing as messages from the FBI and the CIA warning recipients that their Internet address has been implicated in illegal activity online.

The messages obviously were not sent by either agency, but any recipient who clicks on the attachment carried in the e-mail may indeed soon find their computers involved a variety of illegal activities at the hands of the virus authors. Both the CIA and the FBI have posted warnings about this latest worm on their Web sites.

FBI spokesperson Cathy Milhoan said the agency has been swamped with calls from people who received the e-mails because the message includes the actual phone number for the FBI headquarters in Washington. She said FBI operators have had their hands full routing calls and complaints to its Internet Crime Complaint Center in West Virginia, which received more than 4,000 complaints about the worm on Monday alone. The ICC typically receives 18,000 complaints each month.

Finnish anti-virus firm F-Secure calls the latest Sober outbreak the largest e-mail worm epidemic so far this year. UK-based e-mail security company MessageLabs said it has intercepted more than 2.7 million copies of Sober and its variants, noting that "the size of the attack indicates that this is a major offensive, certainly one of the largest in the last few months."

The criminals behind the Sober family of worms usually release several variants of the worm at once, each one altered slightly to evade detection by anti-virus software; security firms often take several hours to push out new virus definitions that their software uses to spot the worm.

The Sober worm uses its own e-mail engine to blast copies of itself out to all of the addresses found on an infected computer. Sober kills a long list of security applications that may be running, including anti-virus and firewall software, and prevents the victim from visiting a long list of security-related Web sites. Finally, it opens a backdoor on the infected machine, allowing attackers to upload whatever software they want.

As usual, be extremely cautious about clicking on links and opening e-mail attachments, even if they appear to come from someone you know. As Sober illustrates, you cannot always depend on scanning an attachment with anti-virus software to be sure it is safe to open. If you have any doubts about the integrity of an attachment or weren't expecting it, contact the person who sent it.
 
This email comes to you from the Virus Emergency Response Team at
Proland Software.

One more variant of W32/Sober Worm, named as W32/Sober.Y has been
discovered in the wild. The W32/Sober.Y Worm is rapidly spreading across
the internet. As in the case of the earlier W32/Sober Worm variants,
this variant also spreads through email. You may recall our previous alert,
which was run last week about the other variants of W32/Sober Worm.
Protector Plus users are advised to download the latest update.

We stress again to follow these general safe computing practices
to avoid similar virus/worm infections in the future.

a. Do not open any compressed file, unless it is scanned from
Protector Plus.
b. If the name of the attachment is associated with the subject
of the email, then it is possible that it is infected.
c. Do not fall prey for any attractive subject or attachment name,
which entices you to click on it.
d. Always scan your mailbox with latest version of Protector Plus.
e. Add the following latest virus information link to your browser's
favorites list to learn about new threats:

http://www.protectorplus.com/virusinfo/alerts.htm

About the W32/Sober.Y Worm:

W32/Sober.Y Worm spreads through email. This worm will infect
Windows systems. The subject and the content of the infected email
will be from a predefined list maintained by the worm like an email
sent by the FBI for visiting some illegal websites or some thing about
Registration or about your email account and password.

You can read more information about this worm at:

http://www.protectorplus.com/virusinfo/worms/sobery.htm

Also to know more, check this list of W32/Sober Worm variants
that appear in chronological order:

http://www.protectorplus.com/virusinfo/worms/sobervar.htm

Instructions to remove the W32/Sober.Y worm from
your computer:

An emergency virus database update to detect and remove this worm is
available to the users of Protector Plus anti-virus software. To download
this update from our web site, right click on Protector Plus icon from the
system tray then select 'Update Virus Database now!' from the menu.

Others can download a 30 day, fully functional evaluation copy from:

http://www.protectorplus.com/download

The evaluation copy will detect and remove this worm and also all
other known viruses, trojans and worms.

You are welcome to use this information to help any one who might need or
benefit from it. If you have questions or issues in the usage of
Protector Plus, please write to support@protectorplus.com .

The reason this alert is being sent to you is because either you or someone
acting on your behalf, subscribed to the Virus Alert Mailing List
maintained by us.

If you do not wish to receive further alerts, please send a return mail to
unsub@pspl.com
 
OMG my dad got that email just an hour ago , I just told him to delete it because panda antivirus said it was infected. I thought it was kind of wierd because he hollered upstairs " Hey mike I got an email from the FBI" and I was like WTF!!!
 
good thing your dad listens to you, if he had been anything like my family he would have completely ignored you (i guess having A+, CCNA, Network+ still doesnt mean crap)....

good example is when my mom asks me to help her with the computer and then tells me that she doesnt want to do what i tell her because "it wont fix it".. but thats off topic im just ranting

sounds like a serious worm=) thanks for the valuable information (although if i got a government email i wouldnt open it anyway)... actually... i dont open any email..... except from close friends or family members.......

... i have 8142 unread emails....

thank you Hotmail for giving me 500MB free storage=)
 
Status
Not open for further replies.
Back
Top Bottom