name: Sobig
type: Worm
host platform: Windows
first Incidence: 01/17/03
last incidence: 08/20/03
level of incidence: High
damage capacity: Medium
links:
McAfee,
Norton
look for:Emails from
- big@boss.com
- support@microsoft.com
- bill@microsoft.com
- Sobig may also use a random address
Subjects of
- Re: Movies
- Re: Sample
- Re: Document
- Re: Here is that sample
- Your details
- Approved (Ref: 38446-263)
- Re: Approved (Ref: 3394-65467)
- Your password
- Re: My details
- Screensaver
- Cool screensaver
- Re: Movie
- Re: My application
- Re: Submited (004756-3463)
- Re: 45443-343556
- Re: Approved
- Approved
- Re: Your application
- Re: Application
- Re: Documents
- Re: App. 00347545-002
- Application Ref: 456003
- Re: Your Application (Ref: 003844)
- Re: Screensaver
- Re: Accepted
- Your Application
- Re: Application
- Re: Movie
- Re: Movies
- Re: Submitted
- Re: ScRe:ensaver
- Re: Documents
- Re: Re: Application ref 003644
- Re: Re: Document
- Your application
- Application.pif
- Applications.pif
- movie.pif
- Screensaver.scr
- submited.pif
- new document.pif
- Re: document.pif
- 004448554.pif
- Referer.pif
Attachments of
- Movie_0074.mpeg.pif
- Document003.pif
- Untitled1.pif
- Sample.pif
- your_details.pif
- ref-394755.pif
- approved.pif
- password.pif
- doc_details.pif
- screen_temp.pif
- screen_doc.pif
- movie28.pif
- application.pif
- screensaver.scr
- movie.pif
- submited.pif
- 45443.pif
- documents.pif
- approved.pif
- application.pif
- Document.pif
- app003475.pif
- movies.pif
- ref_456.pif
- Application844.pif
- Screensaver.scr
- Accepted.pif
- Applications.pif
- Application.pif
- Your_details.zip (contains Details.pif)
- Application.zip (contains Application.pif)
- Document.zip (contains Document.pif)
- Screensaver.zip (contains Sky.world.scr)
- Movie.zip (contains Movie.pif)
Sobig is a computer worm affecting Windows-based machines. It is spread
through an email attachment. Opening the attachment installs the worm on the
machine. Once infected, the worm looks for email addresses in address books
and other documents residing on the infected machine and sends itself out as
an email to these addresses. Besides the annoyance factor, the worm does not
do any file damage.
Sobig has mutated numerous times. The latest is Sobig.F. As variants have
differing capacities, hallmarks and removal requirements, Symantec has
developed pages and removal tools for each.
Sobig.A:
Info,
Removal Tool
Sobig.B:
Info,
Removal Tool
Sobig.C:
Info,
Removal Tool
Sobig.D:
Info,
Removal Tool
Sobig.E:
Info,
Removal Tool
Sobig.F:
Info,
Removal Tool
|