andsome Posted March 29, 2004 Report Share Posted March 29, 2004 Worm.Win32.Sober.E alert!Worm.Win32.Sober.E is the 5th variant of the highly spread Sober worm and was first seen by our analysts on 03/28/2004 at 2:30pm CET. Like its predecessors its origin could be found in one of the german speaking countries. The worm is coded in Visual Basic 6 and is packed using UPX. The file size of the packed worm file is 30,720 bytes.InfectionWorm.Win32.Sober.E comes via email to your PC. Worm mails have the following layout while always one of the subject, mail body and attachment options is chosen to generate the mail:Subject:HEYhey?Hey!OK Ok OK!OK OKOk ;-)Hi :-)hiHithxThx!THXThx !!!Mail body:;-)ha!HA :-)yo!lolLoLLOLYo!Attachment name:Text.zipText.pifRead.zipRead.pifGraphic-doc.zipGraphic-doc.pifdocument.zipdocument.pifWord.zipWord.pifSober.E can be detected and removed with a² with the latest signature updates loaded. The a² background guard blocks the worm immediately if it is started.A more detailed description of the worm can be found at the a² Malware Database:http://www.emsisoft.com/en/malware/?Worm.Win32.Sober.E Sincerley yours,Your a² Teamhttp://www.emsisoft.comNote! This is an automatically sent post only email. Please do not reply. Kindly note our contact page on our website. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.