FRISK Software International


Summary of W32/Sobig.D@mm
Alias:I-Worm.Sobig.gen, W32/NetworkWorm, Win32.HLLM.Reteras, Sobig.D
Discovered: 18 Jun 2003
Definition files: 18 Jun 2003
Risk Level: Medium
Distribution:Medium
Infection Method:Mass mailing and network shares
 
Jump to:
Brief description
Technical description

Brief Description
A new variant of Sobig, known as Sobig.D was found on June 18., 2003. This is a minor variant of Sobig.C.

Sobig.D has a limited lifespan - it will deactivate its speading routine on July 2nd, 2003.


Technical Description
The worm copies itself to the Windows folder as
cftrb32.exe

and adds the following registry key:
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] SFtrb Service = %WindowsDir%\cftrb32.exe

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] SFtrb Service = %WindowsDir%\cftrb32.exe

so that it's launched every time Windows starts.

Mass mailing

This variant uses the same mass mailing component as the previous one, Sobig.C. The default e-mail address used is "admin@support.com".

Message subjects are chosen from:

Re: Documents Re: App. 00347545-002 Re: Movies Application Ref: 456003 Re: Your Application (Ref: 003844) Re: Screensaver Re: Accepted Your Application Re: Application

Attachment names are chosen from:

Document.pif app003475.pif movies.pif ref_456.pif Application844.pif Screensaver.scr Accepted.pif Applications.pif Application.pif

The body of the messages is always fixed:

See the attached file for details.

Gathers e-mail addresses from files with extensions:

'.wab' '.dbx' '.htm' '.html' '.eml' '.txt'

Local Area Network propagation.

It also tries to infect computers with open shares, copying itself to the following locations:

Windows\All Users\Start Menu\Programs\Startup\

Documents and Settings\All Users\Start Menu\Programs\Startup

Updating

This variant appears to listen in several ports for messages from its creator. Those message will contain URLs from where to download additional components.



[Analysis: F-Secure Anti-Virus Research Team; June 18., 2003]
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is