Search OutlookPower's 8,981 Outlook and all-things-email article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
EMAIL UNDER ATTACK
How the SoBig.F virus works
By Daniel Koffler

The latest incarnation of the SoBig worm has been devastating mail servers all over the Internet. SoBig was first spotted in the wild, in January. Since then, several new versions have popped up; the latest and most virulent, SoBig.F was first spotted on August 18th and has been wreaking havoc since.

This latest version of SoBig is especially nasty because it uses techniques from other worms, Trojans and even spammers to replicate itself and infect other systems. The most frustrating aspect of the SoBig worm to system administrators is the fact that the worm won't infect a system without the cooperation of a mail user.

Infectious beginnings
All of the SoBig variants are spread as an email attachment with either a ".pif" of ".scr" extension. The file names vary with each version of the worm, but the ones used by SoBig.F are listed in Figure A below.

FIGURE A


Here are the characteristics of SoBig.F. Roll over picture for a larger image.

Unlike other worms that take advantage of bugs in mail clients to automatically execute attachments, SoBig relies on enticing the email user to open the attachment manually. Because the email generally appears to come from someone they know many users end up opening the attachment and infecting their machine.

First wave: replication
Once run, SoBig.F will copy itself to your Windows directory as winppr32.exe and add registry entries to automatically start every time you boot your computer or login. Once installed and running SoBig.F will scour your hard disks for certain files and harvest any email addresses found within, creating a massive list of targets. Table A, above, lists the file extensions SoBig.F looks for.

SoBig.F doesn't rely on an installed mail client to send itself out (although it can); it comes with its own SMTP server to blast itself to its target list. SoBig will use email addresses from its target list as a spoofed "From" address in the mail envelope in order to make these messages appear to be more legitimate. SoBig.F uses carefully crafted subject lines to complete the illusion of a valid email from someone you know.

Second wave: is the cure worse then the disease?
Shortly after the worm was first seen in the wild and analyzed, most anti-virus vendors sent out immediate updates to their virus definitions to find and block SoBig.F. While some systems were already infected and infecting others, many other users were being protected by gateway and mail server anti-virus scanning products. These scanning products find the SoBig worm and either reject the message or clean it. The logic built into many of these products compounded the SoBig problem.


1  ·  2  ·  Next »
Other articles you might like
Home > Online Safety > Virus protection (7 articles)
   Readers clock in on Microsoft v. Symantec
   The great Windows Vista antivirus war
   Another month, another virus
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent OutlookPower Articles
Running auto-respond rules when Outlook is closed
Running rules when Outlook is closed
Disappearing text that's not supposed to disappear
What to do when Outlook complains about a program you know you uninstalled
Nothing says new year better than emails from crazy people
Say goodbye to the Uh-Ohs. Long live the Tens.
How to have a clean inbox in 2010
OutlookPower News Center
EML to PST Converter - Conversion of Popular Email Formats to Outlook
Windows 2000, XP SP2, Vista RTM support nears end
Windows 7 Just Being Honest About Battery Life
Remo Software Launches Data Recovery Software
US scientists get free cloud on-ramp
Leaky anti-virus defences letting malware through
Patch Tuesday Release Will Tie Microsoft's Record
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad: Apple's latest heartbreaker
David Gewirtz Online: CNN commentary and analysis
DominoPower: Lotusphere 2010: mobility and collaboration
-- Advertisement --

ONLINE GROUP CALENDAR - FOR UP TO 100 OF YOUR CLOSEST FRIENDS
Stay organized and in control with 24/7 access to all of your important events, projects and files --whether you're at work, at home or on the road.

You can share your calendar, projects and files so everyone in your office is up to date. Plus, search your entire group to find times when everyone is available to meet, manage company resources and much more.

Organize your entire team for as low as $9.95 per year (and yes, that's where the decimal place is supposed to be!)

Tap here to get started right away.

-- Advertisement --

Take Control Over Both Your Incoming And Outgoing Emails
File everything quickly and logically at the click of a mouse

Just tell QuickFile once where you want emails from each sender to be filed, and from then on a simple mouse click files them away automatically.

We know how important your sent emails are. With one click, your outgoing mail is sent and filed to the correct folder, automatically.

No more digging. It's all where it's supposed to be. Automatically.

Tap here to download a fully-functional 30-day trial.

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.
Editor's Login