Virus
virus

SoBig spam hits millions of mailboxes

SoBig is so prevalent, as sixth variant mass mails itself around the world

Written by Iain Thomson

A new variant of the SoBig worm has been filling inboxes worldwide, after it was mass-mailed to millions of email addresses.

The worm arrives as a .Pif (Program Information file) attachment in emails with the headers:

  • Re: That movie
  • Re: Wicked screensaver
  • Re: Your application
  • Re: Approved
  • Re: Re: My details
  • Re: Details
  • Your details
  • Thank you!

The worm is 72,000 bytes. Once activated it copies itself to Windows as 'winppr32.exe' and edits the registry to ensure that it starts whenever the computer boots.

All email addresses on the PC are collected and are then sent copies of the worm using the worm's own SMTP engine.

Email headers are spoofed to hide the location of infected machines, and it can also be spread using network shares.

"SoBig.F seems to be extremely prevalent," said Graham Cluley, senior analyst at antivirus company Sophos.

"We suspect the author must have spammed it to millions of people, which gave it a huge head start in infections.

"As with all the other SoBig variants, if IT managers would just block .Pif files at the firewall they'd have very few problems."

This is the sixth variant on the SoBig worm, which first surfaced in January of this year.

All operating systems from Windows 95 to XP are affected, although the worm will automatically deactivate on 10 September.

Tags:

Further reading

2004 to be year of the 'superworm'

Virus writers create secret P2P virus network   More...

Viruses 'a blessing in disguise'

Tell that to the IT managers ...   More...

SoBig boosts IT security spending

Fears lead to increased budgets to fight hacking and virus attacks   More...

SoBig will spawn yet another variant

Antivirus company warns of new SoBig worm on the way after version F goes away   More...

Related articles

Storm worm back with a vengeance

Quarter of all detected threats during August, says BitDefender   More...

Halloween 'skeleton' spam hides Storm Trojan

Don't let your PC be turned into a zombie   More...

Hacker spam poses as old school friend

Blonde with pigtails infects the curious with a Trojan   More...

Fujacks hackers jailed in China

Do no pass Go. Do not collect 100,000 yuan   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement