Visit the Ironworks Gaming Website Email the Webmaster Graphics Library Rules and Regulations Help Support Ironworks Forum with a Donation to Keep us Online - We rely totally on Donations from members Donation goal Meter

Ironworks Gaming Radio

Ironworks Gaming Forum

Go Back   Ironworks Gaming Forum > Ironworks Gaming Forums > General Discussion
FAQ Calendar Arcade Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 12-21-2005, 02:10 PM   #1
Morgeruat
Jack Burton
 

Join Date: October 16, 2001
Location: PA
Age: 45
Posts: 5,421
http://www.securityfocus.com/news/11365


Sober virus scares up child-porn confession
Robert Lemos, SecurityFocus 2005-12-20

A 20-year-old German man turned himself and his child-porn collection into authorities after believing a message propagated by the recent Sober virus that law enforcement officers were investigating his activities, Germany's Federal Criminal Investigation Office said on Monday.


“ I'm glad the guy was stupid enough to get caught. If you have to write viruses, something like the type of message is not bad. ”

Mikko Hyppönen, chief research officer, F-Secure

The Sober.X, also known as Sober.Y, virus attempts to fool computer users into running the malicious program by attaching itself to an e-mail that seems to come from the FBI or its German counterpart, known as the Federal Criminal Investigation Office or Bundeskriminalamt (BKA). The message implies that the law enforcement agency is investigating the recipient and asks the user to open up an attachment and answer questions.

In reality, the attachment is the Sober virus, which quickly takes control of the victim's PC to send more copies of itself, said Mikko Hyppönen, chief research officer for antivirus firm F-Secure.

"I'm glad the guy was stupid enough to get caught," Hyppönen said. "If you have to write viruses, something like the type of message is not bad."

While a prior version of the Sober virus had a similar message, this is likely the first time that a message intended to convince the recipient to run the virus scared a wrongdoer enough to turn themselves in. The Sober virus has made headlines because its creator has used the program to spread right-wing German propaganda and messages of hate. The latest variant is expected to download a payload on January 5, the anniversary of the founding of the Nazi party, according to antivirus firms.

While consumers have gotten better about distrusting the e-mail messages produced by such viruses, the number of PCs that are currently infected and compromised by the control software, known as bot software, installed by such viruses is in the millions, according to recent investigations.

The Sober virus does not install sophisticated bot software, but does compromise a PC so that it will spread future versions of the virus, F-Secure's Hyppönen said.

"Every new version of Sober infects every single computer already infected by Sober. So the bigger a Sober infection gets, the bigger the next launch of the next Sober is," he said.

The English version of the latest variant of the Sober virus has a common collection of possible messages, including notes from administrators and e-mail bounce notifications. In addition, there is a message that appears to come from the FBI or the CIA.

The English version of the message states:

we have logged your IP-address on more than 30 illegal Websites. Important: Please answer our questions! The list of questions are attached.

The Paderborn, Germany resident read the bulk e-mailed message sent by the latest Sober virus, panicked and contacted the police to admit he possessed child pornography, the BKA said in a statement. A search of the suspect's hard drive allegedly turned up pornographic images of minors--pictures that the suspect also sent out through e-mail, the BKA stated.

The FBI did not immediately know if any similar cases had occurred in the United States.
__________________
"Any attempt to cheat, especially with my wife, who is a dirty, dirty, tramp, and I am just gonna snap." Knibb High Principal - Billy Madison
Morgeruat is offline   Reply With Quote
Old 12-21-2005, 02:30 PM   #2
Sir Degrader
Thoth - Egyptian God of Wisdom
 

Join Date: November 3, 2001
Location: Canada
Age: 64
Posts: 2,871
Wasn't this posted a day or two ago in the GE forum?
Sir Degrader is offline   Reply With Quote
Old 12-21-2005, 02:40 PM   #3
Luvian
Ironworks Moderator
 

Join Date: June 27, 2001
Location: Montreal, Quebec, Canada
Age: 44
Posts: 6,766
Yeah, for a week I received maybe 5 variant a day of that virus. It was funny the first day, but it got old fast...
__________________
Once upon a time in Canada...
Luvian is offline   Reply With Quote
Old 12-21-2005, 03:09 PM   #4
Sir Degrader
Thoth - Egyptian God of Wisdom
 

Join Date: November 3, 2001
Location: Canada
Age: 64
Posts: 2,871
Especially since we're in Canada. I don't think I've gotten it, but if I did, I'd probably reply ( a big no no, but meh), with something to the effect "come and get me, you yank bastards!"
Sir Degrader is offline   Reply With Quote
Old 12-21-2005, 04:13 PM   #5
Morgeruat
Jack Burton
 

Join Date: October 16, 2001
Location: PA
Age: 45
Posts: 5,421
Quote:
Originally posted by Sir Degrader:
Wasn't this posted a day or two ago in the GE forum?
mebbe but since I hardly ever go there, let alone post there if it was I didn't see it.
__________________
"Any attempt to cheat, especially with my wife, who is a dirty, dirty, tramp, and I am just gonna snap." Knibb High Principal - Billy Madison
Morgeruat is offline   Reply With Quote
Old 12-21-2005, 05:59 PM   #6
krunchyfrogg
Red Dragon
 

Join Date: February 14, 2004
Location: NY, USA
Age: 49
Posts: 1,516
I hope this virus, if used by the athorities only, never gets blocked by any spyware programs.
__________________
<i>A life is not important, except in the impact it has on other lives.</i><br />- Jackie Robinson<br /><br /> [img]\"http://img394.imageshack.us/img394/3353/salsashark7xl.gif\" alt=\" - \" />
krunchyfrogg is offline   Reply With Quote
Old 12-21-2005, 06:25 PM   #7
Luvian
Ironworks Moderator
 

Join Date: June 27, 2001
Location: Montreal, Quebec, Canada
Age: 44
Posts: 6,766
Quote:
Originally posted by krunchyfrogg:
I hope this virus, if used by the athorities only, never gets blocked by any spyware programs.
This virus is not used by any authorities, it just claim it is from the FBI so that you open up the file and get infected.
Luvian is offline   Reply With Quote
Old 12-21-2005, 06:50 PM   #8
Sir Degrader
Thoth - Egyptian God of Wisdom
 

Join Date: November 3, 2001
Location: Canada
Age: 64
Posts: 2,871
Oh yes, because the FBI sends me SO many .txt file attachments... LOL.
Sir Degrader is offline   Reply With Quote
Old 12-21-2005, 07:01 PM   #9
Luvian
Ironworks Moderator
 

Join Date: June 27, 2001
Location: Montreal, Quebec, Canada
Age: 44
Posts: 6,766
Quote:
Originally posted by Sir Degrader:
Oh yes, because the FBI sends me SO many .txt file attachments... LOL.
It wasn't txt. I just checked and it's list.zm9

[ 12-21-2005, 07:03 PM: Message edited by: Luvian ]
Luvian is offline   Reply With Quote
Old 12-21-2005, 07:19 PM   #10
shamrock_uk
Dracolich
 

Join Date: January 24, 2004
Location: UK
Age: 42
Posts: 3,092
Nah, it'll be .bat, .pif or .exe normally.

.zm9 is what Zone Alarm's mail checker leaves the attachment as.
shamrock_uk is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Interesting article on Viruses (virusi?) Arvon General Discussion 4 05-22-2005 07:19 AM
I am in danger... viruses perhaps? URGENT! Xen General Conversation Archives (11/2000 - 01/2005) 18 01-08-2004 04:52 PM
Some new computer viruses (PG13) Arvon General Conversation Archives (11/2000 - 01/2005) 13 11-25-2003 09:27 PM
Help stop the spread of viruses! Memnoch General Conversation Archives (11/2000 - 01/2005) 33 09-14-2001 09:14 PM
Computer Viruses Victor von Steiner General Conversation Archives (11/2000 - 01/2005) 4 07-04-2001 01:36 PM


All times are GMT -4. The time now is 04:10 PM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
©2024 Ironworks Gaming & ©2024 The Great Escape Studios TM - All Rights Reserved