New Worm Variant Attacking Windows - New Sober Worm Bilingual   4/20/2005 - 951 views, 4 Comments

Summary: There's a new Sober worm in town, and this one is both clever and bilingual, being sent in both English and German. The new Sober worm version, being called W32.Sober.N@mm (such appealing names!) originated in Europe, and announces itself in English with ...

Previous Article « A Look Inside the Blog Spammer’s Bag of Tricks
Read Next Article » At Long Last: Sync Your Sidekick with Your Mac with Markspace’s New Missing Sync for Hiptop

There’s a new Sober worm in town, and this one is both clever and bilingual, being sent in both English and German. The new Sober worm version, being called W32.Sober.N@mm (such appealing names!) originated in Europe, and announces itself in English with some version of “I’ve_got your EMail on my_account!” and in German with “FwD: Ich bin’s nochmal”, which, according to Babelfish means “FwD: I bin’s again” (which can’t be right - do any of you gentle readers speak German?)

One thing which makes this one more compelling is that it seems as if it really could have been sent by a human (and even more so for the German version, as German recipients are used to getting viruses and worms in English, not their native tongue). The text of the email then goes on to say “Hello, First, Very Sorry for my bad English. Someone is sending your private e-mails on my address”, and goes on to explain that the email is forwarded in the attached file. Finally, the payload (the data file containing the worm) is labelled “your_text.zip”. So it seems, at least to some, entirely plausible that someone actually ended up with email meant for them, and has forwarded it to them in a file. (Ok, probably not plausible to most of Aunty’s readers, of course, but to some.)

Of course what really happens when the file is opened and the worm is unleashed is that it searches your hard drive for your contacts and other email addresses, and sends itself out to them.

As always, the best defense is a good offense: be sure that your virus and worm definitions in your anti-virus program are current.

Previous Article « A Look Inside the Blog Spammer’s Bag of Tricks
Read Next Article » At Long Last: Sync Your Sidekick with Your Mac with Markspace’s New Missing Sync for Hiptop

Get a FREE summary of the week's articles every Friday!
(You can stop it any time!)
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Be sure to watch for the confirmation email!

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  New Windows Worm Offers Free Soccer Tickets

»  Fake Email from the FBI or CIA is Really a Worm, Not Steven Allison

»  Sober Worm Convinces Pedophile to Turn Self In!

»  New Sober Worm Progeny Spews German Hate Spam

For additional similar stories check out our archives on Virus & AntiVirus

 

4 Comments »

  1. Ich bin’s nochmal……………I have it once more!

    Comment by Deirdre Henderson — 4/20/2005 @ 11:00 pm

  2. “Ich bin?s nochmal” means “It’s me again” in German.

    Comment by Keith — 4/20/2005 @ 11:18 pm

  3. Looks like Babelfish is living up to its name - if you want a correct translation, ask an interpreter! Luckily, Keith saved the day before I had a chance.

    Comment by Elfi — 4/21/2005 @ 12:00 am

  4. I am german, and to get rid of confusion, Keith is right, it is It’s me again

    Comment by Andrea — 4/21/2005 @ 4:37 pm

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
The Internet Patrol
Patrolling the Internet for You!