You are here: silicon.com > Software > Malware

Malware

Sober virus code cracked by security firms

Administrators warned to make PCs safe by 5 January 2006...

Tags: sober

By Munir Kotadia

Published: 12 December 2005 09:55 GMT

Antivirus companies say they have cracked an algorithm that was being used by the Sober worm to "communicate" with its author.

The latest variant of the Sober worm caused havoc in November by duping users into executing it by masking itself as emails from the FBI and CIA. Antivirus companies were aware that the worm somehow knew how to update itself via the web. The worm's author programmed this functionality to control infected machines and, if required, change their behaviour.

Finnish antivirus firm F-Secure revealed last week that it had cracked the algorithm used by the worm and could now calculate the exact URLs the worm would check on a particular day.

Mikko Hypponen, chief research officer at F-Secure, explained that the virus author has not used a constant URL because authorities would easily be able to block it.

He said in his blog: "Sober has been using an algorithm to create pseudorandom URLs which will change based on dates. Ninety-nine per cent of the URLs simply don't exist...However, the virus author can pre-calculate the URL for any date, and when he wants to run something on all the infected machines, he just registers the right URL, uploads his program and 'bang', it's run globally on hundreds of thousands of machines."

According to F-Secure's calculations, on 5 January 2006, all computers infected with the latest variant of Sober will look for an updated file located in a list of domains.

Hypponen advised administrators to ensure any infected PCs can't upgrade automatically by blocking access to the domains.

Adam Biviano, premium services manager at Trend Micro, said that blocking the URLs could be beneficial, but the safest bet would be to ensure that PCs are safe.

He said: "Blocking those URLs is not a bad idea but administrators need to make sure their machines are not infected in the first place."

Munir Kotadia writes for ZDNet Australia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Veritas Netbackup Consultant

Production NetBackup domains are in-scope, and 2 Disaster Recovery (DR) NetBackup domains. My client a large Service Intergration Partner is ...

Rotating Equipment / Machines Engineer - North East England!!

Equipment / Machines Engineer. Are you looking for unmatched career potential? Then i have the job for you! My client, based near Hull, is a global ...

Control Systems Algorithm Developer - Bristol

My client, a leading international consultancy based in Bristol, are urgently seeking a talented control systems algorithm development engineer, to ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: