20/08/2003

SoBig.F


New email infection SoBig.F.

Name: I-WORM.SoBig.F

AKA:

Type: Internet Worm

Size: 73369 bytes 

Platform: Win 95/98/ME/NT/2000/XP 

Description:

SoBig.F is a new variant of the SoBig Worm; this worm spread itself throug email messages, retrieving address from Outlook's contacs or html files.

The worm sends email messages using the infected user as email sender (the address gets retrieved from outlook address book).

 

Messages has the following subjects: 

Your Details,  Thank you!,  Re: Thank you!,  Re: Wicked screensaver,  Re: Your application,

Re: Approved, Re: Details, Re: That movie, Re: Re: My details

 

With the following bodies:
See the attached file for details
Please see the attached file for details

 

It attachs the following files:

wicked_scr.scr
movie0045.pif
application.pif
document_9446.pif
details.pif
your_details.pif
thank_you.pif
document_all.pif
your_document.pif

 

Once executed, SoBig.F worm creates the file winppr32.exe inside Windows' folder. It then edits the registry so to execute that file at every windows startup.

Any information published on our site may be used and published on other websites, blogs, forums, facebook and/or in any other form both in paper and electronic form as long as the source is always and in any case cited explicitly “Source: CRAM by TG Soft www.tgsoft.it” with a clickable link to the original information and / or web page from which textual content, ideas and / or images have been extrapolated.
It will be appreciated in case of use of the information of C.R.A.M. by TG Soft www.tgsoft.it in the report of summary articles the following acknowledgment/thanks “Thanks to Anti-Malware Research Center C.R.A.M. by TG Soft of which we point out the direct link to the original information: [direct clickable link]”

Vir.IT eXplorer PRO is certified by the biggest international organisation: