Return of the Sober worm
p2pnet.net News:- “The FBI today warned the public to avoid falling victim to an on-going mass e-mail scheme wherein computer users receive unsolicited e-mails purportedly sent by the FBI,” said an alert issued in February this year.
The subject was the Sober K worm. Now there’s another variant, Sober.P, which surfaced yesterday and is still spreading, says F-Secure director of research Mikko Hypponen.
It overloaded the systems of FIFA (Fédération Internationale de Football Association ) to the extent organizers weren’t able to receive or send normal e-mails yesterday, says vp Wolfgang Niersbach, quoted by F-Secure.
“One example of a mail Sober.P might send is a German message promising free tickets to the soccer world championships,” says Hypponen on the company’s blog.
“The ticket sales for the next World cup were opened on Monday – the same day the virus was released.”
Below is an example”
From: Ticket@fifa.de
Subject : WM-Ticket-Auslosung
Herzlichen Glueckwunsch,
beim Run auf die begehrten Tickets für die 64 Spiele der
Weltmeisterschaft 2006 in Deutschland sind Sie dabei.
Weitere Details ihrer Daten entnehmen Sie bitte dem Anhang.
Ihr "ok2006" Team
St. Rainer Gellhaus
— FIFA-Pressekontakt:
— Pressesprecher Jens Grittner und Gerd Graus
— FIFA Fussball-Weltmeisterschaft 2006
— Organisationskomitee Deutschland
— Tel. 069 / 2006 – 2600
— Jens.Grittner@ok2006.de
— Gerd.Graus@ok2006.de
Attachment: Fifa_Info-Text.zip
Something you think we should know? tips[at]p2pnet.net
<——To err is human, but for a real disaster you need a computer——>
See:-
an alert – Virus lurks within FBI email, p2pnet, February 23, 2005
surfaced yesterday – New Sober worm likes soccer, p2pnet, May 3, 2005
F-Secure – Sober Agent, May 3, 2005






May 4th, 2005 at 9:36 pm
here’s the header of the email i got with a .txt attachment that had the sober worm in it:
From:”Service@lists.wku.edu” <Service@lists.wku.edu>
Subject:FwD: your email was refused
Datum: 03.5.2005 10:23:57
An: “server@XXX.XX” <server@XX.XX>
the body stated that my email (which i had NEVER sent) encountered a problem and couldn’t be delivered.
the attachmnet with the worm in it is called: “autoemail-text.zip”
i know it had the sober in it because when i clicked to open it, NAV told me.