Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 14th, 2005, 04:46 PM
IBK IBK is offline
AV Expert
 
Join Date: Dec 2003
Location: Innsbruck (Austria)
Posts: 1,689
Exclamation Sober.q

Sober.q will be around soon. Update your scanners to detect it as soon as it spreads.

(I read this on KAV weblog)
__________________
http://www.av-comparatives.org
AV-Comparatives WEBLOG / FORUM
AV-Comparatives Fan-Page on Facebook
Not speaking here on behalf of AV-Comparatives. Post questions in our forum.
  #2  
Old May 15th, 2005, 12:15 AM
Firecat's Avatar
Firecat Firecat is offline
Incredibly Massive Poster
 
Join Date: Jan 2005
Location: The land of no identity :D
Posts: 7,672
Default Re: Sober.q

How do they know that Sober.q is coming?
__________________
Last edited by Radu : Today, at 5:32 AM. Reason: Found new malicious code

  #3  
Old May 15th, 2005, 12:25 AM
Trans's Avatar
Trans Trans is offline
Regular Poster
 
Join Date: Dec 2003
Posts: 76
Big Grin Re: Sober.q

Quote:
Originally Posted by Firecat
How do they know that Sober.q is coming?

Maybe some first incidents ?
  #4  
Old May 15th, 2005, 04:41 AM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Sober.q

They probably monitored the "update" URL's that the previous Sober is trying to download files from. The trigger date for updating of the last Sober variant passed a few days ago, so the author probably placed the new variant.

We detect it as Sober.Gen.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #5  
Old May 15th, 2005, 07:14 AM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Sober.q

The new Sober started to send out spam (some rightwing crap) this night, trigger date was 11th of May, 4 days later is the date to start spamming. The first spam mails arrived at midnight.
12 days after the trigger date it is supposed to download updates.

So this is not an email worm, it's a trojan spammer. It doesn't have code to send attachments.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
  #6  
Old May 15th, 2005, 08:54 AM
jlo jlo is offline
Frequent Poster
 
Join Date: Nov 2004
Location: UK
Posts: 473
Default Re: Sober.q

Thanks for the heads up!

Not many Av's have updated yet for it?

As you said KAV has the update and F-secure updated yesterday but Symantec, Trend, AVG and Avast no sign of update yet. Had a look at VirusTotal and cant see any samples submitted yet so it will be interesting to see how quickly and if this spreads.

Cheers

Jlo
  #7  
Old May 15th, 2005, 08:57 AM
Stefan Kurtzhals's Avatar
Stefan Kurtzhals Stefan Kurtzhals is offline
AV Expert
 
Join Date: Sep 2003
Posts: 625
Default Re: Sober.q

It was uploaded at Jotti and VirusTotal, so all antivirus companies should have a sample by now.

As it is only a trojan, it doesn't self-replicate/email. So there is no danger except the spam it sends.
__________________
Chuck Norris does not use any antivirus software. He knows the hashes of all clean software on earth. Even those that are not compiled yet. It is not known if he got that list from dividing by zero or counting to infinity.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:33 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums