[PLUG] The big virus in the news - Update on Action
Michael Rasmussen
mikeraz at patch.com
Fri Aug 22 11:33:02 UTC 2003
On Fri, Aug 22, 2003 at 07:50:31AM -0700, Paul Heinlein wrote:
> Percentage-wise, Sobig-F is off the charts, outrunning its nearest
> rival by well over 2000% -- and it's not done yet. By Sept. 10, when
> Sobig-F is supposedly set to turn itself off, I expect we'll have
> intercepted over 25,000 copies of this thing. No other worm/virus
> comes close.
>
> Until Sobig-G, of course, which will likely be even "better" than its
> -F-in' cousin.
This advisory just came across my desk at work:
(Extra corp-security speak left in for entertainment value)
Note that 1900 UTC is Noon local time.
SUBJECT:
Sobig.F Set to Update 1900 UTC
SUMMARY:
The Sobig.F worm will update to remote servers starting 1900 UTC today.
What code will be downloaded has not been determined. This behavior
has been reported by major antivirus vendors: F-Secure, TrendMicro,
Symantec and Sophos. Infected computers are using NTP to synchronize
the activation to start exactly at the same time around the world: at
19:00:00 UTC. The worm starts the download attempt by sending a probe to
port 8998/udp of the master server. Then, the server replies with a URL,
where the worm can download the file to execute.
RECOMMENDATIONS:
Block inbound traffic on ports 99x/udp. Block outbound traffic on port
8998/udp. Monitor NTP requests (port 123/udp), as these could be coming
from infected computers. (The frequency of such checks for an infected
computer should be once per hour.)
Update your antivirus software's definitions immediately. If possible
configure your antivirus software to update and scan automatically every
day. Gateway mailservers should be filtering for possibly malicious .vbs,
.bat, .com, .exe, .scr or .pif files, and .zip files containing these
attachments. Filtering on subject line may affect legitimate traffic,
and it is in any case easy for the virus creator to vary these fields.
Ensure that network shares are protected with strong passwords and
disable any unneeded services.
Do not open or execute files from untrusted sources. Scan all downloaded
.com, .exe, .scr or .pif files with updated antivirus software.
Users who know not to run .exe files are continuing to run unknown
screensavers. They should be educated to the fact that these files,
.pif files and .zip files are executables too, equally as dangerous as
.exe files. The contents of zip files should always be examined (e.g. by
right-clicking and choosing "Open with Winzip") before extracting.
--
Michael Rasmussen aka mikeraz
Be appropriate && Follow your curiosity
http://www.patch.com/ http://wiki.patch.com/
http://wiki.patch.com/index.php/BicycleCommuting
The fortune cookie says:
I don't do it for the money.
-- Donald Trump, Art of the Deal
More information about the PLUG
mailing list