Virus Busters Home


The W32/Sobig.E@MM Virus Spreads Steadily; Forges Its "From:" Field

by Bruce P. Burrell (bpb@umich.edu)
for the U-M Virus Busters (virus.busters@umich.edu)
Last significant update: 25 June, 2003

This information can be freely reproduced in any medium, as long as the information is unmodified.

The Sobig virus family affects only PC computers running Windows; Macintosh users, and users of other non-Windows operating systems cannot be infected by this virus. These users may, however, see plenty of infected email from Sobig.E, in particular, so its "annoyance factor" is large.

On 25 June, 2003, the W32/Sobig.E virus was discovered; our antivirus vendor provided us with a fix early that afternoon -- the 4273 drivers. We made this solution available, within about half an hour of its release. In fact, VirusScan protected our users since the 4266 drivers were released Wednesday May 21, 2003 although these drivers used "heuristic techniques" to recognize the variants released previously (this recognition was fuzzy, of course but sufficient to protect us well in advance). The 4273 drivers accurately identify Sobig.E as "W32/Sobig.E@MM"

We haven't seen a lot of copies of Sobig.E here at the University, but it definitely is out "In The Wild" to at least a moderate degree.

The main features of Sobig.E are these:

The main properties about Sobig.E are that it spreads fairly successfully, and the forged From:field. Here is what happens frequently:

  1. Person A's computer gets infected
  2. Sobig.E harvests email addresses, including addresses for persons B and C

  3. Sobig.E sends email from A's computer, using a From: address of person B, and a To: address of person C.

  4. Person C's antivirus software notices that the email "from" person B is infected, so C emails B to warn him or her.

  5. Person B scans his or her computer and finds no virus; person B is very confused.

What should you do if:

The URL for this document is http://www.umich.edu/~virus-busters/sobig-e.html

For virus or hoax info, please see our main page (http://www.umich.edu/~virus-busters/) or go to another reputable site, like The Urban Legends Reference Pages (leaving our site).

   -BPB

Virus Busters Home


Last updated: Friday, 27-Jun-2003 08:31:09 EDT.
University of Michigan Virus Busters - virus.busters@umich.edu

visits to this page since 25 June, 2003 22:00 EDT