About > Computing & Technology > Antivirus Software > Email Viruses > Articles > Mass Attack of SoBig.F 
Search       
 

Antivirus Software

with Mary Landesman
Your Guide to one of hundreds of sites
 Home · Articles · Forums · Chat · Newsletters · Help    
Subjects

  ESSENTIALS
· Virus Protection
· Blaster Worm Info
· JDBGMGR.EXE Hoax
· Securing Internet Explorer
· Hoax Encyclopedia
  BUYER'S GUIDE

Tutorials
Top Picks
About.com Resource
Adware/Spyware
Amiga Virus Info
Antivirus Vendors
Content Filtering
Downloads DOS
Downloads Windows
Email Viruses
Free Tools
Glossary
Groupware
Hoaxes and Myths
In The Wild Lists
Linux/Unix Viruses
Macintosh Resource
Macro Viruses
PC Viruses
Reading Material
Security Mailings
Security Resources
Software Reviews
Tips for Safety
Trojans
Virus Encyclopedia
Wireless Threats

Subject Library

All articles on this topic

 
Stay up-to-date!
Subscribe to our newsletter.
 
ResultsAbout
New from About.com!
Get Paid to Improve Search
Find Results Now:
Software
Computer
Freeware
Genealogy
FTP
 
 
   

Mass Attack of SoBig.F

 
      Related Resources
• SoBig.F Description
• SoBig.F Removal
• Finding the Real SoBig.F Sender

Elsewhere on the Web
• SoBig.E: Evolution of the Worm
• SoBig.A: Spam Worm

About Antivirus Software
Subscribe to the Free Newsletter
Your Email Address:

 
 

Worm wreaks havoc worldwide

Aug 26 2003  

On the 18th of August 2003, using a hacked computer and a stolen credit card, someone calling themselves "Misiko" posted the binaries for SoBig.F to various porn newsgroups via Easynews, using the subject: "Nice, who has more of it? DSC-00465.jpeg". By the following day, hundreds of thousands of copies of the Sobig.F email worm were flooding users' inboxes worldwide. Arriving with subject lines such as 'Re: That movie', 'Re: Your application', 'Your details', 'Re: Wicked screensaver', 'Thank you!', 'Re: Thank you!', 'Re: Details', 'Re: Approved', SoBig's assumed goal was to turn infected systems into a spam server. Within 24 hours, UK-based MessageLabs had detected one million SoBig.F emails, at a rate of 1:17 emails - much higher than previous record holder Loveletter (1:28). But these enormous figures were small potatoes compared to NY-based Berrex Computer Solutions, also a managed service provider. In its first day, Berrex had already stopped three million of the SoBig.F emails and the numbers were still rising.

Though the numbers seemed alarming, it was soon clear that relatively few source IPs were involved in the mailings. In short, despite millions of SoBig.F emails swamping servers and threatening a Denial of Service (DoS) attack on mail clients, it appeared that the actual number of infected hosts might have been as low as tens of thousands. While at first glance this may appear heartening, consider the implications of a worm that only infected such a small number, but impacted millions. In short, SoBig.F is a rude reminder that we are all susceptible to the follies and negligence of our online companions. One man's unprotected system can become a global nightmare for us all.

As with previous variants, it was known that SoBig.F intended to update itself. In this case, from 1900-2200 (UTC) each Friday and Sunday beginning August 22nd and ending September 6th, SoBig.F would attempt to procure a text file via the Internet. This second stage download of the text file would provide the worm with directions for where to download future components, dubbed the third stage. Examining the code, investigators were able to decrypt a set of twenty IP addresses, presumed to be used for this second stage download. Moving to thwart the worm, nearly all of the IP addresses were shutdown minutes before SoBig.F was to begin its update quest on the 22nd.

Security experts disagree as to what happened next. Some claimed the operation a success, declaring the SoBig.F worm had been successfully stopped from downloading its second stage instructions and thus no third stage was possible. Others, including system administrators, reported activity from the worm that indicated the downloads had occurred, a few providing unique IP addresses that did not appear on the original "magic 20" list found in the worm's code. Adding to the mystery, at least some of the SoBig.F worm mailings halted abrubtly minutes after Friday's 1900UTC download was due to commence. Considering that the worm is programmed to stop spreading after the download instructions have been received, the sudden stop of some of them lent credence to the argument that SoBig.F had been able to update on at least some of the systems.

Find the real SoBig.F sender

SoBig.F spoofs the From address, making thousands of innocent users look like villains. If you're getting flooded with SoBig.F emails, or getting angry email from folks accusing you of sending it, follow the steps outlined in this article to track the real culprit.

 
 ~ Mary Landesman


Email this page!

    
Explore More on the About Network!
Related Sites
Business Software
Email
Focus on PC Support
Internet/Network Security
Urban Legends and Folklore
Cancer on the Job
Career Planning Guide Dawn Rosenberg McKay explains patients' employment rights.
What Are Ghosts?
Paranormal Guide Stephen Wagner looks at different theories about the cause of haunting.
Horrifying Hoaxes
Urban Legends Guide David Emery lists the 25 most common hoaxes on the Internet today.
Search About
  

About Us | Advertise on This Site | User Agreement | Privacy Policy | Kids' Privacy Policy | Help
Copyright  © 2003 About, Inc. About and About.com are registered trademarks of About, Inc. The About logo is a trademark of About, Inc. All rights reserved.