Home / malwarePDF  

Email-Worm:W32/Sober.AA


First posted on 11 April 2007.
Source: SecurityHome

Aliases :

Email-Worm:W32/Sober.AA is also known as Email-Worm.Win32.Sober.aa, Worm:Win32/Sober.AH@mm.

Explanation :

Sober.AA is a mass mailing worm that uses English and German texts in the e-mails generated by this worm.

This worm is written in Visual Basic. It is compressed using UPX.

Installation to the System

Upon execution, this worm creates the folder PoolData in the Windows directory. It then creates several copies of itself as follows:


These files are identical to each other with a single byte difference located at offset 0xA0.

This worm also creates the following Registry entries in order to enable its automatic execution upon system start up:


Spreading via E-mail messages

Before spreading, this worm scans files with certain extensions on all hard disk drives to harvest e-mail addresses. All files with the following extensions are scanned:


This worm creates the following files, where the system harvested e-mail addresses are stored:


It can then send e-mails with English and German based text together with a Zip archived copy of itself as an attachment.

It ignores any email addresses that contain any of the following substrings:


The worm composes the following German messages:

Subject:


Body:


Attachment:


--- or ---

Subject:


Body:

Attachment:


--- or ---

Subject:


Body:


Attachment:


It also composes the following English messages:

Subject:


Body:


Attachment:


--- or ---

Subject:


Body:


Attachment:


These e-mail messages may appear to come from the following senders:

Last update 11 April 2007

 

TOP

Malware :

Family: