Due to an increased rate of submissions, Symantec Security Response has upgraded this threat from a Category 2 to a Category 3.
W32.Sobig.E@mm is a mass-mailing worm that sends itself to all the email addresses that it finds in the files with the following extensions:
.wab
.dbx
.htm
.html
.eml
.txt
The email falsely purports that Yahoo sent it (
support@yahoo.com).
Email Routine Details
The email message has the following characteristics:
From:
support@yahoo.com (NOTE: W32.Sobig.E@mm spoofs this field. It could be any address.)
Subject: The subject line will be one of the following:
Re: Application
Re: Movie
Re: Movies
Re: Submitted
Re: ScRe:ensaver
Re: Documents
Re: Re: Application ref 003644
Re: Re: Document
Your application
Application.pif
Applications.pif
movie.pif
Screensaver.scr
submited.pif
new document.pif
Re: document.pif
004448554.pif
Referer.pif
Attachment: The attachment name will be one of the following:
Your_details.zip (contains Details.pif)
Application.zip (contains Application.pif)
Document.zip (contains Document.pif)
Screensaver.zip (contains Sky.world.scr)
Movie.zip (contains Movie.pif)
NOTE: The worm de-activates on July 14, 2003, and therefore, the last day on which the worm will spread is July 13, 2003.
Symantec Security Response has created a tool to remove W32.Sobig.E@mm.
Also Known As: Win32.Sobig.E [CA], W32/Sobig-E [Sophos], W32/Sobig.e@MM [McAfee], WORM_SOBIG.E [Trend]
Type: Worm
Infection Length: 82,195 bytes (zip file), 86,528 bytes (executable)
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected: Macintosh, OS/2, UNIX, Linux