Feeds

Sobig-F is dead

Good riddance

  • alert
  • submit to reddit

Using blade systems to cut costs and sharpen efficiencies

The prolific Sobig-F virus stopped spreading today, marking the end of arguably the worst single email-borne viral epidemic to date.

Managed services firm MessageLabs blocked the virus a staggering 16.5 million times during its month-long spread. At the height of the epidemic, one in 17 emails the firm scanned were viral (other companies say the situation was even worse).

Sobig-F, first detected on 18 August, is the sixth variant issued in the Sobig series and appears to be the most sophisticated to date, according to MessageLabs. Like earlier versions of the virus it was programmed to stop spreading on a set date: for Sobig-F this date was September 10.

Although Sobig-F isn't spreading any more, infected machines still need to be identified and decontaminated.

Sobig-F outstripped the infamous LoveBug, Klez and Kournikova viruses in prevalence but its overall impact is arguably less than that of Internet worm like Slammer and Blaster. In scanning for fresh victims, Blaster generated copious quantities of traffic that had a measurable effect on Internet performance, according to Net performance monitoring firm, which says Sobig-F had a much lesser effect on the Net.

That's small comfort for the numerous users with prominent Net addresses, like us at The Reg, who were carpet bombed by the worm, whose email spoofing tactics created mass confusion.

The effects of the worm raised questions about the effectiveness of traditional AV scanner software. There's concern that it's only a matter of time before a similarly effective email nastie is next released.

Mirror, mirror on the wall: what's the worst virus of them all?

According to a study from security firm TruSecure released earlier this month, the past four years have seen a rise in virus worm infections of 11 per cent per year.

The company broke down this analysis to review on the impact of eight of the biggest viruses over the last four years, giving an indication of the relative severity of each.

Data obtained from the study was obtained from surveys on NT BugTraq, responses from vendors participating in ICSA Labs certification programme, emails passing through TruSecure's Shadowmail messaging service, group monitoring of firewalls and IDS systems and monitoring of the hacker underground by TruSecure.

The figures are accurate within an uncertainty of 20 per cent, according to TruSecure.

Sobig.F - August 2003

The biggest and most virulent worm over the last four years. It infected one in 15 messages during the peak of the outbreak last month. Sobig-F infected 200 million email messages across the Internet during its first week of activity, causing $1 billion in corporate impact through loss of productivity, according to TruSecure. The company estimates Sobig impacted 30 per cent of smaller organisations and 15 per cent of large organisations, chiefly because of the message storm the worm generated. Of these only one in 20 were actually infected.

Blaster - August 2003

One in three (34 per cent) of organisations were infected, 15 per cent of which suffered a moderate or major impact, according to TruSecure. Blaster exploited the DCOM vulnerability - inside infections were very common in large organisations, which led to a significant impact.

Slammer - January 2003

Infected 10 per cent of smaller organisations and 48 per cent of larger companies, according to TruSecure. Slammer exploited a MS SQL Server vulnerability and spread over VPNs, laptops and direct attacks. Perimeter filtering, desktop configuration upgrades and testing eventually succeeded in halting the outbreak.

Klez-H - throughout 2002

Largest infection in 2002. Slow but steady producer of infectious email. TruSecure estimates it infected 12 per cent of corporations via mail, infecting up to 100 million emails in total.

Nimda - September 2001

Nimda, according to TruSecure, infected 68 per cent of corporations, half (48 per cent) of which suffered a major infection. The number of remote users and sites heavily influenced the level of infection. Perimeter filtering, desktop configuration upgrades and testing eventually succeeded in containing the virus.

Code Red - July 2001

According to TruSecure, 38 per cent of corporations suffered a moderate or major infection because of Code Red. The level of infection was highest among businesses with remote users and remote sites.

Love Letter (Love Bug) - May 2000

Infected one in twelve messages and in excess of 100 million total infected messages in the first week. Caused significantly more harm in large organisations than Sobig, infecting nearly 50 per cent of corporations, causing an average of $155,000 of damages to each, and a total cost of $2 billion, according to TruSecure. ®

Related stories

Why Sobig is bad for privacy and AV vendors
AV bigwigs weigh in on Sobig debate
The trouble with anti-virus
Blaster rewrites Windows worm rules
US warns nuke plants of worm threat
Sobig second wave attack fails to strike
Sobig-F is fastest growing virus ever - official
Why spammers lurve the 'Microsoft support' worm (Sobig-A)
Virus writers outpace traditional AV
AV vendors sell 'blunt razor blades'

Boost IT visibility and business value

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Securing Web Applications Made Simple and Scalable
Learn how automated security testing can provide a simple and scalable way to protect your web applications.