Feeds

World Cup worm gives Windows users the willies

'ere we go (again)

  • alert
  • submit to reddit

Security for virtualized datacentres

A new version of the increasingly tedious Sober email worm series is ensnaring victims by posing as an email from the next year's World Cup organising committee. Like previous variants, Sober-P spreads as an infected ZIP attachment to messages written in either German or English.

Infected emails pose as ticket confirmation messages from organisers of the football World Cup, due to be held in Germany next year. The worm composes messages with subject lines such as "WM-Ticket-Auslosung" and "Your Password" with attachments such as Fifa_Info-Text.zip containing a .pif payload file. Sober-P only infects Windows machines.

The first appearance of the worm on Monday coincided with the start the second phase of ticket sales for Germany 2006. No further tickets for countries who sold out their first phase allocations are been released at this point (13 nations including Germany and England) but that hasn't stopped attempts by virus writers to exploit global interest in the tournament.

Most anti-virus vendors rate Sober-P as medium-risk. Home users are at greatest risk which means, yet again, that it's time to update anti-virus tools and to resist the temptation to open suspicious-looking emails. Sober-P is the fourteenth incarnation of a worm first seen in October 2003.

In other football related news, tickets for Tuesday's Champions' League semi-final between Liverpool and Chelsea are on sale on eBay from between £205 and £950. The resale of UK football tickets contravenes eBay rules but touts are chancing their arm anyway in the hopes of making a killing on tickets with a face value of somewhere between £30 to £50. ®

Related links

FIFA issues warning over virus

Related stories

Sober worm shakes Windows security
Sober worm speaks with forked tongue
Sober email worm gives Windows users the DTs
FBI issues Sober notice over Windows worm
The strange decline of computer worms (perhaps we spoke too soon)

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
Admins! Never mind POODLE, there're NEW OpenSSL bugs to splat
Four new patches for open-source crypto libraries
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.