Skip to main content

Worm:W32/Sobig

Classification

Category:

Malware

Type:

Worm

Aliases:

  • Worm:W32/Sobig

Summary

The Sobig worm was found in the wild on January 9th 2003. The worm spreads via email and network shared drives. It also tries to download other files from web pages located on a Geocities site.

Removal

Technical Details

Update 2003-04-23 09:00 GMTIt has been reported that the webpage that controls the trojan downloader component of the worm had been updated for a period of time. The page pointed to a location containing a trojan (detected by F-Secure Anti-Virus as Backdoor.Delf.da). At the time of this update, the control page is no longer available.

Infection

When the worm is run on a system for the first time it copies itself to the Windows System Directory using the name winmgm32.exe. After this a new value, pointing to this file is added to the registry as

  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WindowsMGM

This way the worm will be started every time Windows starts.

Activity

Sobig contains a routine that downloads a text file from a website. The content of the file is used as a URL to download some program and run it on the infected machine. At the time of writing this description this feature is inactive, as the file points to a non-exisiting location.

The worm might affect network printers. In such cases printers might start to print garbage.

Propagation (email)

Email addresses are collected from files with various extensions:

  • .WAB
  • .DBX
  • .HML
  • .HTML
  • .EML
  • .TXT

The sender address is fixed, it is always big@boss.com.

Subjects are randomly chosen from the following list:

  • Re: Here is that sample
  • Re: Document
  • Re: Sample
  • Re: Movies

The message body says:

  • Attached file:

The message contains an executable attachment. The attachment name can be one of the following:

  • Sample.pif
  • Untitled1.pif
  • Document003.pif
  • Movie_0074.mpeg.pif

The infected emails are sent using the worms own STMP engine that is independent from the users email settings.

Propagation (Local Area Network)

Sobig lists all the network shares available to the infected computer and tries to copy itself to either of these directories:

  • Windows\All Users\Start Menu\Programs\StartUp

or

  • Documents and Settings\All Users\Start Menu\Programs\Startup

These are the default startup folders for Windows 9x and NT/XP based systems. If the worm is copied there Windows will run it next time the user logs in. This way the system gets infected.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.