Open main menu
Home
Random
Recent changes
Special pages
Community portal
Preferences
About Wikipedia
Disclaimers
Incubator escapee wiki
Search
User menu
Talk
Dark mode
Contributions
Create account
Log in
Editing
Sobig
(section)
Warning:
You are not logged in. Your IP address will be publicly visible if you make any edits. If you
log in
or
create an account
, your edits will be attributed to your username, along with other benefits.
Anti-spam check. Do
not
fill this in!
==Technical details== The Sobig viruses infected a host computer by way of the above-mentioned attachment. When this is started they will replicate by using their own [[SMTP]] agent engine. E-mail addresses that will be targeted by the virus are gathered from files on the host computer. The [[file extension]]s that will be searched for e-mail addresses are: * .dbx * .eml * .hlp * .htm * .html * .mht * .wab * .txt The Sobig.F variant was programmed to contact 20 [[Internet Protocol|IP addresses]] on [[User Datagram Protocol|UDP]] port 8998 on August 26, 2003 to install some program or update itself. It is unclear what this program was, but earlier versions of the virus had installed the [[WinGate]] [[proxy server]] software—a legitimate product—in a configuration allowing it to be used as a [[Backdoor (computing)|backdoor]] for [[spamming|spammers]] to distribute unsolicited e-mail. The Sobig worm was written using the Microsoft Visual C++ compiler, and subsequently compressed using a data compression program called [[tElock]]. The Sobig.F worm deactivated itself on September 10, 2003. On November 5 the same year, [[Microsoft]] announced that they will pay $250,000 for information leading to the arrest of the creator of the Sobig worm. Ruslan Ibragimov is attributed to be the original creator of the worm, however this is not confirmed.[https://www.eweek.com/security/who-wrote-sobig/#:~:text=Ruslan%20Ibragimov%20of%20Moscow%2C%20Russia,team%2C%20authored%20the%20Sobig%20virus.]
Edit summary
(Briefly describe your changes)
By publishing changes, you agree to the
Terms of Use
, and you irrevocably agree to release your contribution under the
CC BY-SA 4.0 License
and the
GFDL
. You agree that a hyperlink or URL is sufficient attribution under the Creative Commons license.
Cancel
Editing help
(opens in new window)