|
2005¦~11¤ë23¤é
3¯ÅSober.XÅܺدfÂΨӶլ¤¬¤ ¥´µÛFBI¡BªÝ²úµ·§Æº¸¹yºX¼m¦Ó¨Ó
ÁɪùÅK§J©IÆ~¥Î¤á¥ß§Y§ó·s¯f¬r©w¸qÀÉ ¤Á¤Å¶}±Ò¨Ó¸ô¤£©úªº¹q¤l¶l¥ó
¯fÂΦWºÙ¡GSober.X¯fÂÎ (W32.Sober.X@mm)
¯fÂίżÆ: ¬Ò¬°3¯Å
¯fÂΦWºÙ»¡©ú¡G@mmªí¥Ü·|¤j¶q¶l±H´²§Gªº¯fÂÎ
¯fÂά¡°Ê¤£¥V¯v¡ASoberÅܺئ¿´ò¦A²{¡CÁɪùÅK§J¦w¥þ¾÷¨îÀ³Åܤ¤¤ß¤µ(23)µý¹êSober.XÅܺدfÂΡ]W32.Sober.X@mm¡ACME-681¡^¥¿¦bºô¸ô§Ö³t¬y«¡A¥Ñ©ó·P¬V³q³ø¼Æ¼W¥[¡AÁɪùÅK§J±N¨ä¯fÂΦM®`«ü¼Æ´£¤É¦Ü3¯Å¡]5¯Å¬°³Ì¦MÀI¡^¡CSober.X¬O³z¹L¤§«eªºSoberÅܺدfÂΧ@¬°¸õªO¦P¨B¶Ç°e¡A©Ò¥HÂX´²³t«×¬Û·íÅå¤H¡C¦P®ÉÁɪùÅK§J¤]±Nºô¸ô·ÀI«ü¼Æ½Õ¤É¬°²Ä¤G¯Å¡u¤¤«×·ÀI¡v¡A©IÆ~¨Ï¥ÎªÌ¥ß§Y¤Wºô¤U¸ü³Ì·sªº¯f¬r©w¸qÀÉ¡A¤Á°O¤£n¶}±Ò¨Ó¸ô¤£©úªº¹q¤l¶l¥ó¡A¨Ã¥B´£¨Ñ²¾°£¤u¨ã¨Ñ¥Î¤á¤U¸ü¡C
ÂÂSoberÅܺدfÂÎ©ó®æªL«Âªv¼Ð·Ç®É¶¡11¤ë21¤é±ß¤W¤C®É°_¡A¶}©l¦P¨B¤j³W¼Ò¶Ç°e§¨±aSober.X¯fÂΪº¹q¤l¶l¥ó¡CÂÂSoberÅܺدfÂγz¹Lºô¸ô®É¶¡¨ó©w(Network Time Protocol¡ANTP)¦P¨B®Õ¥¿®É¶¡¡AµM«á³]©w©ó®æªL«Âªv¼Ð·Ç®É¶¡10¤ë29¤é±ß¤W¤C®É«áªº²Ä23¤Ñµo°e¶l¥ó¡C
Sober.X ÅܺدfÂη|±q¨ü·P¬Vªº¹q¸£¤¤¦¬¶°¹q¤l¶l¥ó¦ì§}¡AµM«á§Q¥Î SMTP ¤ÞÀº±N¥»¨¨Ë¸Ë¦¨¶l¥óªþ¥ó¶Ç°e¥X¥h¡C¹q¤l¶l¥ó¬O¥H¼w¤å©Î^¤å¼¶¼g¡A¨Ã³z¹L¤£¦Pªº¥D¦®©M¤º¤å»¤©ä¦¬¥ó¤H¶}±Òªþ¥ó¡A¨Ò¦p°²«_¬O FBI ©Î CIA ±H¥Xªº¶l¥ó¡A©Î¬O¥HªÝ²úµ·§Æº¸¹y (Paris Hilton) ªº·Ó¤ù§@·E¤l¤Þ»¤¨Ï¥ÎªÌ¤W·í¡CÁɪùÅK§J¦w¥þ¾÷¨î¤¤ ¤ß º¥ý ¦b 11 ¤ë 19 ¤é °»´ú¥X¸Ó¯fÂΡA¨Ã¦b·í¤Ñ´£¨Ñ³Ì·s¯f¬r©w¸qÀÉ¡CºI¦Ü¥Ø«e¬°¤î¡AÁɪùÅK§J¤w¦¬¨ì¨Ó¦Û¥ø·~ºÝªº·P¬V³q³ø¶W¹L 1,600 °_¡AÓ¤H¥Î¤áºÝ³q³ø¶W¹L 300 °_¡A¦Ó¨È¤Ó°Ï¤]¦¬¨ì 23 °_³q³ø¡C
¥Ñ©ó Sober.X ÅܺدfÂηP¬V±¡§ÎÄY«¡A¥[¤W¤é«e¥X²{°w¹ï·L³n IE º|¬}ªº§ðÀ»µ{¦¡¡AÁɪùÅK§J±Nºô¸ô·ÀI«ü¼Æ (DeepSight ThreatCon) ±q²Ä¤@¯Å½Õ¤É¬°²Ä¤G¯Å¡u¤¤«×·ÀI¡v¡Cºô¸ô·ÀI«ü¼Æ¬°ÁɪùÅK§JÆ[¹î¥þ²yºô¸ôÀô¹Ò«á¡A¨Ì·ÀIµ{«×°ª§C¤À¬°¤@¦Ü¥|¯Å¡A¥|¯Å¬°³Ì¦MÀI¡C
ÁɪùÅK§J¤w´£¨ÑSober.X¯fÂΪº²¾°£¤u¨ã¨Ñ¨Ï¥ÎªÌ¤U¸ü¡G http://securityresponse.symantec.com/avcenter/venc/data/w32.sober.removal.tool.html?Open
W32.Sober. X¯fÂίS¼x
- ¦¬¶°¨ü·P¬V¹q¸£¸Ìªº¹q¤l¶l¥ó¦ì§}¡A±Hµo¤j¶q©U§£¶l¥óªº¤è¦¡ÂX´²¶Ç¼½
ƒÞ - ¤W·íªº¦¬¥ó¤H¶}±Òªþ¥ó«á·|¥X²{¸ÑÀ£ÁY¥¢±Ñªº¿ù»~°T®§
ƒÞ - µM«á¯fÂη|Ãö³¬·L³n´c·Nµ{¦¡²¾°£¤u¨ã(mrt.exe)¥H°§C¨t²Î¦w¥þ³]©w
ƒÞ - ¨ü¼vÅTªº§@·~¨t²Î¡GWindows 2000¡BWindows 95¡BWindows 98¡BWindows Me¡BWindows NT¡BWindows Server 2003¡BWindows XP
¶l¥ó¯S¼x
- ¶l¥ó¬O¥H^¤å©Î¼w¤å¼g¦¨
- ¶l¥ó¥D¦®¡G¡]¥H¤U¦C¥X^¤åªº¶l¥ó¥D¦®¡^
- - Your Password
- - Registration Confirmation
- - smtp mail failed
- - Mail delivery failed
- - hi, ive a new mail address
- - You visit illegal websites
- - Your IP was logged
- - Paris Hilton & Nicole Richie
- ¶l¥ó¤º¤å¡G¥H¶BÄF°T®§¤Þ»¤¦¬¥ó¤H¶}±Ò¹q¤l¶l¥ó¡A¨Ò¦p¨Ë¸Ë¦¨FBI¡BCIA±H¥Xªº®£À~«H¡A©Î¥´µÛªÝ²úµ·§Æº¸¹yªººX¸¹§l¤Þ¥Î¤á¶}±Òªþ¥ó¡C
¦³ÃöW32.Sober. X¯fÂΪº¸Ô²Ó¸ê®Æ¡A½Ð°Ñ¾\¥H¤Uºô§}:
http://www.symantec.com/region/tw/techsupp/avcenter/venc/data/tw-w32.sober.x@mm.html
ÁɪùÅK§J¦w¥þ¾÷¨îÀ³Åܤ¤¤ß(Symantec Security Response)
°w¹ïºô¸ô¤W²£¥Íªº¦UºØ´c·N«Â¯Ù¡A¦w¥þ¾÷¨îÀ³Åܤ¤¤ß´£¨Ñ¹d²ÓÃû¿òªº¤ÀªR¡A¤F¸Ñ¨ä¹B§@¼Ò¦¡¡A¨Ã´£¨Ñ§Y®ÉªºÀ³ÅܤθѨM¤è®×¡C
ÁɪùÅK§J¹q¸£¯fÂΦM®`«ü¼Æ¡G
ÁɪùÅK§J¦w¥þ¾÷¨îÀ³Åܤ¤¤ß®Ú¾Ú¹q¸£¯f¬r/ÂηP¬V½d³ò¡B¦M®`µ{«×¥H¤Î´²¥¬³t«×¡A±N©Ò°»´ú¨ìªº¯f¬r/Âζi¦æ¦M®`«ü¼Æ1¨ì5ªº¤À¯Å¡A¯Å¼Æ¶V°ª¡Aªí¥Ü¦¹¤@¯f¬r/ÂηP¬V³t«×¡B¦M®`µ{«×¥H¤Î´²¥¬³t«×³£¸û§Ö¡A¦]¦¹¥i¯à³y¦¨ªº¼vÅT½d³ò¤]´N¶V¼s¡C
¦M®`«ü¼Æ 5¯Å ·¥«×¦MÀI¡C¦p¡G±¡®Ñ¯fÂÎè¥X²{®É(VBS.LoveLetter.A)
¦M®`«ü¼Æ 4¯Å ¦MÀI¡C ¦p¡GBlaster¡ASobig.F¡BMydoom
¦M®`«ü¼Æ 3¯Å ¤¤«×¡C ¦p¡G°g´A¨à¯fÂÎ
¦M®`«ü¼Æ 2¯Å »´«×¡C ¦p¡Gªwªw¨k«Ä¡]Bubbleboy¡^
¦M®`«ü¼Æ 1¯Å §C«×¡C
|