1. Symantec/
  2. Security Response/
  3. W32.Sobig.A@mm


Risk Level 2: Low

January 9, 2003
February 13, 2007 11:42:13 AM
Also Known As:
W32/Sobig [McAfee], WORM_SOBIG.A [Trend], W32/Sobig-A [Sophos], I-Worm.Sobig [KAV], Win32.Sobig [CA]
Systems Affected:

NOTE: Due to a decreased rate of submissions, Symantec Security Response has downgraded this threat from Category 3 to Category 2 as of June 13, 2003.

The W32.Sobig.A@mm worm sends itself to all the addresses it finds in the .txt, .eml, .html, .htm, .dbx, and .wab files. The email message has the following characteristics:
From: big@boss.com
Subject: The subject will be one of these:
  • Re: Movies
  • Re: Sample
  • Re: Document
  • Re: Here is that sample

Attachment: The attachment will be one of these:
  • Movie_0074.mpeg.pif
  • Document003.pif
  • Untitled1.pif
  • Sample.pif

Before W32.Sobig.A@mm sends the messages, it sends a message to an address at pagers.icq.com.

The worm also attempts to copy itself to the following folders on all the open network shares:
  • \Windows\All Users\Start Menu\Programs\StartUp
  • Documents and Settings\All Users\Start Menu\Programs\Startup

Note: Symantec Security Response has received reports of W32.Sobig.A@mm downloading and installing the Backdoor Trojan, Backdoor.Lala.

Antivirus Protection Dates

  • Initial Rapid Release version January 10, 2003
  • Latest Rapid Release version August 8, 2016 revision 023
  • Initial Daily Certified version January 10, 2003
  • Latest Daily Certified version August 9, 2016 revision 001
  • Initial Weekly Certified release date January 10, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Douglas Knowles

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube