Home Malware Programs Worms W32.Sobig.E

W32.Sobig.E

Posted: March 28, 2006

This worm propagates via network shares and via email using its own SMTP engine. It gathers its target email addresses from files with the extensions:
WAB, DBX, HTM, HTML, EML, TXT

From field is such that a different email
address appears instead of the email account it uses to send the messages. It can use
support@yahoo.com, an email address that it has obtained from the computer, or the user
name and the domain of the currently logged on user.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 i-worm.sobig.exe
Loading...