SoBig Encore Not Likely, Say Experts

SoBig Encore Not Likely, Say Experts

Written By
Dennis Fisher
Dennis Fisher
Aug 27, 2003
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Anti-virus experts are downplaying recent claims that there is a second hidden cache of data in the SoBig worms code that directs infected computers to contact a group of seven mail and name servers owned by an AOL Time Warner Inc. subsidiary.

Officials at BitDefender, a unit of Softwin SRL in Bucharest, Romania, said on Tuesday that they had found a second set of encrypted server addresses in the code of the eminently annoying SoBig.F worm. All of the server names appear to belong to Time Warner Telecom Inc.

“The code is quite straightforward and accurately indicates that the virus asks for information at this address, waits for the answer and than runs the downloaded file on the infected host,” said Mihai Chiriac, a virus researcher at BitDefender. “As for the moment, there is no information at any of these addresses; we cant predict the codes effects.”

BitDefenders claims come less than a week after a similar warning from several anti-virus companies touched off fears that the hundreds of thousands of SoBig-infected machines would all contact one of 20 PCs whose IP addresses were hidden in the worms code. Once connected to one of the PCs, the infected machines would download an unknown file and experts worried the action could be the precursor to a large-scale secondary attack.

But security specialists were able to locate and take down most of the 20 PCs before the hour at which the infected computers were supposed to begin their downloads.

Despite the revelation of the additional server names in the worms instructions, anti-virus experts say there is little reason to get worked up.

Ian Hameroff, eTrust security strategist at Computer Associates International Inc., in Islandia, N.Y., said the discovery of the server names is “nothing special” and does not constitute a “hidden treasure trove.”

Specialists in CAs anti-virus lab said the server names could simply be part of SoBig.Fs e-mail spreading routine.

Time Warner Telecom, based in Littleton, Colo., is a provider of broadband optical networks for enterprises.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.