Latest Sober attack appears to do little damage

06.01.2006

In the last 24 hours alone, Postini has blocked over 53 million e-mails containing the latest Sober variant on behalf of its clients, Lochart said. That number is about 10 times higher than the next most prolific worm and represents close to 98 percent of all e-mails blocked by Postini, he said.

'It really is an astonishingly virulent worm' that has easily surpassed all other worms in history in terms of its propagation, he said. 'We've never seen a single worm or virus that has just kept going on and on like this one has."

The director of information security at a speciality retailer in California who wished to remain anonymous said that his company stopped a higher than normal volume of Sober-related e-mails at its network gateways last week. Starting around Dec 27, when the news of the Windows Metafile (WMF) flaw was disclosed, the company began seeing a sharp spike in the volume of e-mails -- from an average of about 1,500 to 2,000 per day to more than 50,000 e-mails that were filtered out by its perimeter defenses, he said.

'The biggest question is whether this represents the high water mark or if it will go higher,' he said.