German Spam: What virus is this? [May. 15th, 2005|10:10 am]
Brad Fitzpatrick

Between SpamAssassin and ClamAV, I haven't been getting much spam or viruses. A couple per day.

But this morning I check my mail to find over 100 German spam messages, most just saying "Lese selbst:" and some URL that's supposed to look like a news article about "Massenhafter Steuerbetrug durch auslaendische Arbeitnehmer" or something, but I'm sure is just porn or a worm.

Oh, and like 2 in English, just saying "Full Article:" and a URL in the same way. What virus is this?

[User Picture]From: calliste
2005-05-15 05:47 pm (UTC)
(Reply) (Parent) (Thread)
From: subsven
2005-05-15 09:20 pm (UTC)
Sober.P updated itself to Sober.Q (by fetching a "plugin" from a website) and instead of distributing itself (that's why virus scanners don't catch the emails) it now sends neo-nazi and right-wing spam messages around the world.

http://www.heise.de/newsticker/meldung/59562 (German)

So may be the initial Sober.P flooding two weeks ago (it promised tickets for the soccer world cup 2006, so it was immensly "popular" in Germany) was only intended to infect as many PCs as possible for this spam attack...
(Reply) (Parent) (Thread)
[User Picture]From: xotiffany
2005-05-15 05:47 pm (UTC)

Deutsche Buerger trauen sich nicht ...

It started yesterday for me. I got about 2 dozen German Spam messages and today I had 80.

My favorite is probably "The Whole Lived Like a German".
(Reply) (Thread)
[User Picture]From: scsi
2005-05-15 05:50 pm (UTC)
Im getting bombed by them.. Even with heavy spamassassin/clamav/RBL/SURBL's..

Add this in your /etc/mail/spamassassin and restart:


Ruleset to stop the Sober crap thats been going around like crazy currently.
(Reply) (Thread)
[User Picture]From: j7xz49br3m93xrr
2005-05-15 07:03 pm (UTC)
I've been getting quite a few of these. I don't think they're viruses or typical spam. They're all racist diatribes about Turks in Germany. It seems to be some sort of scare-mongerinig right-wing racist stuff. I loaded some of the pages and they're just long essays (in German) about German Turks.
(Reply) (Thread)
[User Picture]From: pne
2005-05-15 07:42 pm (UTC)
I think it's both.

As in, the news article is indeed a (link to) a news article (about stuff such as "foreigners = criminals" or similarly politically-correct topics, often on a right-wing party's web page or similar), but the emails are sent by a worm.
(Reply) (Thread)
[User Picture]From: jwz
2005-05-15 09:25 pm (UTC)
The weird thing is, the messages don't seem to have any viral payload at all (by the time they reach me, at least). Why is the worm bothering to send this mail if it's not trying to propagate or enlarge my pen1s?
(Reply) (Parent) (Thread)
[User Picture]From: brad
2005-05-15 09:37 pm (UTC)
See subsven's post above. It's all just to send neo-nazi propoganda?
(Reply) (Parent) (Thread)
From: edge_walker
2005-05-24 01:47 pm (UTC)
Yeah. Not the first time it happens either. There was a similar wave of virally propagated xenophobic spam about a year or so ago. Considering the cases where the virus authors were caught, this does not actually even have to mean any sort of organized effort; it could be just one or two nutjobs responsible.
(Reply) (Parent) (Thread)
[User Picture]From: quelrod
2005-05-15 08:12 pm (UTC)
No kidding my yahoo mail account normally gets about 5 spams a day. When I woke up this morning I had 25 sitting in my bulk mail folder.
(Reply) (Thread)
[User Picture]From: xpaperxcutx
2005-05-15 08:28 pm (UTC)
I've been bombarded with those as well
(Reply) (Thread)
[User Picture]From: quirrc
2005-05-16 04:48 am (UTC)
You'd better think not only about filters for yourself but also add (optional) spam filtering for all forwarding addresses @livejournal.com
(Reply) (Thread)
[User Picture]From: brentdax
2005-05-16 06:59 am (UTC)
I keep getting these addressed from prominent Perl people--think Larry Wall, Randal Schwartz, Brian Ingerson, and so on--to my @cpan.org address. It's really annoying, because I don't want to blacklist those addresses.
(Reply) (Thread)
From: (Anonymous)
2005-05-16 02:29 pm (UTC)

Even me...

Even I am getting same messages. It seems to bypass spamassasin. Good I read your journal daily, I will try the spamassin patch given in one of the comments above.

-Ritesh, Webyog
(Reply) (Thread)