Welcome to the Virus Encyclopedia of Panda Security.
|Alias:||Trojan.Ascetic.A, W32.Sober.H@mm, W32/Sober.h|
It attempts to download and execute a file from an specific web site. It sends political e-mails.
|First detected on:||June 11, 2004|
|Detection updated on:||June 11, 2004|
|Yes, using TruPrevent Technologies
Sober.H is a worm that connects to the web site people.freenet.de and attempts to download and execute a file.
Sober.H searches for e-mail addresses in files with certain extensions, and sends political e-mails to the addresses gathered, using its own SMTP engine.
Sober.H does not spread automatically using its own means. It needs the attacking user's intervention in order to reach the affected computer. The means of transmission used include, among others, floppy disks, CD-ROMs, e-mail messages with attached files, Internet downloads, FTP, IRC channels, peer-to-peer (P2P) file sharing networks, etc.
Sober.H is difficult to recognize, as it does not show any messages or warnings that indicate it has reached the computer.