Sobig.
Sobig was a computer worm that infected millions of Internet-connected, Microsoft Windows computers in August 2003. Although there were indications that tests of the worm were carried out as early as August 2002, Sobig.A was first released to the public in January 2003. Sobig.B was released in May 2003, though first called Palyh. It was renamed after anti-virus experts discovered it was a variant of Sobig. Sobig.C was released May 31; it fixed the timing bug in Sobig.B. Sobig.D came a couple of weeks later followed by Sobig.E. On August 19, Sobig.F became known and set a record in sheer volume of e-mails. The worm was most widespread in its "Sobig.F" variant.
Sobig is not only a computer worm in the sense that it replicates by itself, but also a Trojan horse in that it masquerades as something other than malware. The e-mail contained the text: "See the attached file for details" or "Please see the attached file for details." and contains either a .pif or .scr file. When the file is installed, the virus will replicate by using its own SMTP agent engine. E-mail addresses that will be targeted by the virus are gathered from files on the host computer.
The Sobig.F variant was programmed to contact 20 IP addresses on UDP port 8998 on August 26, 2003 to install some program or update itself. It is unclear what this program was, but earlier versions of the virus had installed the WinGate proxy server software—a legitimate product—in a configuration allowing it to be used as a backdoor for spammers to distribute unsolicited e-mail. The virus was written using Microsoft Visual C++ compiler, and was compressed using a program called tElock.
The Sobig.F worm deactivated itself on September 10, 2003. On November 5 the same year, Microsoft announced that they will pay $250,000 for information leading to the arrest of the creator of the Sobig worm. To date, the perpetrator has not been caught.












