F-secure list of sober virus urls
When the news was first out that an antivirus firm (f-secure) had cracked the psuedo-random algorithm that the sober worm uses to determine where to download “updates” from, they said that they had previously notified German authorities where the free hosting sites were located so that they could deal with the sites. I did find that they have announced a list of the addresses for the January 5th update (and the January 6th as well.)
Great to see this information released. They’ve left out the filename, but I’ll reproduce the list here…
http://people.freenet.de/gixcihnm/
http://people.freenet.de/tobtrfjabzw/
http://people.freenet.de/utzmfucaau/
http://people.freenet.de/phyibrpkcpl/
http://people.freenet.de/lhxrdryo/
http://people.freenet.de/yediykdq/
http://people.freenet.de/bjjhdkybpyaj/
http://scifi.pages.at/agzytvfbybn/
http://home.pages.at/bdalczxpctcb/
http://free.pages.at/ftvuefbumebug/
http://home.arcor.de/ijdsqkkxuwp/
http://home.arcor.de/ldhdytdu/
http://home.arcor.de/wdqodvdhwwese/
http://home.arcor.de/frweemrecuvw/
http://home.arcor.de/nulmjznomnt/
The above addresses are due to be used for the January 5th download, the following list will be those used on January 6th…
http://people.freenet.de/mookflolfctm/
http://people.freenet.de/aohobygi/
http://people.freenet.de/wlpgskmv/
http://people.freenet.de/svclxatmlhavj/
http://people.freenet.de/jpjpoptwql/
http://people.freenet.de/iohgdhkzfhdzo/
http://people.freenet.de/eetbuviaebe/
http://scifi.pages.at/vvvjkhmbgnbbw/
http://home.pages.at/twfofrfzlugq/
http://free.pages.at/sfhfksjzsfu/
http://home.arcor.de/qlqqlbojvii/
http://home.arcor.de/fulmxct/
http://home.arcor.de/fowclxccdxn/
http://home.arcor.de/lnzzlnbk/
http://home.arcor.de/rprpgbnrppb/
After that the list is expected to change every 14 days. The virus syncs the systems time so that it does know the correct date and time. (NTP? via the atomic clocks?)
So, if your a system administrator and can block urls on your network – this might be a good batch to add to your list.