Home→Descriptions→Email-Worm.Win32.NetSky.o
| Detected | Aug 04 2004 09:01 GMT |
| Released | Jan 17 2008 21:07 GMT |
| Published | Aug 04 2004 09:01 GMT |
This worm spreads via the Internet as an attachment to infected messages.
The worm itself is a Windows PE EXE file, written in Microsoft Visual C++. It is approximately 16KB in size and packed using UPX. The unpacked file is approximately 140KB in size.
When launched, the worm recursively scans all disks, starting with C: for files with the following extensions:
.pl .htm .html .eml .txt .php .asp .wab .doc .vbs .rtf .uin .shtm .cgi .dhtm .adb .tbb .dbx .sht .oft .msg .jsp .wsh .xml
It sends copies of itself to email addresses harvested from these files.
The worm creates the following files:
<%Windir%>\zip1.tmp <%Windir%>\zip2.tmp <%Windir%>\zip3.tmp <%Windir%>\zip4.tmp <%Windir%>\zip5.tmp <%Windir%>\zip6.tmp, which contains a MIME encoded copy of the worm <%Windir%>\zipped.tmp - a copy of the worm in a ZIP archiveIt deletes the following system registry keys:
[HKLM(HKCU)\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] system. msgsvr32 au.exe service DELETE ME d3dupdate.exe OLE Sentry gouday.exe rate.exe Taskmon Windows Services Host sysmon.exe srate.exe ssate.exe
When launching, the worm copies itself to the Windows directory as Avprotect9x.exe. It then registers the full path to this file in the system registry.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
NetDy = <%windir%>\VisualGuard.exe
Re: Re: Re: your my approved important here hi hello thanks! approved corrected patched improved important read it immediately
document file details information letter product website application screensaver bill word document excel document data message text document_all
Your details. Your document. I have received your document. The corrected document is attached. I have attached your document. Your document is attached to this mail. Authentication required. Requested file. See the file. Please read the important document. Please confirm the document. Your file is attached. Please read the document. Your document is attached. Please read the attached file. Please see the attached file for details.
The worm contains the following text strings:
<*>NetDy: Thanks to the S*k*y*N*e*t alias *N*e*t*S*k*y* crew for the sourcecode. <*>NetDy: We have rewritten *N*e*t*S*k*y. <*>NetDy: Thats a good tactic to detroy the bagle and mydoom worms. <*>NetDy: Our group will continue the war. <*>NetDy: Malware writers ',27h,'End',27h,' comes true. <*>NetDy: Our Social Engineering is the best *lol* (You have no virus symantec says!). <*>NetDy: ---------------------------------------------------------------------------- <*>NetDy: We are greeting all russia people! USA SUCKS!!! AFGHAN SUCKS 2!!! BURN, SADDAM! BURN IN HELL! AND YOU, OSAMA BIN LADEN, BURN IN THE DEVILS FIRE 2!!! SHAME ON YOU MR. BUSH!!!
The worm opens a group of several ports. The port numbers are increased incrementally across the whole group every few seconds. This behaviour makes it possible to detect the worm using Kaspersky Anti-Hacker.
Email-Worms spread via email. The worm sends a copy of itself as an attachment to an email message or a link to its file on a network resource (e.g. a URL to an infected file on a compromised website or a hacker-owned website).
In the first case, the worm code activates when the infected attachment is opened (launched). In the second case, the code is activated when the link to the infected file is opened. In both case, the result is the same: the worm code is activated.
Email-Worms use a range of methods to send infected emails. The most common are:
Email-Worms use a number of different sources to find email addresses to which infected emails will be sent:
Many Email-Worms use more than one of the sources listed above. There are also other sources of email addresses, such as address books associated with web-based email services.
Email-Worm.