Home→Descriptions→Email-Worm.Win32.NetSky.y
| Detected | Apr 20 2004 12:45 GMT |
| Released | Aug 01 2004 15:50 GMT |
| Published | Apr 20 2004 12:45 GMT |
This worm spreads via the Internet as a file attached to infected messages. It is written in Microsoft Visual C++ and packed using PE_Patch+TeLock. The packed file is 26112 bytes in size, and the unpacked file is 28160 bytes in size.
hukanmikloiuo@yahoo.comDomain ".tc":
Re: belge
mutlu etmek okumak belgili tanimlik belge.
belge.pifDomain ".se":
Re: dokumenten
Behaga läsa dokumenten.
dokumenten.pifDomain ".fi":
Re: dokumentoida
Haluta kuulua dokumentoida.
dokumentoida.pifDomain ".pl":
Re: udokumentowac
Podobac sie przeczytac ten udokumentowac.
udokumentowac.pifDomain ".no":
Re: dokumentet
Behage lese dokumentet.
dokumentet.pifDomain ".pt":
Re: original
Leia por favor o original.
original.pifDomain ".it":
Re: documento
Legga prego il documento.
documento.pifDomain ".fr":
Re: document
Veuillez lire le document.
document.pifDomain ".de":
Re: dokument
Bitte lesen Sie das Dokument.
dokument.pifOther Domains:
Re: document
Please read the document.
document.pif
The worm will be activated only if the user launches the infected file by clicking twice on the attachment. The worm will then install itself on the system and start propagating.
When installing, the worm copies itself under the name FirewallSvr.exe to the Windows folder and registers this file in the system registry autorun key:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run\FirewallSvr]
The worm searches for files with the extensions adb, asp, dbx, doc, eml, htm, html, msg, oft, php, pl, rtf, sht, tbb, txt, uin, vbs, É wab, harvest email addresses and then sends copies of itself to these addresses. It creates a file in the Windows directory called fuck_you_bagle.txt, and writes its body to this file. This file is then used to generate infected messages.
The worm opens port 82 and tracks port activity. The backdoor function makes it possible for files to be downloaded onto the victim machine.
The worm is programmed to carry out DoS attacks between the 27th and 30th April on the following servers:
www.educa.ch www.medinfo.ufl.edu www.nibis.de
Email-Worms spread via email. The worm sends a copy of itself as an attachment to an email message or a link to its file on a network resource (e.g. a URL to an infected file on a compromised website or a hacker-owned website).
In the first case, the worm code activates when the infected attachment is opened (launched). In the second case, the code is activated when the link to the infected file is opened. In both case, the result is the same: the worm code is activated.
Email-Worms use a range of methods to send infected emails. The most common are:
Email-Worms use a number of different sources to find email addresses to which infected emails will be sent:
Many Email-Worms use more than one of the sources listed above. There are also other sources of email addresses, such as address books associated with web-based email services.
Email-Worm.