Nume: Worm/NetSky.B.1 Descoperit pe data de: 18/02/2004 Tip: Vierme ITW: Da Numar infectii raportate: Mediu Potential de raspandire: Mediu spre ridicat Potential de distrugere: Scazut Fisier static: Da Marime: 22.016 Bytes MD5: D4A3677976B656AEC6AFCF2E03459A8D Versiune VDF: 6.24.0.9
General Metode de raspandire: • Email • Peer to Peer Alias: • Symantec: W32.Netsky.B@mm • Mcafee: W32/Netsky.b@MM • Kaspersky: Email-Worm.Win32.NetSky.b • TrendMicro: WORM_NETSKY.B • F-Secure: W32/Netsky.B@mm • Grisoft: I-Worm/Netsky.B • VirusBuster: I-Worm/Netsky.B • Bitdefender: Win32.Netsky.B@mm Sistem de operare: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Creeaza fisiere malware • Utilizeaza propriul motor de email • Modificari in registri Imediat dupa lansarea in executie, pe ecran este afisat: Fisiere Se copiaza in urmatoarea locatie: • %WINDIR%\services.exe Se copiaza intr-o arhiva in urmatoarele locatii: • %WINDIR%\misc.zip • %WINDIR%\party.zip • %WINDIR%\disco.zip • %WINDIR%\part2.zip • %WINDIR%\mail2.zip • %WINDIR%\object.zip • %WINDIR%\ranking.zip • %WINDIR%\dinner.zip • %WINDIR%\release.zip • %WINDIR%\final.zip • %WINDIR%\location.zip • %WINDIR%\jokes.zip • %WINDIR%\friend.zip • %WINDIR%\website.zip • %WINDIR%\mails.zip • %WINDIR%\story.zip • %WINDIR%\found.zip • %WINDIR%\nomoney.zip • %WINDIR%\aboutyou.zip • %WINDIR%\shower.zip • %WINDIR%\topseller.zip • %WINDIR%\product.zip • %WINDIR%\swimmingpool.zip • %WINDIR%\bill.zip • %WINDIR%\note.zip • %WINDIR%\concert.zip • %WINDIR%\textfile.zip • %WINDIR%\posting.zip • %WINDIR%\stuff.zip • %WINDIR%\attachment.zip • %WINDIR%\details.zip • %WINDIR%\creditcard.zip • %WINDIR%\message.zip • %WINDIR%\talk.zip • %WINDIR%\doc.zip • %WINDIR%\msg.zip • %WINDIR%\document.zip • %WINDIR%\unknown.zip • %WINDIR%\fake.zip • %WINDIR%\stolen.zip • %WINDIR%\information.zip • %WINDIR%\warning.zip Registrii sistemului Urmatoarea cheie este adaugata in registri pentru a rula procesul la repornirea sistemului: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "service"="%WINDIR%\services.exe -serv" Valorile urmatoarelor chei sunt sterse din registrii sistemului: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • Taskmon • system • KasperskyAv • Explorer – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] • system – [HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}] • InProcServer32 – [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • Taskmon • Explorer Email Are un motor SMTP integrat. Va fi facuta o conexiune directa cu serverul destinatar. Iata caracteristicile lui: De la: Adresa este falsificata. Catre: – Adrese de email gasite pe sistem. Subiect: Unul din urmatoarele: • unknown • fake • stolen • information • warning • something for you • read it immediately • hello • hi Corpul email-ului: Corpul email-ului este unul din textele: • something is fool • something is going wrong • you are bad • you try to steal • you feel the same • you earn money • thats wrong • why? • take it easy • reply • do you? • that's funny • here, the cheats • here, the introduction • here, the serials • from the chatter • about me • information about you • something is going wrong! • stuff about you? • greetings • see you • here it is • that is bad • yes, really? • i found this document about you • your name is wrong • i hope it is not true! • kill the writer of this document! • something about you! • I have your password! • you are a bad writer • is that from you? • i wait for a reply! • is that your account? • is that your name? • is that true? • here • my hero • read it immediately! • here is the document. • read the details. • i'm waiting • what does it mean? • anything ok? Atasament: Numele fisierelor atasate este alcatuit dupa cum urmeaza: – Incepe cu unul din urmatoarele: • aboutyou • attachment • bill • concert • creditcard • details • dinner • disco • doc • document • final • found • friend • information • jokes • location • mail2 • mails • me • message • misc • msg • nomoney • note • object • part2 • party • posting • product • ps • ranking • release • shower • story • stuff • swimmingpool • talk • textfile • topseller • website Urmat uneori de una din urmatoarele extensii false: • .doc • .htm • .rtf • .txt Extensia fisierului este una din urmatoarele: • .com • .exe • .pif • .scr • .zip Cateva exemple de nume al fisierului atasat: • posting.txt.com • concert.zip • creditcard.pif Atasamentul este o copie malware. Email-ul poate arata ca unul din urmatoarele: Email Cautare adrese: Cauta adrese de email in urmatoarele fisiere: • .msg; .oft; .sht; .dbx; .tbb; .adb; .doc; .wab; .asp; .uin; .rtf; .vbs; .html; .htm; .pl; .php; .txt; .eml Server MX: Daca cererea folosind serverul MX implicit esueaza, continua cu urmatoarele: Se poate conecta la serverul MX: • 217.5.100.1 P2P Pentru a infecta alte sisteme din retele Peer-to-Peer, efectueaza urmatarele operatii: – Cauta directoarele care au in numele lor unul din urmatoarele texte: • "share" • "sharing" Daca reuseste, sunt create urmatoarele fisiere: • doom2.doc.pif; sex sex sex sex.doc.exe; rfc compilation.doc.exe; dictionary.doc.exe; win longhorn.doc.exe; e.book.doc.exe; programming basics.doc.exe; how to hack.doc.exe; max payne 2.crack.exe; e-book.archive.doc.exe; virii.scr; nero.7.exe; eminem - lick my pussy.mp3.pif; cool screensaver.scr; serial.txt.exe; office_crack.exe; hardcore porn.jpg.exe; angels.pif; porno.scr; matrix.scr; photoshop 9 crack.exe; strippoker.exe; dolly_buster.jpg.pif; winxp_crack.exe Alte informatii Mutex: Creeaza urmatorul mutex: • AdmSkynetJklS003 Detaliile fisierului Limbaj de programare: Limbaj de programare folosit: C (compilat cu Microsoft Visual C++). Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit urmatorul program de arhivare: • UPX
Die Beschreibung wurde erstellt von Andrei Gherman am Montag, 29. August 2005 Die Beschreibung wurde geändert von Andrei Gherman am Mittwoch, 31. August 2005
zurück
.
.
.
.