Nume: Worm/Netsky.O.2 Descoperit pe data de: 16/04/2004 Tip: Vierme ITW: Da Numar infectii raportate: Scazut Potential de raspandire: Scazut spre mediu Potential de distrugere: Scazut spre mediu Fisier static: Da Marime: 24.064 Bytes MD5: e6d771c24e8dbaf9543851e893c3e304 Versiune IVDF: 6.25.00.16 - Freitag, 16. April 2004
General Metoda de raspandire: • Email Alias: • Mcafee: W32/Netsky.w • Sophos: W32/Netsky-N • Panda: W32/Netsky.W.worm • Eset: Win32/Netsky.N • Bitdefender: Win32.NetSky.X@mm Sistem de operare: • Windows 2000 • Windows XP • Windows 2003 Efecte secundare: • Creeaza fisiere malware • Utilizeaza propriul motor de email • Modificari in registri Fisiere Se copiaza in urmatoarea locatie: • %WINDIR%\VisualGuard.exe Sunt create fisierele: – %WINDIR%\zip1.tmp – %WINDIR%\zip4.tmp – %WINDIR%\base64.tmp – %WINDIR%\zip3.tmp – %WINDIR%\zip5.tmp Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: Worm/Netsky.W.1 – %WINDIR%\zipped.tmp Analiza ulterioara a relevat ca si acest fisier este malware. Detectat ca: Worm/Netsky.X – %WINDIR%\zip2.tmp – %WINDIR%\zip6.tmp Registrii sistemului Una din urmatoarele valori este adaugata in registri pentru pornirea automata a procesului dupa reboot: – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "NetDy"="%WINDIR%\VisualGuard.exe" Valorile urmatoarelor chei sunt sterse din registrii sistemului: – [HKLM\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ InProcServer32] • "@" • "ThreadingModel" – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "d3dupdate.exe" • "Explorer" • "Taskmon" • "Windows Services Host" • "au.exe" • "sysmon.exe" • "ssate.exe" • "gouday.exe" • "rate.exe" • "srate.exe" • "OLE" – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • "Explorer" • "service" • "system." • "Taskmon" • "Sentry" • "Windows Services Host" • "DELETE ME" • "msgsvr32" Email Are un motor SMTP integrat. Va fi facuta o conexiune directa cu serverul destinatar. Iata caracteristicile lui: Foloseste Messaging Application Programming Interface (MAPI) pentru a trimite email-uri. Iata caracteristicile lui: De la: Adresa este falsificata. De la: Adresa expeditorului este chiar contul Outlook al utilizatorului Catre: – Adrese de email gasite pe sistem. – Adrese de email obtinute din WAB (Windows Address Book) Subiectul mesajului se compune din: Incepe cu unul din urmatoarele: • Re: Urmata uneori de una din urmatoarele: • Re: Continuand cu una din urmatoarele: • read it immediately • important • improved • patched • corrected • approved • thanks! • hello • hi • here • document_all • text • message • data • excel document • word document • bill • screensaver • application • website • product • letter • information • details • file • document • important • approved • my • your Corpul email-ului: – Contine cod HTML. Corpul email-ului este unul din textele: • Your details. Your document. I have received your document. The corrected document is attached. I have attached your document. Your document is attached to this mail. Authentication required. Requested file. See the file. Please read the important document. Please confirm the document. Your file is attached. Please read the document. Your document is attached. Please read the attached file. Please see the attached file for details. In continuare: • %numele atasamentului% : No virus found Powered by the new Norton OnlineScan Get protected: www.symantec.com Atasament: Numele fisierelor atasate este alcatuit dupa cum urmeaza: – Incepe cu unul din urmatoarele: • important • improved • patched • corrected • approved • thanks! • hello • hi • here • document_all • text • message • data • excel document • word document • bill • screensaver • application • website • product • letter • information • details • file • document • important • approved • my • your Urmat de una din urmatoarele extensii false: • .zip • .pif • .exe • .scr Cateva exemple de nume al fisierului atasat: • application.pif • application.scr • data.exe • details.zip • document.exe • document_all.scr • document_all_infoservice.pif • excel document.zip • file.pif • information_hot-line.zip • message.zip • product.pif • screensaver.scr • website_mts.zip Atasamentul este o copie malware. Email Cautare adrese: Cauta adrese de email in urmatoarele fisiere: • .xml; .wsh; .jsp; .msg; .oft; .sht; .dbx; .tbb; .adb; .dhtm; .cgi; .shtm; .uin; .rtf; .vbs; .doc; .wab; .asp; .php; .txt; .eml; .html; .htm; .pl Alte informatii Sir de caractere: In plus, mai contine urmatoarele siruri de caractere: • <*>NetDy: Thanks to the SkyNet alias NetSky crew for the sourcecode. • <*>NetDy: We have rewritten NetSky. • <*>NetDy: Thats a good tactic to detroy the bagle and mydoom worms. • <*>NetDy: Our group will continue the war. • <*>NetDy: Malware writers 'End' comes true. • <*>NetDy: Our Social Engineering is the best *lol* (You have no virus symantec says!). • <*>NetDy: ---------------------------------------------------------------------------- • <*>NetDy: We are greeting all russia people! Detaliile fisierului Compresia fisierului: Pentru a ingreuna detectia si a reduce marimea fisierului, este folosit un program de compresie runtime.
Die Beschreibung wurde erstellt von Petre Galan am Freitag, 5. März 2010 Die Beschreibung wurde geändert von Petre Galan am Montag, 8. März 2010
zurück
.
.
.
.