April 06, 2004

New Netsky worms change their stripes

Latest strains open back doors on infected machines

New versions of the Netsky e-mail worm are spreading on the Internet and may be the work of a different author than previous editions of that worm, according to antivirus software companies.

Netsky.S appeared on Monday and Netsky.T was detected Tuesday. They are the 19th and 20th editions of an e-mail virus that first appeared in February. Unlike earlier variants, the new Netsky strains open "back doors" on machines they infect, prompting at least one antivirus expert to declare the worm the work of a different virus author.

Network Associates Inc.'s McAfee Antivirus Emergency Response Team (AVERT) rated Netsky.S a "medium" threat. The company has received around 300 samples from customers and from virus-infected machines, said Craig Schmugar, virus research manager for McAfee AVERT.

The company has received only a few copies of the Netsky.T virus, he said. Sophos PLC said it received just one copy of the Netsky.T worm, according to an advisory.

Like its predecessors, the new Netsky variants target machines running versions of Microsoft Corp.'s Windows operating system. The viruses arrive as files enclosed in e-mail messages that have faked (or "spoofed") sender addresses and vague subjects such as "Re: My details," "Request" and "Thank You!" according to antivirus company Symantec Corp.

Earlier versions of the Netsky variant abstained from opening communications ports that could be used as so-called "back doors" that remote attackers could use to access the compromised system. They removed copies of the Bagle e-mail worm from infected machines.

Some antivirus experts believe that Netsky's attack on Bagle installations is behind a war of words between the Netsky author or authors and the creators of the Bagle virus family in recent weeks. The two groups have used new worm variants as vehicles for barbs and retorts to previous insults.

In those exchanges, Netsky's author or authors positioned themselves as the "good guys" locked in a battle with online criminals and spammers. One recent variant, Netsky.Q, even contained an impassioned defense of the Netsky worms.

"We don't have any criminal inspirations (sic). Due to many reports, we do not have any backdoors included for spam relaying," read text hidden in Netsky.Q and transcribed by Sophos and other antivirus companies.

However, the latest Netsky variants abandon the high ground, opening a backdoor on TCP (Transmission Control Protocol) port 6789, which could be used to receive instructions or malicious code from the worm author. A message in the new worm tries to make distinctions between opening a back door and installing a remote access Trojan, but does not contain any overt criticisms of the Bagle author, said Schmugar.

"If you look at the 'purpose' behind Netsky, it was trying to uninstall other viruses. Now we're seeing behavior in the new variants like remote access components and DoS (denial of service) attacks," he said.

New variants of Netsky could be linked to a promise by its author, buried in an earlier variant of the worm, that the worm's source code would be released on the Internet.

Antivirus companies have noted differences in the worm's code with variants released since that promise was made in text hidden in the Netsky.K worm, though antivirus companies haven't located a copy of the source code on the Internet yet.

Still, despite new buried messages and slight variations in the worm's use of file attachments and subject lines, even the latest Netsky worm variants are very similar to previous versions of the worm, Schmugar said.

E-mail users should make sure they have antivirus software installed on their computer and consider deploying an Internet firewall if they have not already done so, Schmugar said.

 

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.