CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Weekly Summaries: Weekly report on viruses and intrusions image
Viruses


For it is far better to know something about everything
than to know all about one thing. This universality is the best.
Blaise Pascal (1623-1662); French scientist and philosopher.

- Weekly report on viruses and intrusions -
Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, April 18, 2004 - Today's report focuses on two variants of Netsky -V
and U-, and a hacking tool called Hideout.A.



Nesky.V spreads via e-mail in a message with variable characteristics that
does not include an attached file. Instead, it contains HTML code with an
ObjectData exploit. When this code is run, the worm is downloaded.

Nesky.V carries out various actions in the computers it infects, including
the following:

- It creates a backdoor that listens in on TCP ports 5556 and 5557.

- From April 22 to 28, 2004 -inclusive- it launches Denial of Service (DoS)
attacks against different websites.

- It looks for e-mail addresses in the files it finds with the following
extensions: ADB, ASP, CFG, CGI, DBX, DHTM, DOC, EML, HTM, HTML, JSP, MBX,
MDX, MHT, MMF, MSG, NCH, ODS, OFT, PHP, PL, PPT, RTF, SHT, SHTM, STM, TBB,
TXT, UIN, VBS, WAB, WSH, XLS and XML. Then it sends itself out to the
addresses it has obtained using its own SMTP engine.

- It creates the mutex _-=oOOSOkOyONOeOtOo=-_ in order to avoid being run
several times simultaneously.

The U variant of Netsky spreads via e-mail in a message with variable
characteristics, which always includes an attached file with a PIF
extension. It creates a backdoor that listens in on TCP port 6789 and like
the variant described above, it sends itself out to the addresses it obtains
from the affected computer using its own SMTP engine. Netsky.U creates a
mutex to avoid being run several times simultaneously and from April 14 to
23, 2004 -inclusive- it tries to launch Denial of Service (DoS) attacks
against different websites.

We are going to finish today's report with Hideout.A, a program that is run
from the command line. This program allows several actions to be carried out
on the services in a remote computer, such as making a list of the services
running, displaying information about them or stopping them.

For further information about these and other computer threats, visit Panda
Software's Virus Encyclopedia at:
http://www.pandasoftware.com/virus_info/encyclopedia/

Additional information

- Exploit: This can be a technique or a program that takes advantage of a
vulnerability or security hole in a certain communication protocol,
operating system, or other IT utility or application.

- Hacking tool: Program that can be used by a hacker to carry out actions
that cause problems for the user of the affected computer (allowing the
hacker to control the affected computer, steal confidential information,
scan communication ports, etc.).

More definitions of virus and antivirus terminology at:
http://www.pandasoftware.com/virus_info/glossary/default.aspx

NOTE: The addresses above may not show up on your screen as single lines.
This would prevent you from using the links to access the web pages. If this
happens, just use the 'cut' and 'paste' options to join the pieces of the
URL.

Posted on Monday, 19 April 2004 @ 10:05:37 UTC by phoenix22 (1265 reads)
[ Trackback ]
image

"Weekly Summaries: Weekly report on viruses and intrusions" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· HotScripts
· W3 Consortium
· HTML Standard
· More about Viruses
· News by phoenix22


Most read story about Viruses:
Xupiter Virus!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer