Virus Characteristics
-- Update February 3, 2005
--
The assessment of this threat has been downgraded to Low-Profiled due to a decrease in prevalence.
--
This is a mass-mailing worm with the following characteristics:
- contains its own SMTP engine to construct outgoing messages
- harvests email addresses from the victim machine
- the From: address of messages is spoofed
- attachment can be a password-protected zip file, with the password included in the message body.
- contains a remote access component (notification is sent to hacker)
- copies itself to folders that have the phrase shar
in the name (such as common peer-to-peer applications; KaZaa, Bearshare, Limewire, etc)
- uses various mutex names selected from those W32/Netsky variants have used, in order to prevent those W32/Netsky variants running on infected machines
- terminates processes of security programs and other worms
- deletes registry entries of security programs and other worms
Mail Propagation
The details are as follows:
From :
(address is spoofed)
Subject :
Body Text:
- >foto3 and MP3
- >fotogalary and Music
- >fotoinfo
- >Lovely animals
- >Animals
- >Predators
- >The snake
- >Screen and Music
The worm will add the following body text if the attachment is sent as a password-protected ZIP file.
- Password: (random number)
- Pass - (random number)
- Key - (random number)
Attachment:
(with extension .EXE, .SCR, .COM, .CPL or .ZIP)
- MP3
- Music_MP3
- New_MP3_Player
- Cool_MP3
- Doll
- Garry
- Cat
- Dog
- Fish
Password-protected ZIP files may also contain a second, randomly-named file with one of the following extensions:
- .ini
- .cfg
- .txt
- .doc
- .vxd
- .def
- .dll
Installation
The virus copies itself into the Windows System directory as WinXP.exe. For example:
- C:\WINNT\SYSTEM32\WinXP.exe
It also creates other files in this directory to perform its functions:
- %SysDir%
\WinXP.exeopen
- %SysDir%
\WinXP.exeopenopen
- %SysDir%
\WinXP.exeopenopenopen
- %SysDir%
\WinXP.exeopenopenopenopen
The following Registry key is added to hook system startup:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Run "key" = %SysDir%
\WinXP.exe
A mutex is created to ensure only one instance of the worm is running at a time. One of the following mutex names is used in an attempt to stop particular variants of W32/Netsky running on the infected machine:
- 'D'r'o'p'p'e'd'S'k'y'N'e't'
- _-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
- [SkyNet.cz]SystemsMutex
- AdmSkynetJklS003
- ____--->>>>U<<<<--____
- _-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
The worm opens port 1080 (TCP) and port 1040 (UDP) on the victim machine.