ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Netsky copycat sparks search for source code

Munir Kotadia ZDNet.co.uk

Published: 12 Mar 2004 12:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts suspect that the author of Netsky, which has been one of the most successful pieces of malware this year, is distributing the worm's source code among the black-hat community.

On Tuesday, the eleventh incarnation of the Netsky worm (Netsky.K) was found to contain a message from its author saying there would be no more variants. However, the note also indicated that the worm's source code would be published, which could allow any number of people to develop their own version of Netsky. Since then, Netsky.L and Netsky.M have been discovered and security researchers say they show signs of being written by a different author.

Mikko Hyppönen, director of antivirus research at F-Secure, told ZDNet UK that although the latest variants seem to have been written by a different person, he has not found any proof that the code is being distributed: "We haven't seen the source code in any of the typical places where we would expect to see it but we have been talking to our informants from the underground."

Graham Cluley, senior technology consultant at Sophos, also admitted that he could not confirm that the source code has been published on the Internet, but suspects it is being sent to small mailing lists: "We have no proof that the source code is out there but our suspicion is it may be available to just a small number of people because the Netsky.L and Netsky.M versions look like they have reused the source code to an extent."

Until Tuesday, all of the Netsky worm variants contained text that insulted the authors of the MyDoom and Bagle worms. But the last two variants of Netsky have not included this "childish banter".

"We don't think they are written by the same guy because a lot of the childish banter isn't there, the anti-Bagle attack isn't there and, most importantly perhaps, the reference to SkyNet, which has been included in all the other variants isn't in there either," said Cluley.

But Hyppönen said there is a possibility that the author is simply wants it to look like he is no longer creating new variants: "It looks like either this guy is releasing new versions and trying to make it look like he is not doing it or -- and this I think is more likely -- he has distributed the code to a small group and the variants are coming from there."

Even if the code is distributed, Sophos's Cluely doesn't think it will result in a deluge of Netsky worms: "This doesn't necessarily mean we will se a glut of new worms that will have the same impact as the original Netsky because there are lots of other virus source codes available on the Internet. But the Netsky.L and Netsky.M variants haven't spread as far as the earlier ones, possibly because the original author of Netsky had a better system for distributing the virus."

However, Hyppönen admits that if the source code was published, it would be "hot stuff" as far as the malware writing community was concerned: "I would have thought the source code from Netsky is hot stuff because the worm has been so successful," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
89 out of 152 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Citrix Engineer/Consultant - Migration project

Main responsilities: Building Citrix Servers on HP hardware Installing applications via Softgrid Publishing applications Initial application ...

World class Systems administrator Hedge fund city based 6 mth contract

Linux, Windows, and Solaris Operating Systems OS shell scripting and automation (Linux, Windows) Windows desktop support/administration (including ...

C++ Developer for cutting Edge design. North Lincoln 30000

You will require extensive experience in C++ and Unix development, SMP multithreading experience, knowledge of distributed algorithms and familiarity ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment