ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

NetSky threat increases

Dawn Kawamoto CNET News.com

Published: 30 Mar 2004 08:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company Symantec raised its severity rating of the latest incarnation of the NetSky worm.

NetSky.Q was upgraded from a level 2 to level 3 threat on the security firm's five-point rating system. The company said it has received 379 reports of the worm since its discovery on Sunday.

"We see quite a few variations of any major threat," said Sharon Rockman, senior director of Symantec Security Response. "But what is unusual about this time is we are having so many level 3 upgrades with NetSky, MyDoom and Bagle... Usually, there is one (worm) that is very popular and one to three variants."

Two previous NetSky variants received an upgrade to level 3 for their wide distribution.

NetSky is a mass-mailing worm that uses a bogus sender address and continually changes its subject line and content. An email attachment usually carries an .exe, .pif, .scr or .zip file extension. The worm distributes itself to email addresses in a victim's hard drive and copies itself into shared folders via file-sharing programs.

Unlike its predecessors, NetSky.Q is scheduled to trigger a beeping alarm at 5:11 a.m. on Tuesday. This will occur only in infected computers that are operating at the time the alarm is set. NetSky.Q is also expected to release a denial-of-service attack between 8 April and 11 April on several Web sites, including those of eDonkey2000, Kazaa, eMule, Cracks.am and Cracks.st, according to Symantec.

The latest NetSky variant marks the second consecutive time the worm has been upgraded to a level 3 threat since the original author announced plans in early March to discontinue releasing variants. That announcement, part of NetSky.K, also noted that the worm's source code would be published, making it available for others to use.

Following the NetSky.K announcement, four other versions of NetSky were released, but those never exceeded a level 2 threat. Antivirus experts speculated that they were written by other authors who may not have had the same widespread distribution system as the original author had.

Security experts say it's difficult to ascertain whether the original author has stepped back into the game or new virus writers have become more proficient in developing a distribution system for their work.

"Once you release the source code, it's hard to tell if it's from a new author or the original writer," Rockman said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
96 out of 214 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

IBM Maximo Solution Architect

Be capable of proactively engaging subject matter experts from various organisations (including IBM) as a means to deliver a complete vision of the ...

SAP HCM Business Development Executive (Europe)

We are looking for experienced consultants with a strong background in HCM transformation who are viewed as subject matter experts in this area, with ...

Implementation Consultant - Calypso or Murex experts required !!

Leading Investment banking consultancy is currently looking for a specialist implementation consultant to join their growing specialist department. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment