Advertisement
Promo

Security threats Toolkit

NetSky threat increases

Dawn Kawamoto CNET News

Published: 30 Mar 2004 08:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company Symantec raised its severity rating of the latest incarnation of the NetSky worm.

NetSky.Q was upgraded from a level 2 to level 3 threat on the security firm's five-point rating system. The company said it has received 379 reports of the worm since its discovery on Sunday.

"We see quite a few variations of any major threat," said Sharon Rockman, senior director of Symantec Security Response. "But what is unusual about this time is we are having so many level 3 upgrades with NetSky, MyDoom and Bagle... Usually, there is one (worm) that is very popular and one to three variants."

Two previous NetSky variants received an upgrade to level 3 for their wide distribution.

NetSky is a mass-mailing worm that uses a bogus sender address and continually changes its subject line and content. An email attachment usually carries an .exe, .pif, .scr or .zip file extension. The worm distributes itself to email addresses in a victim's hard drive and copies itself into shared folders via file-sharing programs.

Unlike its predecessors, NetSky.Q is scheduled to trigger a beeping alarm at 5:11 a.m. on Tuesday. This will occur only in infected computers that are operating at the time the alarm is set. NetSky.Q is also expected to release a denial-of-service attack between 8 April and 11 April on several Web sites, including those of eDonkey2000, Kazaa, eMule, Cracks.am and Cracks.st, according to Symantec.

The latest NetSky variant marks the second consecutive time the worm has been upgraded to a level 3 threat since the original author announced plans in early March to discontinue releasing variants. That announcement, part of NetSky.K, also noted that the worm's source code would be published, making it available for others to use.

Following the NetSky.K announcement, four other versions of NetSky were released, but those never exceeded a level 2 threat. Antivirus experts speculated that they were written by other authors who may not have had the same widespread distribution system as the original author had.

Security experts say it's difficult to ascertain whether the original author has stepped back into the game or new virus writers have become more proficient in developing a distribution system for their work.

"Once you release the source code, it's hard to tell if it's from a new author or the original writer," Rockman said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
96 out of 214 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

5 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters