F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : NetSky.V

[Summary] | [Disinfection] | [Detailed Description] | [Detection]



NAME:NetSky.V
ALIAS:W32/NetSky.V@mm, I-Worm.Netsky.w
SIZE:19432

Summary

NetSky.V worm was discovered late night on April 14th, 2004.

Netsky.V does not send itself as an attachment but uses HTML emails which exploit vulnerability known as Microsoft Internet Explorer XML Page Object Type Validation Vulnerability (MS03-040) and tries to download and execute itself from an infected host.

The binary code bears high resemblance to the latest NetSky variant, NetSky.U. Sharing up to approximately 86% of the code.

Disinfection

F-Secure provides the special disinfection utility to eliminate Netsky.V worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.zip

Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.txt

System administrators who are using F-Secure Policy Manager, can distribute the tool as a JAR package automatically to all workstations.

System administrators can download the JAR version from:

http://www.europe.f-secure.com/tools/f-netsky.jar

ftp://ftp.europe.f-secure.com/anti-virus/tools/f-netsky.jar

Back to the Top


Detailed Description

The worm's file is a packed PE executable of length 19432 bytes.

Some of the worm's text strings are scrambled.

Installation to system

Upon execution NetSky.V copies itself as EastAV.exe file to Windows folder and adds a startup key for this file into System Registry:

 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "KasperskyAVEng" = "%WinDir%\KasperskyAVEng.exe"

where %WinDir% represents Windows folder name.

Spreading in e-mail

Netsky.V arrives in infected emails but does not use an attachment. It sends HTML emails which exploit vulnerability known as Microsoft Internet Explorer XML Page Object Type Validation Vulnerability (MS03-040) that downloads a HTML page from an infected host. This HTML page then uses another vulnerbility, Internet Explorer Object Data Remote Execution (MS03-032), that attempts to download the binary part of the worm using command line ftp client, and executes it.

Further information about these vulnerabilities, including a fix, is available from Microsoft: http://www.microsoft.com/technet/security/bulletin/ms03-032.mspx http://www.microsoft.com/technet/security/bulletin/ms03-040.mspx

The email harvesting functionality is identical to the variant NetSky.U.

The messages will have any of the following format:

 Subject: Mail Delivery Sytem failure
 Body:    The processing of this message can take a few minutes...

 Subject: Mail delivery failed
 Body:    Converting message. Please wait...

 Subject: Server Status failure
 Body:    Please wait while loading failed message...

 Subject: Gateway Status failure
 Body:    Please wait while converting the message...

Payload

Netsky.V has a payload. It performs a DoS (Denial of Service) attack on the following websites from 22nd to 29th of April 2004:

 www.cracks.am
 www.emule.de
 www.kazaa.com
 www.freemule.net
 www.keygen.us


Back to the Top


Detection

Detection of NetSky.V worm was published on April 15th, 2004 in the following F-Secure Anti-Virus updates:

[FSAV_Database_Version]

Version=2004-04-15_02

Back to the Top


Technical Details: Katrin Tocheva, Ero Carrera, Sami Rautiainen, Alexey Podrezov, April 15th, 2004;

Description Updated: Alexey Podrezov, April 28th, 2004;

F-Secure Corporation