F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : NetSky.Z

[Summary] | [Disinfection] | [Detailed Description] | [Detection]



NAME:NetSky.Z
ALIAS:W32/NetSky.Z@mm, I-Worm.Netsky.aa, Netsky.Z
SIZE:22016

Summary

NetSky.Z worm was found on April 21st, 2004. This variant is very close to previous Netsky variants. The worm spreads in e-mails, but does not spread to local network and P2P and does not uninstall Bagle worm. The worm has a backdoor that listens on port 665.

Disinfection

F-Secure provides the special disinfection utility to eliminate Netsky.Z worm infection. You can download this utility from our ftp site:

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.exe

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.zip

Disinfection instructions can be found here:

ftp://ftp.f-secure.com/anti-virus/tools/f-netsky.txt

Back to the Top


Detection

Detailed Description

The worm's file is a PE executable 22016 bytes long packed with a new or modified file compressor. Some of the worm's text strings are encrypted.

Installation to system

Upon execution NetSky.Z copies itself as Jammer2nd.exe file to Windows folder and adds a startup key for this file into System Registry:

 [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "Jammer2nd" = "%WinDir%\Jammer2nd.exe"

where %WinDir% represents Windows folder name.

Additionally the worm creates a few files with .LOG extension in Windows folder. These files contain binary and MIME-encoded copies of the worm's executable that will be sent in e-mails.

Spreading in e-mail

Before spreading in e-mail the worm collects e-mail addresses. It scans all files on all drives from C: to Z: except CD-ROM drives. If any file with the following extensions is found, the worm opens it and searches for e-mail addresses there:

 .cfg
 .mbx
 .mdx
 .pl
 .htm
 .html
 .asp
 .wab
 .doc
 .eml
 .txt
 .php
 .vbs
 .rtf
 .uin
 .shtm
 .cgi
 .dhtm
 .ods
 .stm
 .xls
 .adb
 .tbb
 .dbx
 .mht
 .mmf
 .nch
 .sht
 .oft
 .msg
 .jsp
 .wsh
 .xml
 .ppt

The worm spreads itself in e-mails It sends messages with different subject lines, body text and attachment names. Here's the list of subjects that the worm uses:

 Important
 Document
 Hello
 Information
 Hi

The message body is composed from one the following strings:

 Important details!
 Important notice!
 Important document!
 Important bill!
 Important data!
 Important!
 Important textfile!
 Important informations!

The attachment name is selected from the following variants:

 Details.zip
 Notice.zip
 Important.zip
 Bill.zip
 Data.zip
 Part-2.zip
 Textfile.zip
 Informations.zip

The ZIP attachments contain worm's executables with one of the following names:

 Informations.txt  <lots of spaces>  .exe
 Textfile.txt  <lots of spaces>  .exe
 Part-2.txt  <lots of spaces>  .exe
 Data.txt  <lots of spaces>  .exe
 Bill.txt  <lots of spaces>  .exe
 Important.txt  <lots of spaces>  .exe
 Notice.txt  <lots of spaces>  .exe
 Details.txt  <lots of spaces>  .exe

Backdoor

The worm has a backdoor that listens on TCP port 665. It allows to download and execute files on an infected computer.

Payload

NetSky.Z has a payload. It performs a DoS (Denial of Service) attack on the following websites from 2nd to 5th of May, 2004:

 www.educa.ch
 www.medinfo.ufl.edu
 www.nibis.de


Back to the Top


Detection

Detection of NetSky.Z worm was published on April 21st, 2004 in the following F-Secure Anti-Virus updates:

[FSAV_Database_Version]

Version=2004-04-21_05

Back to the Top


Technical Details: Alexey Podrezov, April 21st, 2004;

Description Updated: Alexey Podrezov, April 29th, 2004;

F-Secure Corporation