«Лаборатория Касперского» сообщает об учащении случаев заражения новой версией почтового червя I-Worm.NetSky.q. Данная версия была обнаружена 21 марта, однако лишь теперь уровень её распространенности превысили критическую отметку.
Червь распространяется через интернет в виде вложений в зараженные электронные письма. Также червь обладает функцией размножения через P2P-сети и доступные HTTP и FTP каталоги.
Основной компонент червя представляет собой PE EXE-файл, размером около 29KB. Червь упакован FSG, размер распакованного файла около 40KB.
Характеристики зараженных писем
Зараженные письма формируются из произвольных комбинаций:
Адрес отправителя:
Выбирается произвольно из числа найденных на зараженной машине.
Тема письма:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 |
0i09u5rug08r89589gjrg Administrator approved Congratulations! corrected Do you? Does it matter? Error Fwd: Warning again hello here hi I cannot forget you! I love you! Illegal Website important Important m$6h?3p improved Information Internet Provider Abuse Is that your password? Mail Account Mail Authentication Mail Delivery my News Notice again patched Postcard Private document Protected Mail System Re: A!p$ghsa Re: Administration Re: Approved document Re: Bad Request Re: Delivery Protection Re: Delivery Server Re: Developement Re: Encrypted Mail Re: Error Re: Error in document Re: Extended Mail Re: Extended Mail System Re: Failure Re: Free porn Re: Hello Re: Hi Re: Is that your document? Re: Its me Re: List Re: Mail Authentification Re: Mail Server Re: Message Re: Message Error Re: Notify Re: Old photos Re: Old times Re: Proof of concept Re: Protected Mail Delivery Re: Protected Mail Request Re: Protected Mail System Re: Question Re: Request Re: Sample Re: Secure delivery Re: Secure SMTP Message Re: Sex pictures Re: SMTP Server Re: Status Re: Submit a Virus Sample Re: Test Re: Thank you for delivery Re: Virus Sample Re: Your document read it immediately Shocking document Spam Spamed? Stolen document Thank you! thanks! You cannot do that! your Your day |
или произвольный набор символов.
Текст письма:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 |
9u049u89gh89fsdpokofkdpbm3-4i am shocked about your document! Are you a spammer? (I found your email on a spammer website!?!) Authentication required. Bad Gateway: The message has been attached. Binary message is available. Can you confirm it? Delivered message is attached. Do not visit this illegal websites! Encrypted message is available. Encrypted message is available. ESMTP [Secure Mail System #334]: Secure message is attached. First part of the secure mail is available. Follow the instructions to read the message. For further details see the attachment. For more details see the attachment. For more details see the attachment. Forwarded message is available. Here is it! Here is my icq list. Here is my phone number. Here is the website. ;-) I have attached it to this mail. I have attached the sample. I have attached your document. I have corrected your document. I have received your document. The corrected document is attached. I have visited this website and I found you in the spammer list. Is that true? I hope you accept the result! Important message, do not show this anyone! Let'us be short: you have no experience in writing letters!!! lovely, :-) Message has been sent as a binary attachment. Monthly news report. My favourite page. New message is available. Now a new message is available. Partial message is available. Please answer quickly! Please authenticate the secure message. Please confirm my request. Please confirm the document. Please confirm! Please r564g!he4a56a3haafdogu#mfn3o Please read the attached file! Please read the attached file. Please read the attachment to get the message. Please read the document. Please read the important document. Please see the attached file for details po44u90ugjid-k9z5894z0 Protected Mail System Test. Protected message is attached. Protected message is attached. Protected message is available. Requested file. Secure Mail System Beta Test. See the file. See the ghg5%&6gfz65!4Hf55d!46gfgf Server Error #203 SMTP Error #201 SMTP: Please confirm the attached message. Thank you for your request, your details are attached! Thanks! The sample is attached! Try this, or nothing! Waiting for a Response. Please read the attachment. Waiting for authentification. You got a new message. You have downloaded these illegal cracks? You have received an extended message. Please read the instructions. You have written a very good text, excellent, good work! You were registered to the pay system. Your archive is attached. your big love, ;-) Your bill is attached to this mail. Your details. Your document is attached to this mail. Your document is attached. Your document is attached. Your document is attached. Your document. Your file is attached. Your important document, correction is finished! Your photo, uahhh.... , you are naked! Your requested mail has been attached. Greetings from france, your friend. Have a look at these. I noticed that you have visited illegal websites. See the name in the list! You have visited illegal websites. I have a big list of the websites you surfed. Your mail account is expired. See the details to reactivate it. Your mail account has been closed. For further details see the document. The file is protected with the password ghj001. I have attached your file. Your password is jkl44563. The sample file you sent contains a new virus version of mydoom.j. Please clean your system with the attached signature. Sincerly, Robert Ferrew Best wishes, your friend. Congratulations!, your best friend. I found this document about you. I cannot believe that. Try this game ;-) I hope the patch works. |
Также червь может дописывать в конец зараженного письма ложное сообщение о том, что данное письмо было проверено каким-либо антивирусом:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 |
+++ Attachment: No Virus found +++ MessageLabs AntiVirus - www.messagelabs.com +++ Attachment: No Virus found +++ Bitdefender AntiVirus - www.bitdefender.com +++ Attachment: No Virus found +++ MC-Afee AntiVirus - www.mcafee.com +++ Attachment: No Virus found +++ Kaspersky AntiVirus - www.kaspersky.com +++ Attachment: No Virus found +++ Panda AntiVirus - www.pandasoftware.com ++++ Attachment: No Virus found ++++ Norman AntiVirus - www.norman.com ++++ Attachment: No Virus found ++++ F-Secure AntiVirus - www.f-secure.com ++++ Attachment: No Virus found ++++ Norton AntiVirus - www.symantec.de |
Имя вложения имеет множество различных вариантов. Зачастую это файлы с двойным расширением, где первое «doc» или «txt», а второе выбирается из списка:
1 2 3 4 |
exe pif scr zip |
Также червь способен посылать свои копии в виде ZIP-архивов.
Червь не посылает себя на адреса, в которых имеются подстроки:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 |
@antivi @avp @bitdefender @fbi @f-pro @freeav @f-secur @kaspersky @mcafee @messagel @microsof @norman @norton @pandasof @skynet @sophos @spam @symantec @viruslis abuse@ noreply@ ntivir reports@ spam@ |
Червь может посылать письма, содержащие IFRAME Exploit (аналогично червям Klez.h или Swen). В таком случае, при просмотре письма из уязвимого почтового клиента, произойдет автоматический запуск вложенного файла червя.
Процедуры детектирования и удаления нового червя были добавлены в базу данных «Антивируса Касперского» еще в момент его обнаружения.
Подробное описание I-Worm.NetSky.q будет доступно в «Вирусной энциклопедии» в ближайшее время.
I-Worm.NetSky.q