Discussion in 'malware problems & news' started by Marianna, Apr 16, 2004.

Thread Status:
Not open for further replies.
  1. Marianna

    Marianna Spyware Fighter

    Apr 23, 2002
    B.C. Canada
    Virus Information
    Discovery Date: 04/16/2004
    Origin: Unknown
    Length: 24,064 bytes
    Type: Virus
    SubType: E-mail

    --Update 04/16/2004 14:30 PST
    W32/Netsky.w@MM has been updated to low-profiled due to press at http://www.techweb.com/wire/story/TWB20040416S0007


    This variant of W32/Netsky is similar to W32/Netsky.n@MM . It bears the following characteristics:

    constructs messages using its own SMTP engine
    harvests email addresses from the victim machine
    spoofs the From: address of messages
    This worm is detected with current DATs as W32/Netsky.gen@MM with scanning compressed files enabled. Specific detection will be added to the 4352 DATs.

    Mail Propagation

    Email addresses are harvested from the victim machine. Files with the following extensions are searched:

    Constructed messages bear the following characteristics:

    From: (forged address taken from infected system)
    Subject: (Taken from the following list)

    Part 1 (one of the following)

    Re: Re:
    Part 2 (one of the following)

    Part 3 (one of the following)

Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.