Transmission via e-mail.
Netsky.B follows the routine below:
It reaches the computer in an e-mail message with variable characteristics:
Sender: one of the following:
- skynet@skynet.be
- Netsky.B spoofs the e-mail address from which it is sent. It uses any of the e-mail addresses that it gathers on the affected computer. This may cause confusion. For further information, click here.
Subject: one of the following:
- fake
- hello
- information
- read it immediately
- something for you
- stolen
- unknown
- warning
Message: any of the following lines:
- about me
- anything ok?
- do you?
- from the chatter
- greetings
- here
- here is the document.
- here it is
- here, the cheats
- here, the introduction
- here, the serials
- i found this document about you
- I have your password!
- i hope it is not true!
- i wait for a reply!
- i'm waiting ok
- information about you
- is that from you?
- is that true?
- is that your account?
- is that your name?
- kill the writer of this document!
- my hero
- read it immediately!
- read the details.
- reply
- see you
- something about you!
- something is fool
- something is going wrong
- something is going wrong!
- stuff about you?
- take it easy
- that is bad
- that's funny
- thats wrong
- what does it mean?
- why?
- yes, really?
- you are a bad writer
- you are bad you try to steal
- you earn money
- you feel the same
- your name is wrong
Attachments: it is variable, and usually has a double extension:
Possible file names: ABOUTYOU, ATTACHMENT, BILL, CONCERT, CREDITCARD, DETAILS, DINNER, DISCO, DOC, DOCUMENT, FAKE, FINAL, FOUND, FRIEND, HELLO, HI, INFORMATION, JOKES, LOCATION, MAIL2, MAILS, ME, MESSAGE, MISC, MSG, NOMONEY, NOTE, OBJECT, PART2, PARTY, POSTING, PRODUCT, PS, RANKING, READ IT IMMEDIATELY, RELEASE, SHOWER, SOMETHING FOR YOU, STOLEN, STORY, STUFF, SWIMMINGPOOL, TALK, TEXTFILE, TOPSELLER, UNKNOWN, WARNING or WEBSITE.
First file extension: DOC, HTM, RTF or TXT.
Second file extension: COM, EXE, PIF or SCR. On some ocassions, the attached file only has one of these executable extensions.
This worm can also be sent in a file compressed in a ZIP format.
The following are only some examples: ABOUTYOU.DOC.EXE, DOCUMENT.RTF.COM, WEBSITE.SCR, STUFF.ZIP, etc.
In addition, in order to trick the user into thinking that the attached file is completely harmless, it has the same icon as a Word document.
The computer is affected when the attached file is run.
Netsky.B searches for e-mail addresses in files that have the following extensions ADB, ASP, DBX, DOC, EML, HTM, HTML, MSG, OFT, PHP, PL, RTF, SHT, TBB, TXT, UIN, VBS and WAB.
Netsky.B sends itself out to all the addresses it has gathered, using its own SMTP engine. In order to obtain the SMTP server, it makes a DNS query to the mail domain of the affected user. It uses the IP address 217.5.100.1 to make DNS queries.