|
Novargis succeeds Sobig.
The worm will arrive as an attachment with a file extension of .bat, .cmd, .exe, .pif, .scr, or .zip. It mostly hides itself as a ZIP file, which most gateway protection softwares allow to enter. Once inside the INBOX of a user's mail database, the user will casually click on the ZIP file and inside the ZIP file, is hidden the malicious code of the worm.
W32.Novargis a mass-mailing worm that started its adventure sometime around
23.00 hrs (IST) on 26th of Jan 2004.
The worm will arrive as an attachment with a file extension of .bat, .cmd, .exe, .pif, .scr, or .zip. It mostly hides itself as a ZIP file, which most gateway protection softwares allow to enter. Once inside the INBOX of a user's mail database, the user will casually click on the ZIP file and inside the ZIP file, is hidden the malicious code of the worm.
If the user clicks on this code, the worm gets immediately activated and will sit silently on the user's computer, and setup a "backdoor" by opening few "ports". Ports are basically entry points which can be used by an external hacker to control the computer.
Technically, when the machine gets infected, the worm will set up a backdoor into the system by opening TCP ports 3127 thru 3198. This will potentially allow a hacker to connect to the machine and utilize it as a proxy to gain access to it's network resources. In addition, the backdoor has the ability to download and execute arbitrary files.
The worm will perform a (Denial of Service) DoS starting on February 1, 2004. On February 12, 2004 the worm has a trigger date to stop spreading.
Novargis is yet another worm, in the recent series that we have seen, that opens up unauthorised access to computers that could be used for sending out SPAMS across the Internet, said Mr. Govind Rammurthy, CEO of MicroWorld Technologies Inc.
For more information on this worm, please visit http://www.mwti.net If you suspect that your computers have been compromised, download MicroWorld's free eScan AntiVirus Toolkit Utility and run a thorough check.
About MicroWorld Technologies Inc.
MicroWorld is the publisher of eScan and MailScan, world's first real time content security and antivirus softwares for desktops and MailServers.
|