UPDATED: New worm threat upgraded

By Patrick Gray
19 May 2003 11:50 AM
Tags: gillespie, patrick, daniel, gray, jamie, mailer, associates, computer
A new mass-mailing worm has begun spreading through Australia, and despite its lack of social smarts, is still managing to spread rapidly.

The Palyh, or Mankx worm, appears to come from support@microsoft.com, a forged address. The message body is invariably: "All information is in the attached file". Users should not open the attachment.

Symantec has upgraded the threat rating of the worm to 3/5 due to the large number of samples the company has received.

The payload is a PIF, or program information file. Upon execution, it self propagates using e-mail addresses from files stored on the targeted system.

According to Jamie Gillespie, security analyst with AusCERT, the virus is a traditional mass-mailer.

"It appears to be using the address book as a single source at least," he said.

Anti-virus vendors have released signatures that can be used to detect this latest threat. The fact the worm wasn't "detectable" this morning could have contributed to its rapid propagation.

"Currently there is no public information regarding this virus," Gillespie told ZDNet Australia  this morning, before the worm was identified and analysed. "Anti virus software is only as good as the signatures [so] 'zero-day' viruses can propagate quite quickly".

An element of reverse psychology could be at work, according to Computer Associates' security consultant Daniel Zatz. Because the e-mail contains little information and doesn't pressure the recipient into opening the attachment could be a reason that people are in fact opening it, he told ZDNet Australia.

"Maybe the curiosity aspect of saying absolutely nothing is perhaps a better lure," he said.

Most large organisations should be protected because they block the .pif file extension, a practice advocated by Zatz, but that small to medium enterprises will probably be impacted.

Advertisement

Talkback 2 comments

    Go ahead... run all the .PIF f ...Craig Bailey -- 19/05/03

    Go ahead... run all the .PIF files you receive in your emails.
    If you don't know what you're doing then you deserve every virus that you get.
    While you're there - run all the .EXE files too, might as well make it a good party!

    Craig's comment must please an ...Anonymous -- 20/05/03

    Craig's comment must please any virus-writers. New users of this Internet/e-mail network outnumber the smarts 10 to one, or Bill Gates' and the industry would fall flat. Why don't Craig think of the un-aware e-mail reader like his own young child starting off. Otherwise all the learners are condemmed to make the same mistakes forever...

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Chris Duckett Get extensions going in Firefox, redux
    Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
  • Array How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • More blogs »

Tags

Back to top

Featured