UPDATED: New worm threat upgraded

By Patrick Gray
19 May 2003 11:50 AM
Tags: gillespie, patrick, daniel, gray, jamie, mailer, associates, computer
A new mass-mailing worm has begun spreading through Australia, and despite its lack of social smarts, is still managing to spread rapidly.

The Palyh, or Mankx worm, appears to come from support@microsoft.com, a forged address. The message body is invariably: "All information is in the attached file". Users should not open the attachment.

Symantec has upgraded the threat rating of the worm to 3/5 due to the large number of samples the company has received.

The payload is a PIF, or program information file. Upon execution, it self propagates using e-mail addresses from files stored on the targeted system.

According to Jamie Gillespie, security analyst with AusCERT, the virus is a traditional mass-mailer.

"It appears to be using the address book as a single source at least," he said.

Anti-virus vendors have released signatures that can be used to detect this latest threat. The fact the worm wasn't "detectable" this morning could have contributed to its rapid propagation.

"Currently there is no public information regarding this virus," Gillespie told ZDNet Australia  this morning, before the worm was identified and analysed. "Anti virus software is only as good as the signatures [so] 'zero-day' viruses can propagate quite quickly".

An element of reverse psychology could be at work, according to Computer Associates' security consultant Daniel Zatz. Because the e-mail contains little information and doesn't pressure the recipient into opening the attachment could be a reason that people are in fact opening it, he told ZDNet Australia.

"Maybe the curiosity aspect of saying absolutely nothing is perhaps a better lure," he said.

Most large organisations should be protected because they block the .pif file extension, a practice advocated by Zatz, but that small to medium enterprises will probably be impacted.

Advertisement

Talkback 2 comments

    Go ahead... run all the .PIF f ...Craig Bailey -- 19/05/03

    Go ahead... run all the .PIF files you receive in your emails.
    If you don't know what you're doing then you deserve every virus that you get.
    While you're there - run all the .EXE files too, might as well make it a good party!

    Craig's comment must please an ...Anonymous -- 20/05/03

    Craig's comment must please any virus-writers. New users of this Internet/e-mail network outnumber the smarts 10 to one, or Bill Gates' and the industry would fall flat. Why don't Craig think of the un-aware e-mail reader like his own young child starting off. Otherwise all the learners are condemmed to make the same mistakes forever...

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

Tags

Back to top

Featured