Author Topic: Skype "Pykse" worm announced - and publicly bragged about  (Read 3227 times)

0 Members and 1 Guest are viewing this topic.

lexein

  • Guest
Skype "Pykse" worm announced - and publicly bragged about
« on: April 17, 2007, 07:39:40 PM »
After reading this announcement:
  http://www.pcworld.com/article/id,130757-c,worms/article.html (see below)
I did a google seach for Pykse and found it mentioned on the russian forum web-hack.ru :
  http://forum.web-hack.ru/index.php?showtopic=56661&view=getnewpost
 After translating it
http://translate.google.com/translate?hl=en&sl=ru&u=http://forum.web-hack.ru/index.php%3Fshowtopic%3D56661%26view%3Dgetnewpost&sa=X&oi=translate&resnum=1&ct=result&prev=/search%3Fq%3DPykse%2Bvirus%2Bavast%26num%3D50

the message author seems happy that it passes so many antivirus scan tools run by VirusTotal
  http://virustotal.com

I hope this is addressed in an Avast update soon.

Lex

Quote
http://www.pcworld.com/article/id,130757-c,worms/article.html
New Worm Wriggles on Skype
VoIP worm travels by instant messenger to seed malicious software.
Jeremy Kirk, IDG News Service
Monday, April 16, 2007 06:00 AM PDT

A worm targeting Skype Ltd.'s VOIP (voice over Internet protocol) application is harvesting e-mail addresses and directing users to a range of sites hosting other malicious software, security vendors said Monday.

Once a machine is infected, the worm sends a malicious link via instant messages to other users in person's Skype contact list, according to F-Secure's blog.

The link leads to an executable file that downloads a Trojan horse capable of downloading other malicious software, F-Secure said. It then shows a photo of a "lightly dressed" woman.

The link also directs users to at least eight Web sites with information about Africa. It's not clear what type of scam or harm those pages intend, but some of the sites have advertising on them, indicating that it might be a click-fraud scam, said Graham Cluley, senior technology consultant for Sophos PLC. Click fraud refers to the various tricks used to get clicks on advertising banners, which generate revenue for Web page owners.

Skype has been targeted by worms in the past, none of which have inflicted great damage, and this one may be no different. "I would think this thing isn't likely to spread terribly far and wide," Cluley said.

That's partly because malware spread via IM does not generally infect as many people as malware spread through more conventional routes, such as e-mail, Cluley said. Also, users can reply to a suspicious IM and ask the sender about the link, and the lack of a response can tip off the user that something is awry.

Some sophisticated IM malware can generate an automated response to trick the user into clicking on the link, but this one does not appear to have that capability, Cluley said. However, it does set Skype to "do not disturb" status, which blocks incoming calls and other notifications, and also prevents a user from responding to an IM, Cluley said.

F-Secure calls the worm "IM-Worm:W32/Pykse.A," and Sophos named it "Mal/Pykse-A."



Quote
http://forum.web-hack.ru/index.php?showtopic=56661&view=getnewpost
 After translating it
http://translate.google.com/translate?hl=en&sl=ru&u=http://forum.web-hack.ru/index.php%3Fshowtopic%3D56661%26view%3Dgetnewpost&sa=X&oi=translate&resnum=1&ct=result&prev=/search%3Fq%3DPykse%2Bvirus%2Bavast%26num%3D50


1) Vkluchaem JS support in your browser, go to the link
2) предлагают скачать файл sandra.scr2) offer download the file sandra.scr
3) качаем и не открываем3) downloading and opening
4) топаем на www.virustotal.com4) pauses at www.virustotal.com
5) скармливаем...5) scarmlebaem ...
6) получаем красивый список.6), we get a beautiful list. wink.gif

Antivirus Version Update ResultAntivirus Version Update Result
AhnLab-V3 2007.4.14.0 04.13.2007 no virus foundAhnLab-V3 2007.4.14.0 04.13.2007 no virus found
AntiVir 7.3.1.52 04.15.2007 no virus foundAntiVir 7.3.1.52 04.15.2007 no virus found
Authentium 4.93.8 04.14.2007 no virus foundAuthentium 4.93.8 04.14.2007 no virus found
Avast 4.7.981.0 04.15.2007 no virus foundAvast 4.7.981.0 04.15.2007 no virus found
AVG 7.5.0.447 04.15.2007 no virus foundAVG 7.5.0.447 04.15.2007 no virus found
BitDefender 7.2 04.15.2007 no virus foundBitDefender 7.2 04.15.2007 no virus found
CAT-QuickHeal 9.00 04.14.2007 (Suspicious) - DNAScanCAT-QuickHeal 9.00 04.14.2007 (Guralnick) - DNAScan
ClamAV devel-20070312 04.15.2007 Trojan.Downloader-5467ClamAV devel-20070312 04.15.2007 Trojan.Downloader-5467
DrWeb 4.33 04.15.2007 no virus foundDrWeb 4.33 04.15.2007 no virus found
eSafe 7.0.15.0 04.15.2007 no virus foundeSafe 7.0.15.0 04.15.2007 no virus found
eTrust-Vet 30.7.3567 04.14.2007 no virus foundeTrust-Vet July 30, 3567 04.14.2007 no virus found
Ewido 4.0 04.15.2007 no virus foundEwido 4.0 04.15.2007 no virus found
FileAdvisor 1 04.15.2007 no virus foundFileAdvisor one 04.15.2007 no virus found
Fortinet 2.85.0.0 04.15.2007 no virus foundFortinet 2.85.0.0 04.15.2007 no virus found
F-Prot 4.3.2.48 04.13.2007 no virus foundF-Prot 4.3.2.48 04.13.2007 no virus found
F-Secure 6.70.13030.0 04.15.2007 no virus foundSecure 6.70.13030.0 04.15.2007 no virus found
Ikarus T3.1.1.5 04.15.2007 no virus foundIkarus T3.1.1.5 04.15.2007 no virus found
Kaspersky 4.0.2.24 04.15.2007 IM-Worm.Win32.Pykse.aKaspersky 4.0.2.24 04.15.2007 IM-Worm.Win32.Pykse.a
McAfee 5009 04.13.2007 no virus foundMcAfee 5009 04.13.2007 no virus found
Microsoft 1.2405 04.15.2007 no virus foundMicrosoft 1.2405 04.15.2007 no virus found
NOD32v2 2187 04.13.2007 no virus foundNOD32v2 2187 04.13.2007 no virus found
Norman 5.80.02 04.14.2007 no virus foundNorman 5.80.02 04.14.2007 no virus found
Panda 9.0.0.4 04.15.2007 Suspicious filePanda 9.0.0.4 04.15.2007 Guralnick file
Prevx1 V2 04.15.2007 no virus foundPrevx1 V2 04.15.2007 no virus found
Sophos 4.16.0 04.12.2007 no virus foundSophos 4.16.0 December 4, 2007 no virus found
Sunbelt 2.2.907.0 04.14.2007 no virus foundSunbelt 2.2.907.0 04.14.2007 no virus found
Symantec 10 04.15.2007 no virus foundSymantec 1910 04.15.2007 no virus found
TheHacker 6.1.6.095 04.15.2007 no virus foundTheHacker 6.1.6.095 04.15.2007 no virus found
VBA32 3.11.3 04.14.2007 no virus foundVBA32 3.11.3 04.14.2007 no virus found
VirusBuster 4.3.7:9 04.15.2007 no virus foundVirusBuster 4.3.7:9 04.15.2007 no virus found
Webwasher-Gateway 6.0.1 04.15.2007 Win32.Malware.gen!94 (suspicious)Webwasher-Gateway 6.0.1 04.15.2007 Win32.Malware.gen! 94 (suspicious)

- - - - - - - -

Так же МэилАгент (mail.ru) проверил и получил красивый список:Just Mailagent (mail.ru) investigated and received a beautiful list :

AhnLab-V3 2007.4.14.0 04.13.2007 no virus foundAhnLab-V3 2007.4.14.0 04.13.2007 no virus found
AntiVir 7.3.1.50 04.13.2007 no virus foundAntiVir 7.3.1.50 04.13.2007 no virus found
Authentium 4.93.8 04.13.2007 no virus foundAuthentium 4.93.8 04.13.2007 no virus found
Avast 4.7.936.0 04.13.2007 no virus foundAvast 4.7.936.0 04.13.2007 no virus found
AVG 7.5.0.447 04.12.2007 no virus foundAVG 7.5.0.447 December 4, 2007 no virus found
BitDefender 7.2 04.13.2007 no virus foundBitDefender 7.2 04.13.2007 no virus found
CAT-QuickHeal 9.00 04.13.2007 no virus foundCAT-QuickHeal 9.00 04.13.2007 no virus found
ClamAV devel-20070312 04.13.2007 no virus foundClamAV devel-20070312 04.13.2007 no virus found
DrWeb 4.33 04.13.2007 no virus foundDrWeb 4.33 04.13.2007 no virus found
eSafe 7.0.15.0 04.12.2007 suspicious Trojan/WormeSafe December 4, 2007 7.0.15.0 suspicious Trojan / Worm
eTrust-Vet 30.7.3565 04.13.2007 no virus foundeTrust-Vet July 30, 3565 04.13.2007 no virus found
Ewido 4.0 04.13.2007 no virus foundEwido 4.0 04.13.2007 no virus found
FileAdvisor 1 04.13.2007 no virus foundFileAdvisor one 04.13.2007 no virus found
Fortinet 2.85.0.0 04.13.2007 suspiciousFortinet 2.85.0.0 04.13.2007 suspicious
F-Prot 4.3.2.48 04.13.2007 no virus foundF-Prot 4.3.2.48 04.13.2007 no virus found
F-Secure 6.70.13030.0 04.13.2007 no virus foundSecure 6.70.13030.0 04.13.2007 no virus found
Ikarus T3.1.1.5 04.13.2007 no virus foundIkarus T3.1.1.5 04.13.2007 no virus found
Kaspersky 4.0.2.24 04.13.2007 no virus foundKaspersky 4.0.2.24 04.13.2007 no virus found
McAfee 5009 04.13.2007 no virus foundMcAfee 5009 04.13.2007 no virus found
Microsoft 1.2405 04.13.2007 no virus foundMicrosoft 1.2405 04.13.2007 no virus found
NOD32v2 2187 04.13.2007 no virus foundNOD32v2 2187 04.13.2007 no virus found
Norman 5.80.02 04.12.2007 no virus foundNorman 5.80.02 December 4, 2007 no virus found
Panda 9.0.0.4 04.13.2007 Suspicious filePanda 9.0.0.4 04.13.2007 Guralnick file
Prevx1 V2 04.13.2007 no virus foundPrevx1 V2 04.13.2007 no virus found
Sophos 4.16.0 04.12.2007 no virus foundSophos 4.16.0 December 4, 2007 no virus found
Sunbelt 2.2.907.0 04.07.2007 no virus foundSunbelt 2.2.907.0 July 4, 2007 no virus found
Symantec 10 04.13.2007 no virus foundSymantec 1910 04.13.2007 no virus found
TheHacker 6.1.6.088 04.09.2007 no virus foundTheHacker 6.1.6.088 September 4, 2007 no virus found
VBA32 3.11.3 04.13.2007 no virus foundVBA32 3.11.3 04.13.2007 no virus found
VirusBuster 4.3.7:9 04.13.2007 no virus foundVirusBuster 4.3.7:9 04.13.2007 no virus found
Webwasher-Gateway 6.0.1 04.13.2007 no virus foundWebwasher-Gateway 6.0.1 04.13.2007 no virus found

Это сообщение отредактировал Dumus - Apr 16 2007, 00:48:44This message was edited Dumus, Apr 16 2007, 00:48:44


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33920
  • malware fighter
Re: Skype "Pykse" worm announced - and publicly bragged about
« Reply #1 on: April 17, 2007, 10:09:25 PM »
Hi lexein,

So mind the links you click on: http://sophos.com/pressoffice/news/articles/2007/04/pykse.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!