Anna virus the work of 'script kiddies'

Antivirus experts have warned that the AnnaKournikova.jpg.vbs virus highlights the ease with which someone with very little technical knowledge can create malicious code capable of spreading around the world in a matter of minutes.

James Middleton

Antivirus experts have warned that the AnnaKournikova.jpg.vbs virus highlights the ease with which someone with very little technical knowledge can create malicious code capable of spreading around the world in a matter of minutes.

The virus, which spread like wildfire late last night, is known as VBS/SST-A and arrives in an email with the subject line "Here you have,;0)" and includes the AnnaKournikova.jpg.vbs attachment.

Advertisement

But instead of displaying a picture of the tennis star, the bug uses the Visual Basic scripting language to infect Outlook and mails itself out to contacts in the infected user's address book.

Eric Chien, chief researcher at Symantec, explained that the virus was actually created with a virus writing kit, known as Vbs Worms Generator 1.50b, which is readily available on the internet.

"The kit was originally created by someone in Argentina and is relatively simple to use. The creator of AnnaKournikova hasn't even added any unique characteristics, it could have been put together by a script kiddie," he said.

But Chien added that the virus was made dangerous through social engineering. "People expected a picture of Anna Kournikova, so they opened the attachment," he said.

Other experts believe that the main problem caused by the virus at the moment is the flooding of mail servers, as the script causes the virus to email itself to everyone in the user's Outlook address book.

Sal Viveros, a spokesman for security firm Network Associates, said: "The mail storm created by this virus is bringing servers down everywhere, making it a high risk case. People have become complacent since the Love Bug virus. We had reports of around 150 enterprises being hit yesterday."

Mikko Hypponen, research manager at F-Secure, added that the virus uses encryption to disguise itself, but that this was a characteristic included in the creation kit.

One user commented in a newsgroup: "Trivial stuff, really. What's the pity, is that it works. This ... simple construction kit virus has got past the script heuristics of most [antivirus software] on the market! Has to be the case. [There's] no other way it could it move so fast through corporate sites. Pathetic."

The code also sets up a registry key named 'Onthefly' allowing a user to detect it easily.

A second payload is also set for release on 26 January when the code will open an infected host's browser and send it to the homepage of Dutch computer shop Dynabyte at www.dynabyte.nl. Chien speculated that the code could have been created by a disgruntled employee or customer of the firm.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Microsoft issues vcard warning for Outlook

A flaw in Microsoft's Outlook Express has left users vulnerable to malicious code embedded into vcards - virtual business cards - which are used to sign many business emails.

Anna virus serves up chaos

Smashing its way into the net at high speed, the "Anna virus" - a worm disguised as a picture of pin-up tennis star Anna Kournikova - wreaked havoc this month.In this special feature, vnunet.com brings you in-depth coverage of the biggest virus outbreak since the Love Bug, as well as expert opinion and advice.

Anna virus writer released

The 20-year-old mystery Dutchman, known only as OnTheFly, arrested for the creation and distribution of the Anna virus, has been released by police after being charged with damaging private property and computer programs, according to reports today.

Anna virus writer arrested

The author of the AnnaKournikova virus has been arrested by the Dutch authorities, only hours after posting an apology for creating the virus on the internet.

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Alcatel-Lucent logo

Summit: Networks swamped by information overload

Alcatel-Lucent's Neal Tilley talks about how enterprises and carriers can...

EU flag

Breach notification laws get green light

Privacy rights strengthened in Europe

Richard Thomas

Summit: Richard Thomas advises on handling the data deluge

Former Information Commissioner speaks out on government databases and data...

oracle sun

War of words escalates between EU and Oracle

Commission comes out fighting after criticism from Oracle and Washington

Primary Navigation