On CNET: Get the Windows 7 upgrade for free
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: May 12, 2004 3:47:00 PM

A new variant of the Sasser worm has appeared, even though the worm's author was arrested in Germany last week.

Antivirus companies suspect that a copycat coder has written the new virus.

Systems infected with the Sasser worm randomly scan local networks and the Internet to look for Windows PCs that have not been updated with the latest Microsoft patch. The worm functions in a very similar way to the MSBlast worm, which caused millions of dollars in damage and disruption last summer.

A teenager suspected of writing the Sasser code has been arrested by police in Germany. Since his arrest, two variants of the worm have been detected in the wild. The suspected author had confessed to German police that he had released the fifth version of the worm, Sasser.E, four days before he was taken into custody. Antivirus firms didn't detect the variant until the day after the arrest. The most recent, Sasser.F, was first detected Tuesday.

Luis Corrons, head of antivirus company Panda's research labs, said the Sasser.F worm's source code looks like it was written by an inexperienced programmer who has slightly modified the original code but had not added any new functions or behaviors.

"Studying the evolution of Sasser, the fact that variant F does not include any new features confirms that it is the work of a different person," Corrons said.

The code and some messages hidden inside the original Sasser worm indicate its authors are closely linked with the Netsky virus, which has led many experts to question if the German teenager could be solely responsible for the Sasser outbreak.

David Kopp, head of Trend Micro's European research labs, said he doubts that the teenager in police custody could have been solely responsible for the Sasser worm because there have been around 30 variants of Netsky since mid-February.

"For just one guy, this is a lot of work. We are not sure that the German teenager is the real virus writer--it's more likely to be a group of virus writers," he said.

Kevin Hogan, senior manager at Symantec Security Response, said that even if there are new variants of Sasser or other malware that exploits the Windows vulnerability, such as the Cycle worm, are unlikely to cause any damage because most businesses have either applied the relevant Windows patch or are using an up-to-date antivirus application.

"The Sassers out there are not really spreading any more and the Cycle worm uses the same vulnerability as Sasser, so it has gone nowhere. People are probably patching to protect themselves against Sasser--that's why we are seeing very little of Cycle," Hogan said.

Munir Kotadia of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 31 Talkback(s)
the messanger ???
The message about this was already out before they wrote this worm.

What message were they spreading? That they can copy someone else's work and destroy people's data with it? Some message, makes them look good.

I think they need to be shot.... (Read the rest)
Posted by: prshaw Posted on: 05/13/04 You are currently: a Guest | | Terms of Use
Attorneys line up to represent Sasser author.  No_Ax_to_Grind | 05/12/04
"Attorneys line up to represent Sasser author."  BitTwiddler | 05/12/04
Good one.  Patrick Jones | 05/12/04
I'm glad one person got it.  No_Ax_to_Grind | 05/12/04
Yes, I'm sure Microsoft holds the patents on all worms  Xunil_Sierutuf | 05/12/04
pretty funny, but in reality...  ryusen | 05/12/04
8.5  Plain Logic | 05/12/04
Virus Authors Steal, Just like Micro$oft  LinuxLover74 | 05/12/04
You Linux guys are....  BitTwiddler | 05/12/04
They seem to be  michael-t | 05/12/04
That post wasn't made by a "Linux guy"  Linux_Developer | 05/12/04
actually...  ryusen | 05/12/04
You may be right...  Linux_Developer | 05/13/04
Get over yourself.  No_Ax_to_Grind | 05/12/04
Hm...looks like you're not as good an actor as some  Linux_Developer | 05/12/04
Mission accomplished.  LinuxLover74 | 05/13/04
Doorknobs like this hurt Linux...  Oggie_z | 05/12/04
Windows still wormy, locked in users still paying Microsoft  jellyclock | 05/12/04
How is an anti-virus going to help you?  amp_z | 05/12/04
Huh?  PA-ITGuy | 05/12/04
Real Sasser author is at-large  OhMyGosh | 05/12/04
Theory...  PA-ITGuy | 05/12/04
Oho! Now for another episode of "Who said it"  Linux_Developer | 05/12/04
Sasser Didn't Kill My Servers Microsoft DID...  john@... | 05/12/04
It so easy  michael-t | 05/12/04
Re: It so easy  issthatso | 05/12/04
WHO CARES  Protector | 05/12/04
Only the people who get attacked  Linux_Developer | 05/12/04
Arresting these guys is like shooting the messanger ...  Plain Logic | 05/12/04
within th enormal usage of that phrase..  ryusen | 05/12/04
the messanger ???  prshaw | 05/13/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here