Virus writing group denies involvement with Code Red

ITworld.com |  Security Add a new comment

Virus writing group 29A denied that any of its members created the Code Red or the Code Red II worm. The denial came after a German media report pinpointed 29A as the brains behind the malicious Internet worms.

A Deutsche Presse Agentur (DPA) report said that 29A has been bragging on online chat rooms about unleashing Code Red onto the Net. DPA also described 29A as a Dutch hacker group.

"Some Chinese guy is responsible (for Code Red) not any 29A member," said a Spanish member of 29A using the alias VirusBuster in an e-mail interview. He added that 29A is not a hacker group, but a virus-writing group. Most members are from Spain and the Czech Republic; none are Dutch, he said.

Mikko Hypponen, manager of antivirus research at anti-virus software vendor F-Secure Corp., has investigated the source of both Code Red and Code Red II and said he "is pretty confident 29A is not involved with any version of Code Red" as they lack the traditional 29A signature.

"The string 29A exists in the code of Code Red II. It is a binary reference to the number 666. The string is part of the code that is executed and not something that was set apart as a signature. In viruses created by a 29A member the signature is not part of the code, but separate and is always in a special format," he said.

Experts and authorities worldwide are trying to determine who is responsible for Code Red and Code Red II. There is some speculation that the first version was made in China because the worm placed a message saying "hacked by Chinese" on infected systems. The economic cost of both worms has reportedly risen to nearly US$2 billion.

F-Secure's Hypponen thinks Code Red II was made in the U.S., by virus writers who believe the original Code Red came from China. Hypponen himself doesn't believe the original worm was created in China, although he doesn't have anything concrete to back that.

"This (Code Red II) is an anti-Chinese virus. It checks whether it has infected a Chinese machine and then doubles the spreading rate. We think Code Red II was made in the U.S. as a retaliation," said Hypponen.

Code Red is a self-propagating worm that exploits a flaw in Internet Information Server (IIS), a part of Microsoft Corp.'s Windows 2000 and Windows NT software. It scans the Internet for vulnerable systems and infects these systems by installing itself. The amount of traffic Code Red generates can slow down the flow of information across the Internet.

The more dangerous Code Red II installs a "back door" in servers that allows attackers to access the infected computer without the usual passwords. Once logged in through the back door, attackers can gain control of the machine.

A patch for the flaw in IIS that is exploited by Code Red and Code Red II has been available from Microsoft since mid-June.

F-Secure, in Espoo, Finland, can be reached at +358-9-859-900 or http://www.f-secure.com/.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question