Mydoom.bb spreading in the wild
Mydoom.bb spreading in the wild
R E L A T E D   C O N T E N T
ADVERTISEMENT

Latest Mydoom mutant on the loose

Security experts raise risk assessment on Mydoom.bb

Robert Jaques, vnunet.com 17 Feb 2005
ADVERTISEMENT

Security experts have raised the risk assessment to medium on the recently discovered Mydoom.bb@MM worm, also known as Mydoom.bb, after receiving reports that the infection is spreading in the wild.

According to McAfee's Avert antivirus team, more than 50 reports of the virus being stopped or infecting users from the field have been recorded. Most of these reports have arrived from the US, though Avert has also received reports from Australia and the UK.

Mydoom.bb is similar to previous variants with a mass-mailing worm constructing messages using its own SMTP engine. It contains a peer-to-peer propagation routine and may be a .exe file. In common with other mutants it also downloads the BackDoor-CEB.f Trojan and spoofs the 'from' address.

Users are advised to be "very wary" and should most likely delete any email containing the following headers:

Delivered
Hello
Hi
Error
Status
Test
Report
Delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error

The virus constructs messages from pools of strings it carries in its body. After being executed, Mydoom.bb copies itself into the Windows System directory, and the worm installs itself as JAVA.EXE in the directory.

It will show Windows Explorer listening on TCP Port 1034, the port on which the web server runs. More information can be found here.

See also:

Trojan-based attacks on the wane as mass-mailers increaseThe advice remains the same: do not click on attachments  02 Mar 2005
Virus displays nationalist sloganMalicious code infects executable files  16 Feb 2005
Vulnerability affects processing of PNG filesUsers urged to be careful when viewing PNG images  11 Feb 2005
Mobile devices the 'new frontier' for virusesVirus writers target handhelds, mobiles ... and your car  10 Feb 2005
David EmmVirus writers are waking up and smelling the money  04 Feb 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities