2/22: MyDoom-BF Worm Sends Mass Emails |
 |
|
|
|
2/22: MyDoom-BF Worm Sends Mass Emails February 22, 2005
W32/MyDoom.bf@MM is another variant of the W32/Mydoom worm and is similar to previous variants. MyDoom.bf bears the following characteristics:
mass-mailing worm constructing messages using its own SMTP engine
harvests email addresses from the victim machine
spoofs the From: address
downloads the BackDoor-CEB.f trojan
From: (spoofed From: header) Do not assume that the sender address is an indication that the sender is infected. Additionally you may receive alert messages from a mail server that you are infected, which may not be the case.
The From: address may be spoofed with a harvested email address. Additionally, it may be constructed so as to appear as a bounce, using the following addresses:
mailer-daemon@(target_domain)
noreply@(target_domain)
postmaster@(target_domain)
The following display names are used in this case:
"Postmaster"
"Mail Administrator"
"Automatic Email Delivery Software"
"Post Office"
"The Post Office"
"Bounced mail"
"Returned mail"
"MAILER-DAEMON"
"Mail Delivery Subsystem"
Subject: The following subjects are used:
hello
hi
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error
Body: The virus constructs messages from pools of strings it carries in its body.
Attachment: The attachment may be an EXE file with one of the following extensions:
EXE
COM
SCR
PIF
BAT
CMD
It may also be a copy of the worm within a ZIP file (may be doubly ZIPped). In this case the extension is:
ZIP
The attachment may use the target email address name as the filename, in addition to the following:
README
INSTRUCTION
TRANSCRIPT
MAIL
LETTER
FILE
TEXT
ATTACHMENT
DOCUMENT
MESSAGE
The attachment may use a double extension, and there may be multiple spaces inserted between the file extensions to deceive users.
View an example email message and other information at McAfee page.
|
|
|
|
Author of Zafi-B Worm Trailed to Hungary
3/8: Tibick-C a P2P Worm
4/8: Mytob-S Worm Continues to Flourish
4/8: Cabir-J Worm Affects Symbian Phones
Open Source CVS Flaw Sparks Use Audits
Cisco's Bundle of Virus-Fighters
5/11: Rbot-ACH Worm Spreads Via Shares
HP Cuts to the Middle of Disaster Recovery
'Critical' Security Hole in Real's Helix Server
Time to Remind Users of Security Responsibilities
3/7: Forbot-EP Worm Targets Remote Shares
Compare Security Camera Products
 |