MyDoom "U" - another one for the watchlist
Hopefully this one will stay low-risk for everyone. McAfee uses “U“ and Symantec uses “S“:
MyDoom "U" - another one for the watchlist
http://vil.nai.com/vil/content/v_128346.htm
http://www.symantec.com/avcenter/venc/data/w32.mydoom.s@mm.html
W32.MyDoom.S@mm is a mass-mailing worm that downloads an executable file.
This new variant, packed with UPX, bears the following characteristics:
- contains its own SMTP engine for constructing messages
- harvests target email addresses from the victim machine
- forges the From: header of outgoing messages
- downloads BackDoor-CEB.c over HTTP