Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

MyDoom "U" - another one for the watchlist

Hopefully this one will stay low-risk for everyone.  McAfee uses “U“ and Symantec uses “S“:

MyDoom "U" - another one for the watchlist

http://vil.nai.com/vil/content/v_128346.htm
http://www.symantec.com/avcenter/venc/data/w32.mydoom.s@mm.html
W32.MyDoom.S@mm is a mass-mailing worm that downloads an executable file.

This new variant, packed with UPX, bears the following characteristics:

  • contains its own SMTP engine for constructing messages
  • harvests target email addresses from the victim machine
  • forges the From: header of outgoing messages
  • downloads BackDoor-CEB.c over HTTP