Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

MyDoom.BE - Escalated to MEDIUM RISK by McAfee

This new variant emerged overnight and has quickly been escalated to MEDIUM RISK by McAfee with an emergency release of virus definition files to detect and clean this new threat.

MyDoom.BE - Escalated to MEDIUM RISK by McAfee
http://vil.nai.com/vil/content/v_131868.htm

This variant W32/Mydoom is similar to previous variants, it bears the following characteristics:

* mass-mailing worm constructing messages using its own SMTP engine
* harvests email addresses from the victim machine
* spoofs the From: address
* contains a peer to peer propagation routine
* downloads the BackDoor-CEB.F trojan

From: (spoofed From: header)

Subject:
delivered
hello
hi
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error

ATTACHMENT: one of the following extensions: EXE, COM, SCR, PIF, BAT, CMD, ZIP


-- Update 21st Feb 2005 -- Due to increased prevalence, the risk assessment of this threat has been raised to MEDIUM. The specified DAT files will be released early to address this threat.

Use the Free AVERT Stinger updated to remove this variant
http://vil.nai.com/vil/stinger