NAI Reports New Mydoom Variant
Similar to Monday's Mydoom; Low Risk
McAfee is reporting a new variant of the Mydoom worm that appeared on Monday, referred to here as Mydoom.M and at McAfee as Mydoom.O. From the description:
This new variant of W32/Mydoom is packed with ASPack.
The dropped SERVICES.EXE is the same binary W32/Mydoom.o@MM uses. Detection for the this file is included in since 4381 DATs (07/26/2004)
The behaviour is simmilar to W32/Mydoom.o@MM and bears the following characteristics:
mass-mailing worm constructing messages using its own SMTP engine
harvests email addresses from the victim machine
spoofs the From: address
contains a peer to peer propagation routine
More information can be found here.