main

New MyDoom Variant Uses Yahoo People Search

malebolgia   on 03 August 2004 - 20:18 · 7 comments & 483 views

Advertisement (Why?)
Another new version of MyDoom is worming its way through the Internet, and this variant—like the last one—uses Yahoo as part of its infection routine. MyDoom.P is similar to most of the other MyDoom variants in that it arrives via e-mail, with a spoofed sending address and a subject line designed to make it look like the message is related to one that the recipient sent. Among the subject lines in the e-mails are "SN: New secure mail," "Secure delivery," "Re: Extended mail," "Delivery Status (Secure)," "Re: Server Reply" and "SN: Server Status."

The body of the e-mail contains any of a number of sentences, some of which refer to the included Zip file. Many of the messages reference security or refer to the attached file as a "secure Zip file." Once opened, the executable file copies itself to the Windows system directory as "winlibs.exe." The executable contains a list of dozens of common first and surnames that it puts through Yahoo's People Search in an attempt to find more e-mail addresses to mail itself to, according to a preliminary analysis of the worm done by the staff of the Internet Storm Center at The SANS Institute in Bethesda, Md.

News source: eWeek


Cont...

Besides exposing plans for a Sudeki sequel, the ad also appeared to reveal two other new games: The Final Option and Dragon Wars. No further information was revealed for those titles, although the listing also mentions Codename Avalon, Climax's previously announced mystery project for next-generation consoles.

Given Sudeki's lackluster critical reception, many industry watchers wondered if Climax will stick with its plans to a sequel. Reps for Climax did not respond to inquiries as of press time.

Post a comment · Send to friend Comments · There are 7 additional comments
(1 reply) #1 [moribundi] on 03 Aug 2004 - 20:46
Am I reading this right...there are *still* people out there that open email attachments that they don't know who it's from or what the file is?
#1.1 StaticX on 03 Aug 2004 - 21:13
lol people will never learn!
(3 replies) #2 NightWalker05 on 03 Aug 2004 - 21:12
Yep lol theys people "out there" who dont either use antivirus software
#2.1 Andareed on 03 Aug 2004 - 22:01
This has nothing to do with it. It is simply that people are incredibly naive.
#2.2 Jon on 04 Aug 2004 - 07:13
Of course that's to do with it!!!!!!!!!!!!!!!!!!!
Of all the stupid comments I've read here!!

And have you actually looked at the different permutations of wordings on mydoom.q (I'm an NAI guy), some of them are VERY convincing to the non technical worker.
#2.3 Magallanes on 05 Aug 2004 - 16:54
I don't use antivirus nor anti-spywares nor anti-trojans, truly i don't need any of this, just have the system updated, disable any useless service, tried to not visit any webpage and don't open any suspicious email, and if a virus is installed in my pc, then i can remove manually (is tricky but easy), even i can remove spywares that nor ad-aware nor spybot can remove.

And i'm testing to protect the run runonce runservice registry (current users and local machine), with a registry protected, i avoid to catch almost all viruses, spywares or trojan, they can enter to my pc but they cannot re-activated himself, so they died in each restart.


#3 shao on 03 Aug 2004 - 22:44
and there's still dumb****s out there writing this malware... virus writers, or email address harvesting for spam senders? i don't see a difference these days, it's just sad to see marketers resorting to illegal practices to get hold of email addresses.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)