Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Panda reports 4 new variants of the Mytob Worm
Search Topic:
Uniqs:
126
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Windows Update error 0x80072EE2 Sygate Personal Pr »
« Lost CD Key  
AuthorAll Replies


blkkat
Live On
Premium
join:2002-11-20
Juneau, AK

 Panda reports 4 new variants of the Mytob Worm

Panda Software reports a wave of variants of the Mytob worm -
MADRID, April 5 2005. PandaLabs has detected the appearance of four new variants (S, U, V and W) of the Mytob worm in just a few hours.

All of these variants have backdoor Trojan characteristics, i.e. they leave a backdoor open on the system to receive commands. This process is not carried out directly, but using servers called 19.xxor.biz (in the case of variants S, U and W), and irc.blackcarder.net, which is used by MyTob.V. This allows their creator to take control of any computers infected with these variants of Mytob.

One of the greatest dangers of this worm lies in its ability to modify system "hosts" files. It does this to prevent users connecting to the web pages of certain antivirus developers. Because of this modification, infected users won't be able to receive the updates needed to eliminate this malicious code.

The worm uses three different methods to spread:

- Exploiting the known LSASS vulnerability, published and corrected by Microsoft in the MS04-011 security bulletin, available at »microsoft.com/technet/security/b···011.mspx

- Through shared resources protected with weak passwords, i.e. ones that are easy to guess.

- By email. Sending messages with an attachment containing the Mytob code with one of the following extensions: .bat, .exe, .pif, .scr or .zip. The attached file could be called Data, Doc, Document, File, Readme, Text or Body, among others.

It sends itself to addresses it finds on the infected system in files with .adb,.asp, .dbx, .htm, .php, .pl, .sht and .tbb extensions and in the Windows address book. The extensions used depend on the variant of Mytob. As is becoming common practice with malicious code that spreads by email, the address of the sender is spoofed to help prevent infected computers from being rapidly pinpointed.

Mytob does not send itself out to certain email addresses (including those that contain the word "panda"), in an attempt, albeit unsuccessful, to impede its detection.

To prevent more than one copy of the worm running at the same time on the system, it creates different mutex, which vary according to the specific version of Mytob. The S version creates the mutex "ggmutexk2", the U variant creates "ggmutexk1", the V version "H-E-L-L-B-O-T-2-BY-DIABLO" and the W variant creates a mutex called "H-E-L-L-B-O-T".

As is becoming common lately, the author or authors of these worms are trying to unleash the largest number of malicious code possible in order to increase the probability of computers being infected. This time, as these are worms that allow remote control of affected computers, it is obvious that their aim is to create a network of computers that can be controlled at the same time. This would allow the attacker to carry out many different malicious actions, from mass installing other malware, like keyloggers or spyware, to creating 'zombies' for sending out spam.
--
"Common sense is genius dressed in its working clothes." Ralph Waldo Emerson (1803 - 1882); US philosopher, poet.
Forums » Up and Running » Security » SecurityWindows Update error 0x80072EE2 Sygate Personal Pr »
« Lost CD Key  


Tuesday, 24-Nov 02:16:01 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [84] New AT&T Ad Campaign Hits Back At Verizon
· [51] New Bill Takes Aim At Higher Verizon ETFs
· [30] AT&T Offers New Prepaid Wireless plans
· [29] Earthlink Suffers From Major E-mail Outage
· [26] Frontier Increases Modem Rental Fee
· [12] Vivendi In Way Of Comcast's NBC Desires
· [11] Charter Still Fighting With Creditors
· [7] Monday Morning Links
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Big Bank Alternative to Bank of America? [General Questions]
· What to use while demonoid is down? [Filesharing Software]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Taking the Plunge into Asterisk/AsteriskNow/TrixBox? [VOIP Tech Chat]
· netTalk tk6000 [VOIP Tech Chat]