Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Panda reports 4 new variants of the Mytob Worm
Search Topic:
Uniqs:
105
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Windows Update error 0x80072EE2 Sygate Personal Pr »
« Lost CD Key  
AuthorAll Replies


blkkat
Live On
Premium
join:2002-11-20
Juneau, AK

 Panda reports 4 new variants of the Mytob Worm

Panda Software reports a wave of variants of the Mytob worm -
MADRID, April 5 2005. PandaLabs has detected the appearance of four new variants (S, U, V and W) of the Mytob worm in just a few hours.

All of these variants have backdoor Trojan characteristics, i.e. they leave a backdoor open on the system to receive commands. This process is not carried out directly, but using servers called 19.xxor.biz (in the case of variants S, U and W), and irc.blackcarder.net, which is used by MyTob.V. This allows their creator to take control of any computers infected with these variants of Mytob.

One of the greatest dangers of this worm lies in its ability to modify system "hosts" files. It does this to prevent users connecting to the web pages of certain antivirus developers. Because of this modification, infected users won't be able to receive the updates needed to eliminate this malicious code.

The worm uses three different methods to spread:

- Exploiting the known LSASS vulnerability, published and corrected by Microsoft in the MS04-011 security bulletin, available at »microsoft.com/technet/security/b···011.mspx

- Through shared resources protected with weak passwords, i.e. ones that are easy to guess.

- By email. Sending messages with an attachment containing the Mytob code with one of the following extensions: .bat, .exe, .pif, .scr or .zip. The attached file could be called Data, Doc, Document, File, Readme, Text or Body, among others.

It sends itself to addresses it finds on the infected system in files with .adb,.asp, .dbx, .htm, .php, .pl, .sht and .tbb extensions and in the Windows address book. The extensions used depend on the variant of Mytob. As is becoming common practice with malicious code that spreads by email, the address of the sender is spoofed to help prevent infected computers from being rapidly pinpointed.

Mytob does not send itself out to certain email addresses (including those that contain the word "panda"), in an attempt, albeit unsuccessful, to impede its detection.

To prevent more than one copy of the worm running at the same time on the system, it creates different mutex, which vary according to the specific version of Mytob. The S version creates the mutex "ggmutexk2", the U variant creates "ggmutexk1", the V version "H-E-L-L-B-O-T-2-BY-DIABLO" and the W variant creates a mutex called "H-E-L-L-B-O-T".

As is becoming common lately, the author or authors of these worms are trying to unleash the largest number of malicious code possible in order to increase the probability of computers being infected. This time, as these are worms that allow remote control of affected computers, it is obvious that their aim is to create a network of computers that can be controlled at the same time. This would allow the attacker to carry out many different malicious actions, from mass installing other malware, like keyloggers or spyware, to creating 'zombies' for sending out spam.
--
"Common sense is genius dressed in its working clothes." Ralph Waldo Emerson (1803 - 1882); US philosopher, poet.
Forums » Up and Running » Security » SecurityWindows Update error 0x80072EE2 Sygate Personal Pr »
« Lost CD Key  


Wednesday, 07-Jan 16:09:47 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [160] New Comcast Throttling System 100% Online
· [109] After 10 Years Of Service, Charter Declares Home 'Unserviceable'
· [103] iTunes Dumps The DRM
· [70] AT&T, Verizon Stocks Tumble
· [54] Feds Start Wait List For DTV Converter Coupons
· [52] Cable To Grab 75% Of New Subs In 2009
· [37] Netflix Via LG HDTVs
· [36] New Zealand's 'One Strike' Piracy Law
· [35] DOCSIS 3.0 Gets Faster
· [34] ISPs Won't Admit Participation In New RIAA Plan
Most people now reading
· [Rant] cops and illegal searches [Rants, Raves, & Praise]
· anyone else getting high pings and slow speeds now? [TekSavvy]
· internet disconnected and phone line busy at 2:45 pm ? [TekSavvy]
· Network Maintenance Tonight [TekSavvy]
· 3.0.8 Patch Notes [World of Warcraft]
· Can't order UVerse and then cancel TV later [AT&T U-verse]
· [ Professions] Northrend Herbalism and Mining Tracks [World of Warcraft]
· Archivis' Guide to Naxx (10-man) [World of Warcraft]
· Constant Network Maintenance interruptions [TekSavvy]
· How to download windows 7 beta [Microsoft help]