Skip the navigation

Update: New Mydoom worm discovered

The new variant, Mydoom.B, targets Microsoft for a denial-of-service attack

By Linda Rosencrance
January 28, 2004 12:00 PM ET

Computerworld - A new variant of the Mydoom.A (Novarg.A) worm, which has been spreading swiftly across the Internet since Monday, emerged today, according to London-based security vendor Mi2g Ltd.
The variant, Mydoom.B, has a larger payload and targets Microsoft's Web site for a distributed denial-of-service attack on Feb. 1, instead of The SCO Group Inc.'s Web site, which was targeted by the first version, Mi2g said in a statement. Mi2g pointed to minor changes to the text padding in the malware and said it's possible that Mydoom.B is being disseminated via infected computers turned into zombie machines by Mydoom.A, as well as the Kazaa file-sharing system.
If so, "this could turn the whole Mydoom episode into a much more adverse series of unfortunate events," Mi2g said.
No one has yet reported an infection by Mydoom.B, said David Perry, global director of education at Cupertino, Calif.-based antivirus vendor Trend Micro Inc. "If 100 people in the world had been infected, we would know," he said. "In fact, almost all of the viruses that have ever been detected never infected anybody ever. We say that there are about 77,000 known viruses, but only about 900 of them have ever infected anyone."
Even so, security companies said the emergence of another version of the worm could cause problems.
"This is an extremely unwelcome development. Mydoom.b may have just multiplied the full impact of Mydoom.A a few fold," said D.K. Matai, executive chairman of Mi2g. "We know that many large and small organizations as well as homes are struggling to cope with the deluge of e-mails originating from the 'a' variant infections -- never mind the arrival of 'b,' which shows signs of being just as vicious."
Early information indicates that the new variant is likely spreading in the wild, said Ken Dunham, director of malicious code at iDefense Inc., a security consulting company in Reston, Va.
Dunham said the Mydoom.B worm modifies the standard hosts file in a Windows folder that can block access to 65 Web sites, most of which are antivirus Web sites, in an apparent attempt to block users from downloading antivirus solutions and data.
"This new variant of Mydoom is worse than Mydoom.A," Dunham said in a statement via e-mail. "And an attack on the Microsoft.com Web site could cause a significant disruption of services for users worldwide. It's feasible that Mydoom.A computers are now being used to help launch Mydoom.B, via the proxy setup supported by the worm. If this is the case, Mydoom.B will likely become very prevalent in the wild in just a few short hours."
Although that doesn't mean millions of computers are actually infected, it could mean millions of e-mails harboring the worm are in the wild, Dunham said.
He said computer users should be on guard for a succession of worm attacks this year. "Undoubtedly, attackers are now mirroring the success of worms like Sobig to launch successive attacks in 2004," Dunham said.
Security vendor BitDefender in Bucharest, Romania, said Mydoom.b is only slightly different from the first virus variant.
"Still, we can expect a new wave of infections, as the author already has a base target," said Mihai Neagu, a virus researcher at BitDefender. "It seems, by the sheer amount of the first version that got sent through networks at this point, that many users will inadvertently cause a new major outbreak."
Moscow-based security software developer Kaspersky Labs has a different reading of the new variant than Mi2g. It said Mydoom.B is scheduled to launch a DoS attack between Feb. 1 and Feb. 12 on both www.sco.com and www.microsoft.com.
"Our analysts believe that Mydoom.B is probably using machines infected by the original Mydoom, which could mean as many as 600,000 units," Kaspersky Labs said in a statement via e-mail. "These infected computers may have received a command to send out copies of Mydoom.B. Therefore, the computer community may be facing a much more serious outbreak than the one caused by Mydoom.A on Jan. 27."




Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs