January 29, 2004

New Mydoom worm discovered

Variant has larger payload and targets Microsoft's Web site for DoS attack

A new variant of the Mydoom.a (Novarg.a) worm, which has been spreading swiftly across the Internet since Monday, emerged Wednesday, according to London-based security vendor Mi2g Ltd.

The variant, Mydoom.b, has a larger payload and targets Microsoft Corp.’s Web site for a distributed denial-of-service attack on Feb. 1, instead of The SCO Group Inc.’s Web site, which was targeted by the first version, Mi2g said in a statement. Mi2g pointed to minor changes to the text padding in the malware and said it’s possible that Mydoom.b is being disseminated via infected computers turned into zombie machines by Mydoom.a, as well as the Kazaa file-sharing system.

If so, "this could turn the whole Mydoom episode into a much more adverse series of unfortunate events," Mi2g said.

No one has yet reported an infection by Mydoom.b, said David Perry, global director of education at Cupertino, Calif.-based antivirus vendor Trend Micro Inc. "If 100 people in the world had been infected, we would know," he said. "In fact, almost all of the viruses that have ever been detected never infected anybody ever. We say that there are about 77,000 known viruses, but only about 900 of them have ever infected anyone."

Even so, security companies said the emergence of another version of the worm could cause problems.

"This is an extremely unwelcome development. Mydoom.b may have just multiplied the full impact of Mydoom.a a few fold," said D.K. Matai, executive chairman of Mi2g. "We know that many large and small organizations as well as homes are struggling to cope with the deluge of e-mails originating from the ‘a’ variant infections -- never mind the arrival of ‘b,’ which shows signs of being just as vicious."

Early information indicates that the new variant is likely spreading in the wild, said Ken Dunham, director of malicious code at iDefense Inc., a security consulting company in Reston, Va.

Dunham said the Mydoom.b worm modifies the standard hosts file in a Windows folder that can block access to 65 Web sites, most of which are antivirus Web sites, in an apparent attempt to block users from downloading antivirus solutions and data.

"This new variant of Mydoom is worse than Mydoom.a," Dunham said in a statement via e-mail. "And an attack on the Microsoft.com Web site could cause a significant disruption of services for users worldwide. It’s feasible that Mydoom.a computers are now being used to help launch Mydoom.b, via the proxy setup supported by the worm. If this is the case, Mydoom.b will likely become very prevalent in the wild in just a few short hours."

Although that doesn’t mean millions of computers are actually infected, it could mean millions of e-mails harboring the worm are in the wild, Dunham said.

He said computer users should be on guard for a succession of worm attacks this year. "Undoubtedly, attackers are now mirroring the success of worms like Sobig to launch successive attacks in 2004," Dunham said.

Security vendor BitDefender in Bucharest, Romania, said Mydoom.b is only slightly different from the first virus variant.

"Still, we can expect a new wave of infections, as the author already has a base target," said Mihai Neagu, a virus researcher at BitDefender. "It seems, by the sheer amount of the first version that got sent through networks at this point, that many users will inadvertently cause a new major outbreak."

Moscow-based security software developer Kaspersky Labs has a different reading of the new variant than Mi2g. It said Mydoom.b is scheduled to launch a DoS attack between Feb. 1 and Feb. 12 on both www.sco.com and www.microsoft.com.

"Our analysts believe that Mydoom.b is probably using machines infected by the original Mydoom, which could mean as many as 600,000 units," Kaspersky Labs said in a statement via e-mail. "These infected computers may have received a command to send out copies of Mydoom.b. Therefore, the computer community may be facing a much more serious outbreak than the one caused by Mydoom.a on Jan. 27."

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.