Like other mass-mailing worms, MyDoom.O avoids sending messages to antivirus company domains such as Sophos (PLC) and Trend (Micro Inc.) It also tries to skirt large Web e-mail providers by not sending e-mail to the Hotmail, Yahoo and Google domains, among others, according to antivirus companies.
The worm uses standard search syntax to look for e-mail addresses, which could make it difficult for search engines to separate MyDoom-generated traffic from other Internet queries, Ullrich said.
Ullrich estimated that "a couple hundred thousand machines" may be infected with MyDoom.O. Those machines can generate huge volumes of search requests, which appear to be bogging down major search engines.
Though MyDoom.O is the fifteenth version of a worm that first appeared in January, and in most ways similar to the variants that came before it, the new techniques used by the latest variant -- including its use of Web search engines to harvest e-mail addresses -- may be paying off and encouraging the spread of the O version, said Sam Curry, vice president of eTrust Security Management at CA.
In addition to the Web searching, MyDoom.O also has improved features for spreading between computers connected over a peer to peer (P-to-P) network and in the message body, which uses "social engineering" tricks to lure recipients into clicking on the virus file, he said.
"It's one of those things where the whole is greater than the sum of its parts," Curry said. "There's nothing here radically new, but there are some small incremental improvements that are leading to drastic improvements in the worm's ability to spread."
McAfee received about 40 MyDoom.O virus samples per hour since first identifying the new variant at around 6:30 a.m. Pacific Time, Telafici said. That's a more sustained rate than recent outbreaks like Bagle.AF, which died out quickly after first appearing. Some antivirus researchers attribute such spikes to virus "seedings" that use compromised machines, or "zombies," to distribute virus-infected e-mail to millions of machines simultaneously.
CA also upgraded its warnings about the worm to "medium" on Monday. The company said it received more than 1,000 samples of the virus from customers since identifying the worm early Monday.
The fact that MyDoom.O submissions have remained high may be evidence that the virus is spreading and generating its own mail traffic, Telafici said.
At Boston College in Chestnut Hill, Massachusetts, network administrators saw a spike in MyDoom.O e-mails between 7:00 a.m. and 10:00 a.m. Eastern Time, but the virus-generated e-mail dropped off sharply after antivirus companies, including McAfee and Sophos PLC, released virus definition updates to detect MyDoom.O, said David Escalante, director of computer security at the college.
Web performance measurement company Keynote Systems Inc. said that it noticed a decrease in the responsiveness of 40 major Web sites that it manages, beginning at around 7:00 AM Pacific Time on Monday, said Dan Berkowitz, director of corporate communications at Keynote.
The reliability measurement of the "Keynote Business 40," an index of large and highly trafficked Web sites, decreased by around 1.5 percent to 95.5 percent Monday morning, which experts at the company believe is due to the MyDoom worm, Berkowitz said.
Keynote, of San Mateo, California, was still analyzing the slowdowns Monday, but said that it noticed more pronounced slowdowns in search features offered by the 40 Web sites during the same period, and that it measured slowdowns at the four search engines targeted by MyDoom.O, he said.
Antivirus companies advised customers to update their virus definitions to detect the MyDoom.O worm.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »