Skip to main content

Swift Mytob Worm is Back

posted onOctober 19, 2005
by hitbsecnews

Security firm MessageLabs detected a new variant of the Mytob worm and said it intercepted 100 copies within the first several hours of its discovery today.

Although it is similar to previous Mytob variants, this version of the malicious code, dubbed DoomBot, is delivered with a header warning individuals that their services are about to be closed.

However, the latest code appears to have more variants, said MessageLabs' Senior Antivirus Researcher Maksym Schipka.

The file name on the attachment reads "important-details.txt." Once executed, the variant installs itself to %sysdir%d.exe, joins a command and control channel named ‘r0x’ on the IRC server rax.oucihax.info.

"It is extremely similar in functionality to previous Mytobs," said Schipka, who believes this variant came from the Chinese hacker group known as Evil Security.

The lead mischief maker, known as Mr. Evil, has said it is the last variant his group intends to produce, according to Schipka.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th