Ads

WORM_MYTOB.JH PDF Print E-mail
Wednesday, 03 August 2005
Malware type: Worm
Aliases: No Alias Found
In the wild: Yes
Destructive: No
Language: English
Platform: Windows 95, 98, ME, NT, 2000, XP, Server 2003
Encrypted: No
Characteristics: Propagates via email, Propagates via network shares Description:

Like other MYTOB variants, this memory-resident worm propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

It obtains target recipients from the users Windows address book (WAB).

It generates email addresses by using a list of names and any of the domain names of the previously gathered addresses.

The email it sends out has the following details:

Subject: (any of the following)
*DETECTED* Online User Violation
Email Account Suspension
Important Notification
Members Support
Notice of account limitation
Security measures
Warning Message: Your services near to be closed.
You have successfully updated your password
Your Account is Suspended
Your Account is Suspended For Security Reasons
Your new account password is approved
Your password has been successfully updated
Your password has been updated

Message body: (any of the following)
Dear user {random}, You have successfully updated the password of your {random} account.

If you did not authorize this change or if you need assistance with your account, please contact {random} customer service at: {random}

Thank you for using {random}!
The {random} Support Team

+++ Attachment: No Virus (Clean)
+++ {random} Antivirus - www.{random}


Dear user {random},

It has come to our attention that your {random} User Profile ( x ) records are out of date. For further details see the attached document.

Thank you for using {random}!
The {random} Support Team

+++ Attachment: No Virus (Clean)
+++ {random} Antivirus www.{random}


Dear {random} Member,

We have temporarily suspended your email account {random}.

This might be due to either of the following reasons:

1. A recent change in your personal information (i.e. change of address).
2. Submiting invalid information during the initial sign up process.
3. An innability to accurately verify your selected option of subscription due to an internal error within our processors.
See the details to reactivate your [random] account.

Sincerely,The {random} Support Team

+++ Attachment: No Virus (Clean)
+++ {random} Antivirus - www.{random}


Dear {random} Member,

Your e-mail account was used to send a huge amount of unsolicited spam messages during the recent week. If you could please take 5-10 minutes out of your online experience and confirm the attached document so you will not run into any future problems with the online service.

If you choose to ignore our request, you leave us no choice but to cancel your membership.

Virtually yours,
The {random} Support Team

+++ Attachment: No Virus found
+++ {random} Antivirus www.{random}

Attachment: (any of the following)
accepted-password
account-details
account-info
account-password
account-report
approved-password
document
email-details
email-password
important-details
new-password
password
readme
updated-password

(with any of the following extensions)
BAT
CMD
EXE
PIF
SCR
ZIP

This worm has backdoor capabilities, which enable it to connect to the Internet Relay Chat (IRC) server, fbi.thuggaming.net/MyNiggazPwn.net. Once a connection is established, it joins the IRC channel ##Hellbot3##, where it listens for certain commands from a remote malicious user. It executes these commands locally on an affected system, providing the remote user virtual control over the affected system.

Moreover, it prevents users from accessing several antivirus and security Web sites by redirecting the connection to the local machine.


 
< Prev   Next >