Home > Security News > New worm uses Yahoo to spread
Security News:
EMAIL THIS

New worm uses Yahoo to spread

By Bill Brenner, News Writer
04 Aug 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Antivirus firms are calling it both Mydoom-Q and Evaman-C, and agree it packs little punch. But like last week's Mydoom-M outbreak, the worm is using a high-profile search engine to gain traction; leaving security experts worried that attackers are quickly perfecting ways to send a damaging payload to many more users.

"This latest iteration is meaningful not because of a particularly damaging payload, but because it uses something we value as a means to reach a larger target," said Brian Cincera, security practice director for New York-based Greenwich Technology Partners Inc. "We rely on easy access to information through search engines. In this case, search engines represent an attractive option for those considering ways to best deliver damaging payloads to a wide target community."

A new Yahoo worm strikes

Editor's note: Check out our article, "JavaScript worm spreads through Yahoo Mail" for more on the JS.Yamanner worm that surfaced in June 2006.
While Mydoom-Q/Evaman-C is considered a low risk, Cincera said, "This kind of delivery with a destructive payload would make it front-page news. For an IT manager, it underscores the importance of having preventative technology at the endpoint."

The mass-mailing worm copies itself to the Windows system folder as "winlibs.exe" and adds the registry entry "HKLMSoftwareMicrosoftWindowsCurrentVersionRunwinlibs.exe." It e-mails a copy of itself to addresses found on the local hard disk in files with the extensions txt, dhtm, msg, htm, xml, eml, html, sht, shtm, shtml, jse, jsp, js, php, cfg, asp, ods, mmf, dbx, tbb, adb, pl and wab. It also sends itself to addresses it finds through Yahoo People Search. Santa Clara, Calif.-based McAfee Inc. said in an advisory that the worm arrives as an e-mail attachment with a spoofed address header, takes a common name within the virus body and attaches it to the recipient's domain name: john@mydomain.com, for example.

"The technique isn't new, but it is certainly becoming more popular," said Craig Schmugar, virus research manager for McAfee AVERT. "We're seeing more blending and blurring between viruses and spam."

Read our Mydoom-M coverage

Mydoom-M on Internet rampage

Users are advised to update their antivirus protection and steer clear of suspicious e-mail attachments, as a new variant of Mydoom rampages across the Internet.
Johannes Ullrich, chief technology officer for the Bethesda, Md.-based Internet Storm Center, agrees the worm's use of a search engine like Yahoo illustrates "further cleverness" on the part of attackers. "The intent of this worm and other recent versions is to increase their pool of e-mail addresses by using big search engines," he said. "In this case, Yahoo is the engine of choice, and while it doesn't change the landscape much for IT managers, it does show the virus writers are finding ways to get many more e-mail addresses."

Despite their concern that virus writers are perfecting the means of a more devastating attack, all agree this latest worm is nothing compared to Mydoom-M, which went on an Internet rampage last week and bogged down the Lycos, Alta Vista, Yahoo and Google search engines. The attack waned by Tuesday, but a new worm, W32.Zindos-A, took advantage of doors Mydoom-M left open.

Zindos was designed to perform a denial-of-service attack against Microsoft.com, though it was not successful. It spread through the backdoor opened on TCP port 1034 by a Trojan horse called Backdoor.Zincite-A, which Mydoom-M dropped as part of its attack.

Tags: Malware, Viruses, Trojans and SpywareVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Malware, Viruses, Trojans and Spyware
How to get rid of malware, botnets on a hospital IT network
Should a national cybersecurity strategy include offensive botnets?
How to prevent mobile phone spying
How can search results lead to malware?
How to defend against rogue DHCP server malware
New Trojan stealing FTP credentials, attacking FTP websites
Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
When BIOS updates become malware attacks
Antispyware buying guide for Indian enterprises
PCI compliance requirement 5: Antivirus

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
directory traversal  (SearchSecurity.com)
government Trojan  (SearchSecurity.com)
Kraken  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
RavMonE virus  (SearchSecurity.com)
RFID virus  (SearchSecurity.com)
Rock Phish  (SearchSecurity.com)
Zotob  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts