Home→Descriptions→Email-Worm.Win32.Mydoom.e
| Detected | Feb 26 2004 15:53 GMT |
| Released | Jul 31 2004 15:02 GMT |
| Published | Feb 26 2004 15:53 GMT |
This worm has also been called Mydoom.F, and is a modification of Mydoom.a.
It spreads via the Internet as a file attached to infected messages. The worm is a PE EXE file of 33KB or slightly larger, packed using UPX. The unpacked file is approximately 55KB in size. The worm is also able to send itself as a ZIP archive.
The worm is only activated if the user opens the archive and launches the infected file, by clicking twice on the attachment. The worm then installs itself on the systems and starts propagation.
The worm includes a backdoor function, and is programmed to carry out DoS attacks on www.microsoft.com and www.riaa.com
Everything points to this worm not being an original creation, but a separate version which has been created around the orignal source code of Mydoom.a. Part of the original code is present in this version, even though it serves no useful function.
Once launched, the worm may display a fake error message on the screen: 'File is corrupted,' 'File cannot be opened,' or 'Unable to open specified file'.
The worm may also create a file in the temporary system directory. This file contains a random selection of characters, and the worm may open it using Notepad.
It also creates a mutex 'jmydoat name of infected computer Xmtx' to flag its presence in the system.
When installing, the worm copies itself under a random name to the Windows system directory and registers this file in the system registry auto-run key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run HKCU\Software\Microsoft\Windows\CurrentVersion\Run random characters = "%System%\name of worm file
The worm then searchs all accessible disks from C: to Z: and copies itself under random names to all disks which it finds which include the words
shar startup startin the name.
The worm creates a file with a random name and .dll extension in the Windows system directory. This file is 9724 bytes in size, and is the backdoor component, which is intended to open a backdoor on port 1080 and act as a proxy server.
The worm creates several copies of itself as ZIP archives in the Windows root directory. These files are then used to send mass emails. In order to flag its presence in the system, the worm also creates several additional keys in the system registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell HKCU\Software\Microsoft\Windows\CurrentVersion\Shell
wab mbx nch mmf ods rtf uin oft mht vbs msg pl eml adb tbb dbx asp php sht htm txtIt then sends itself to all email addresses found in these files.
Infected emails have the following characteristics:
jerry bill smith jim sam james alexA random selection of characters may also be used. In this case, after the @ symbol in the sender's address, one of the following domains will be used:
aol.com msn.com yahoo.com hotmail.com edu
hello hi Announcement read now! forget bug unknown fake Wanted recent news news stolen Attention Accident Schedule Re: Thank you Thank you Re: Details Details Re: Approved Approved hi, it's me Important Readme Read this message please read please reply Thank You very very much You use illegal File Sharing... Your IP was logged Your account is about to be expired Love is Love is... Undeliverable message Re:Your order was registered Your request was registered Your order is being processed Your request is being processed Current Status Your credit card Read it immediately! Read this Read it immediately Something for you For you For your information Information Warning You have 1 day left automatic notification automatic responder Notification Expired account Your account has expired Registration confirmation Confirmation Confirmation Required Returned Mail
Greetings See you Here it is You are bad Take it Reply Please, reply Okay OK Everything ok? Check the attached document. The document was sent in compressed format. Please see the attached file for details See the attached file for details Details are in the attached document. You need Microsoft Office to open it. Information about you We have received this document from your e-mail. Kill the writer of this document! Something about you I have your password :) You are a bad writer Is that yours? Is that from you? I wait for your reply. Here is the document. Read the details. I'm waiting
body message test data file text readme document doc msg photo resume image object website friend jokes joke approved paypal disc misc part3 part2 part4 part1 mail2 list mail story about money check product notes your_document note information textfile posting post stuff attachment creditcard detailsor a selection of random characters.
The attached file has one of the following extensions:
exe scr com pif bat cmd zipand a second extension from the following list:
doc htm rtf xls jpg gif png txt exe pif scr
reged taskmo taskmg avp. avp32 norton navapw navw3 intrena mcafeand attempts to stop them.
Email-Worms spread via email. The worm sends a copy of itself as an attachment to an email message or a link to its file on a network resource (e.g. a URL to an infected file on a compromised website or a hacker-owned website).
In the first case, the worm code activates when the infected attachment is opened (launched). In the second case, the code is activated when the link to the infected file is opened. In both case, the result is the same: the worm code is activated.
Email-Worms use a range of methods to send infected emails. The most common are:
Email-Worms use a number of different sources to find email addresses to which infected emails will be sent:
Many Email-Worms use more than one of the sources listed above. There are also other sources of email addresses, such as address books associated with web-based email services.
Email-Worm.