Sunday, April 4, 2010

W32.Mydoom.M@mm

Discovered: July 26, 2004
Also Known As: W32/Mydoom.o@MM [McAfee], W32/MyDoom-O [Sophos], WORM_MYDOOM.M [Trend Micro], Win32.Mydoom.O [Computer Assoc, I-Worm.Mydoom.m [Kaspersky], W32/Mydoom.N.worm [Panda]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

W32.Mydoom.M@mm is a mass-mailing worm that drops and executes a backdoor, detected as Backdoor.Zincite.A, that listens on TCP port 1034. The worm uses its own SMTP engine to send itself to email addresses it finds on the infected computer.

The email contains a spoofed From address, and the Subject and Body text will vary. The attachment name will also vary.

W32.Mydoom.M@mm is packed with UPX.

Source: http://www.symantec.com/security_response/writeup.jsp?docid=2004-072615-3527-99

Labels: ,


Tuesday, March 23, 2010

Hello World

Labels: , , , , , , , , , , , ,


This page is powered by Blogger. Isn't yours?

Subscribe to Posts [Atom]