iTnews
  • Home
  • News
  • Technology
  • Security

Aust MyDoom impact continues

By Nirmal Chandrasena
Jan 29 2004 12:00AM
Follow google news

A self propagating worm called MyDoom has spread across the globe like digital wildfire, leaving the computer world to face its greatest ever virus attack.


The email virus, also known as Norvag or Mimail-R, broke out on Monday, 26 January and took only three days to reach almost every corner of the internet -- its purpose apparently to launch attacks against Unix vendor SCO's website.

Allan Bell, marketing director at McAfee Security, estimates that MyDoom has already generated over 100 million infected emails.

Likewise, David Banes -- technical director of Message Labs Australia -- stated that one in 12 emails intercepted from around the world contained the virus, and confirmed that the worm was not slowing. "The numbers are still going up", he said.

A worm or email virus typically infects a host computer by 'tricking' a user into executing it, and then spreading to all addresses available on the user's machine. MyDoom 'tricks' or gains attention by pretending to by a system-error, and usually comes with attachments with 'double-extensions' (for example, txt.pif or .htm.zip).

The worm will then launch 'denial of service' (DoS) attacks between 1 and 12 February against Utah-based Unix vendor SCO's website, www.sco.com.

It is believed that the worm's tastes are related to SCO's unpopular move to start charging for the Linux operating system, and launch legal threats on those who don't comply.  SCO has posted a US$250K ($321K) bounty on information leading to arrests of the authors of the virus, and the worm has now attracted the attention of the US Federal Bureau of Investigation.

Though it may not appear that MyDoom poses an immediate threat to the host computers, it will also open the host machines up to hackers -- who can then take remote control of the infected system and launch more attacks or spread spam.
 
According to internet security firm F-Secure, there are a quite a few reasons as to why MyDoom has been more successful in wreaking havoc on the internet.

MyDoom demonstrates more cunning social engineering, 'scaring' users into opening the required executables by posing as error messages, where previous viruses were more transparent by offering content like pornography. McAfee's Bell commented that this method is far superior to older worms such as "Anna Kournikova" and "Love Letter", because MyDoom's email is "not a message that will stick in people's heads".

MyDoom was also launched during the working hours of America and Canada -- a time when corporate email traffic is most dense. It also avoided spreading itself to government and military organisations to avoid early detection by authorities.

FSecure also noted that MyDoom was more aggressive in the way it handled email addresses. It not only stole addresses from infected machines, but it guessed/spoofed addresses. It also copied itself into shared-folders used by the file-sharing application, KaZaa.

Another reason for its successful spread is the manner by which MyDoom disguises itself as an attachment. It uses double file extensions which, according to Bell, is used to confuse email clients that may traditionally hide or block files of certain extentions.

On top of it's spreading, much of the traffic generated by MyDoom consists of 'bounced' emails from servers rejecting emails fake addresses, and auto-responders in virus software that inform/accuse the 'senders' that a virus was detected.

In Australia, McAfee's Bell said that 1 in 10 emails intercepted within Australia were infected, placing the local estimate higher than MessageLab's global rate of 1 in 12.

McAfee does not believe that it will get any worse, Bell commenting that that the infection is currently 'sustained'.

David Banes from Messagelabs said that Australia is accounting for about 5 percent of the global infection, and also added that around 3.4 million emails had been intercepted locally.

When asked if MyDoom would slow in the near future, Bell said that it was too early to comment. Worms traditionally slow after a 24-hour peak, but MyDoom has shown no signs of slowing.

Between Wednesday and Thursday, a sequel to MyDoom (MyDoom.b) had surfaced, targeting also the Microsoft website. According to Bell, the spin-off virus also blocks users' access to anti-virus websites by corrupting how the machine resolves website names. As a consequence, infected machines have a hard time trying to access anti-virus websites.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Tags:
austcontinuesimpactmydoomsecurity

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre
Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.