MYTOB variant fakes email errors

By
Follow google news

A new variant of the MYTOB worm has been discovered that pretends to be a legitimate email warning of a delivery error or email account problem.

A new variant of the MYTOB worm has been discovered that pretends to be a legitimate email warning of a delivery error or email account problem.


The worm, WORM_MYTOB.ED was the 100th variant to be identified since the MYTOB worm first appeared in February this year, security vendor Trend Micro has said in a statement.

The worm propagated by sending a copy of itself as an email attachment which it sent using its own Simple Mail Transfer Prorocol (SMTP) engine, the company said.

Email addresses were harvested from the Temporary Internet Folder Windows Address Book, as well as from files with certain extension names. The worm was also able to generate email addresses by combining names and domains that had previously been gathered.

According to the company, once infected, the worm prevented users from accessing antivirus sites by redirecting connections from the local machine.

MYTOB.ED made a system vulnerable to further attacks by using Internet Relay Chat (IRC) backdoors. This allowed a remote user to download and execute files on an affected machine.

Trend Micro issued a medium risk alert for MYTOB.ED which has been reported in Europe and Asia Pacific.

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Researchers detail Bluetooth headphone attack that can hijack smartphones

Researchers detail Bluetooth headphone attack that can hijack smartphones

Patients fret as ManageMyHealth data breach drama plays out

Patients fret as ManageMyHealth data breach drama plays out

Cloudflare DNS reply change crashed Cisco SME switches

Cloudflare DNS reply change crashed Cisco SME switches

Aussie teenager charged with swatting US retailers and educational institutions

Aussie teenager charged with swatting US retailers and educational institutions

Log In

  |  Forgot your password?