Welcome | Sign In
ECommerceTimes.com
Security

MyDoom.F Spreads Carnage with Malicious Payload

Print Version
E-Mail Article
Reprints
MyDoom.F Spreads Carnage with Malicious Payload

Among the files MyDoom.F attempts to delete are .bmp and .jpg graphic files, .avi movie files, Microsoft Word .doc files, Microsoft Excel .xls files, and Microsoft Access .mdb files. Sophos analyst Graham Cluley estimated the worm's overall success rate as averaging about 40 percent in this regard.


Is Your Website Killing Customer Confidence?
Your Website's privacy policy can be a key factor in a customer's decision to do business with you, and it is vital to ensuring you don't run afoul of your online legal and regulatory responsibilities. Need more reasons? Read on.

The latest iteration of the MyDoom worm, "MyDoom.F," has Internet security experts worried because, in addition to triggering denial-of-service (DoS) attacks, it also can delete files from infected computers. MyDoom.F was first identified last Friday and has picked up steam in just the last few days, Sophos senior technology consultant Graham Cluley told the E-Commerce Times.

"Because it came out just before the weekend, fewer people were opening their e-mails," Cluley said. "But by Monday morning, with people having to plow through spam and other [e-mail], the virus then reaches a critical mass -- a shooting star, if you will -- and causes more problems."

Richard Stiennon, vice president of research for Internet security at Gartner (NYSE: IT), told the E-Commerce Times that MyDoom.F will raise awareness of the mass destruction malware can cause. In the past two years, most worms have caused damage merely by spreading. Destruction of files could have a much greater economic impact and be especially painful for consumers.

In addition to its ability to delete files, MyDoom.F aims to turn infected computers into zombies that will launch DoS attacks on Web sites belonging to Microsoft (Nasdaq: MSFT) and the Recording Industry Association of America (RIAA). Unlike MyDoom.A, which targeted The SCO Group's Web site but had a relatively small attack window of several days, MyDoom.F's expiration date for performing DoS attacks is February 16, 2006 -- almost two years after its introduction into the wild.

The worm affects computers running all versions of Microsoft Windows, from Windows 95 to Windows XP, and targets the C to Z drives, whether they are local or networked. Computers running Linux or Mac OS are not affected, though their e-mail boxes may become clogged by spam generated by the worm.

Purely Vandalism

According to Cluley, MyDoom.F tries to destroy a wide range of files for no apparent reason beyond pure vandalism. He estimated the worm's overall success Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse rate as averaging about 40 percent, adding that a number of different conditions determine the worm's success or failure in this regard.

Among the files MyDoom.F attempts to delete are .bmp and .jpg graphic files, .avi movie files, Microsoft Word .doc files, Microsoft Excel .xls files, and Microsoft Access .mdb files.

Deletion of graphic and video files has the potential to spark major upset among home PC users, according to Cluley, because those users often store family memories and communications with loved ones using such files.

By targeting productivity files, the worm also has potential to wreak havoc on businesses, although most businesses have stricter backup and security regimes than the typical home user, Cluley said.

Assault and Capture

Determining the MyDoom.F writer's motive is difficult, Cluley added. However, he said he thinks the writer might be sympathetic to people whom the RIAA is targeting in its campaign of lawsuits against illegal file-sharers. Notably, the virus is not targeting music files with extensions of .mp3 or .wma.

Even more difficult is determining the identity of the virus writer who based MyDoom.F on the original MyDoom's source code and then altered the payload.

Unlike the original MyDoom virus, MyDoom.F is what Cluley called a "tagged" virus. In the decrypted worm body, a signature reads, "I am 'Irony', made by jxq7."

"If the writer used this nickname in other areas of interest, this may help in capturing" the culprit, he said. "But out of the 88,000 or so computer viruses that exist, fewer than 20 of the writers have been arrested."

For his part, Gartner's Stiennon estimated there are about 30,000 individuals who spend a significant portion of their time hacking. While that is a finite number, it still makes any motivation possible for making a destructive piece of software.

What To Do? The Usual

Cluley went on to say that, on the enterprise level, most virus-infected e-mail is stopped at the e-mail gateway and through antivirus software installed throughout the organization. He recommended that enterprises automate the update process and apply the latest Microsoft security patch so that client users need not worry as much about potential infections.

At the same time, he recommended that IT departments take an extremely proactive stance on virus protection -- one that goes beyond educating users not to open unexpected, unsolicited e-mail attachments.

"Make it so no executable code comes into users' e-mail boxes," Cluley said. "Have it instead go straight through the IT department, where they can then check if it has been properly licensed and isn't a virus. Letting .exe files go to users isn't a safe way to run a business."


Print Version E-Mail Article Reprints More by Staff Writer


More by Staff Writer

A Midsummer's Mac Death Match, Round Two: Enderle vs. Chaffin
July 13, 2004
MacNewsWorld presents round two of our three-round Midsummer Mac Death Match, in which Mac Observer editor-in-chief Bryan Chaffin and the always-controversial industry analyst Rob Enderle square off on one of today's key Mac issues. Today Enderle and Chaffin eachs kicks metaphorical mounds of sand on the arguments the other made in round one on the question of where Apple will be five years from now.
A Midsummer's Mac Death Match, Round One: Enderle vs. Chaffin
July 12, 2004
MacNewsWorld presents round one of our three-round Midsummer Mac Death Match. Today, Mac Observer editor-in-chief Bryan Chaffin and the always-controversial industry analyst Rob Enderle each offer their predictions of what sort of company Apple will be in five years. Will Apple rule the "Digital Life" -- or be the Atari of 2009?
PeopleSoft Blames Oracle for Share Price Free Fall
July 07, 2004
Forrester vice president and CRM analyst Erin Kinikin described PeopleSoft as being on a very narrow tightrope since Oracle first made its takeover offer. "To prove [it] can survive as an independent company, PeopleSoft has to make its numbers," Kinikin told CRM Buyer. "Any time PeopleSoft pre-announces lower earnings, people are going to wonder if [it is] falling off the tightrope."
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network