ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Spreading virus takes aim at SCO

Published: 27 Jan 2004 09:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A mass-mailing virus quickly spread through the Internet on Monday, compromising computers so that they will attack the SCO Group's Web server with a flood of data on 1 February, according to antivirus companies.

The virus -- known as MyDoom, Novarg and as a variant of the Mimail virus by different antivirus companies -- arrives in an inbox with one of several different random subject lines, such as "Mail Delivery System," "Test" or "Mail Transaction Failed." The body of the email contains an executable file and a statement such as: "The message contains Unicode characters and has been sent as a binary attachment."

"It's huge," said Vincent Gullotto, vice president of security software maker Network Associates' antivirus emergency response team. "We have it as a high-risk outbreak."

In one hour, Network Associates itself received 19,500 emails bearing the virus from 3,400 unique Internet addresses, Gullotto said. One large telecommunications company has already shut down its email gateway to stop the virus.

Once the virus infects a Windows-running PC, it installs a program that allows the computer to be controlled remotely. The program primes the PC to send data to the SCO Group's Web server, starting 1 February, a virus researcher said on the condition of anonymity.

The SCO Group has incurred the wrath of the Linux community for its claims that important pieces of the open-source operating system are covered by SCO's Unix copyrights. IBM, Novell and other Linux backers strongly dispute the claims.

The company's Web site was slow to load on Monday afternoon, a SCO spokesperson acknowledged, but the site was still accessible from the World Wide Web.

SCO's Web site was taken offline by denial-of-service attacks a handful of times in the last year, none of which had been initiated by a virus. In the past, the company has blamed Linux sympathisers for at least one of the attacks.

Antivirus companies were scrambling on Monday afternoon to learn more about the virus, which started spreading at about noon PST. The virus affects computers running Windows versions 95, 98, ME, NT, 2000 and XP.

"A lot of the information is encrypted, so we have to decrypt it," said Sharon Ruckman, a senior director of antivirus software maker Symantec's security response centre. Symantec has had about 40 reports of the virus in the first hour, a high rate of submission, Ruckman said.

The virus installs a Windows program that opens up a "back door" in the system, allowing an attacker to upload additional programs onto the compromised device. The back door also enables an intruder to route his connection through the infected computer to hide the source of an attack.

The virus also copies itself to the Kazaa download directory on PCs, on which the file-sharing program is loaded. The virus camouflages itself, using one of seven file names, including Winamp5, RootkitXP, Officecrack and Nuke2004. Variations in the body text include: "The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment."

Early data indicated an epidemic several times the size of the Sobig.F virus, which caused widespread infections last summer, said Scott Petry, a vice president of engineering at email service provider Postini.

"At its current run rate, we will trap almost 8 million in a day," Petry said. The company quarantined only 1,400 copies of Sobig.F in its first day and 3.5 million copies of the virus during that epidemic's peak 24-hour period.

Mail systems that remove executable files from emails can stop the program from spreading.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
94 out of 209 people found this useful


Full Talkback thread

1 comment

  1. If this is one of the LINUX community that is doin... Andrew Cannon

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Web Developer Needed. Bromley. PHP / My SQL / HTML / CSS 30-40K

If you are interested please call Claire Okeeffe, Huxley Associates, 02074695177. PHP Developer Needed. Bromley. My client is one of the UKs largest ...

Project Manager (Online, End-To-End Web-Site builds )

Project Manager to work for a global Media & Publishing organisation. Our client has offices world-wide and have over 300 publications and related ...

Junior Web Developer Needed. 20,000 - 25,000 Bromley PHP / MySQL

If you are interested please call Claire OKeeffe, Huxley Associates, 0207 469 5177. Junior web developer needed. Bromley. My client is one of the UKs ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment