Advertisement
Promo

Security threats Toolkit

Microsoft next target of MyDoom

David Becker CNET News

Published: 28 Jul 2004 08:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

While the spread of the latest version of the MyDoom worm appeared to be quickly halted, the pest lived on Tuesday with a growing host of ancillary infections, including one programmed to launch a denial-of-service attack on Microsoft.

MyDoom.M, a new variant of the prolific worm, came to life on Monday and quickly wreaked havoc on Google and other search sites, thanks to a novel method the worm's creator devised to propagate the pest.

But security experts said on Tuesday that the worm was quickly dying out, with infections peaking a mere 12 hours after the worm was released.

MyDoom.M leaves behind significant potential for collateral damage from infected and unrepaired PCs, however. Besides propagating itself, the worm's main purpose apparently was to open a "back door" so that infected PCs could be used to host other malicious programs, according to researchers at security giant Symantec.

The first of those parasites, dubbed the Zindos.A worm, was released on Tuesday with the intent of crippling Microsoft's main Web site.

According to a Symantec report, Zindos.A is programmed to probe random IP addresses in search of ports left open by Zincite.A, the destructive part of the payload left by MyDoom.M. Once Zindos finds a vulnerable PC, it installs itself and promptly launches a denial-of-service attack against the Microsoft.com domain.

Zindos.A did not appear to have gained a widespread distribution as of Tuesday morning, said Vincent Weafer, senior director for Symantec's security response centre. He said Zindos appeared to be a trial bug intended to exploit MyDoom's spread. "I'd say it's an opportunistic worm from another group," rather than the MyDoom.M creator, he said.

Microsoft representatives said on Tuesday that the company was investigating Zindos and successfully fending off any attacks. "Microsoft has taken steps to ensure that Microsoft.com remains available to customers," according to a company statement. "The Microsoft.com network is stable and has been consistently accessible to customers."

But the situation presented a new and possibly dangerous trend of virus writers using one infection to prime the pump for others, Weafer said. MyDoom.M includes a mechanism to maintain a list of infected systems, permitting the worm's creator to upload new pests while preventing rival attackers from taking over infected PCs. A similar system was recently discovered in the last version of MyDoom, MyDoom.L, and may have been responsible for the fast spread of MyDoom.M, Weafer said.

"We're increasingly seeing infections like this where they're very aggressive during the initial propagation and you see a sharp drop off fairly quickly," he said.

Additionally, MyDoom represents a new trend among malicious code creators of focusing their attacks on known vulnerable PCs, allowing for more rapid and efficient propagation of new pests, Weafer said.

"There's a huge number of compromised machines sitting on the Internet at any one time," he said. "In many cases, these boxes are for hire -- they're essentially owned by the virus writers and rented out to the highest bidder."

"It's a matter of how do we reach the people who own those PCs and let them know what's going on?" Weafer added. "It's not just MyDoom -- they're wide open to anything attackers want to throw at them."

CNET News.com's Ina Fried contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
46 out of 110 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters