Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

eBay worm spreads

Munir Kotadia ZDNet Australia

Published: 26 Oct 2004 11:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An email that claims to have been sent by online auction company eBay's webmaster contains a worm that attacks poorly-protected network drives

The Myfip worm was first detected more than a month ago but email security firm Messagelabs said it has noticed the worm is starting to spread. The company expects Myfip to be difficult for antivirus software to detect because it has been compressed using an uncommon packing utility.

Virus authors have a choice of different utilities to compress and encrypt their malware. Inexperienced malware coders -- 'script kiddies' -- often use one of the popular packing programs available freely on the Internet. But Messagelabs has warned that Myfip uses a packer that it has not seen before, which could indicate that the virus writer created one specially.

According to Messagelabs, "Myfip uses a packer previously unseen in email virus distribution. The use of an uncommon packer could make it more difficult for antivirus software vendors to identify and protect against the malicious code within."

Antivirus firm Symantec's Security Response site said Myfip searches an infected computer for any network directories and attempts to copy itself to those directories with a file-name "Iloveyou.txt.exe".

If the network directory is password protected, Myfip attempts to log in as the administrator using a number of common passwords, which are listed on Symantec's site.

The company reports that the worm is "easy" to remove.

Even if antivirus scanners have a problem spotting the new worm the badly worded email should make any potential victims somewhat suspicious.

Myfip arrives in an email with the subject "hi, [recipient], I'm webmaster of eBay.com, and we raise a research in our Website".

The main body of the email asks the recipient to take part in a "Multiple Item Auction" with the chance of winning a prize.

"If you're the winner of Multiple Item Auctions, you can get the following thing… 1.a notebook that worth 18000$... 2.a camara […] worth 1000$".

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
40 out of 102 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters