Newsletter:

Skip Navigation LinksHome > News > Security > Mydoom, MiMail viruses on the loose

Mydoom, MiMail viruses on the loose

By Byron Connolly
27 January 2004 12:00AM
Tags: mydoom | mimail | viruses | loose

A fresh global virus dubbed Mydoom was discovered at 8am Tuesday morning in the United States, and two Australian companies have already reported outbreaks, according to security outfit McAfee.

Managed email security services outfit MessageLabs had also warned of the latest Mimail variant, Mimail Q, which was intercepted on Sunday 26 January.

MessageLabs too, said it had intercepted over 165,000 copies of the Mydoom viruses within the first few hours of its breaking.

McAfee, which claimed to have first discovered the Mydoom virus, said the mass mailer landed in a user's inbox with EXE, CMD, PIF, ZIP or SCR attachments.

Once the user opened the attachment, the virus would send out thousands of emails, clogging and slowing down corporate networks in the process, according to Allan Bell, Asia-Pacific marketing director at McAfee.

“Mydoom is a mass mailer as most of the outbreaks have been. It generates traffic faster than Sobig. Because it generates mail faster than Sobig, the danger is it could be a bigger attack than Sobig,” he said.

The virus includes its own mail engine which generates the mail, he said.

“Like Sobig, it spoofs the email addresses which make it difficult to work out who the person was who was [originally] infected,” he said.

At 11am this morning, there were some reports of infections at some organisations in Australia, he said.

MessageLabs had also found that once harvesting addresses from infection machines, Mydoom targeted files with WAB, ADB, TBB, DBX, ASP, PHP, SHT, HTM and TXT extensions.

MessageLabs said Mimail.Q was a polymorphic mass mailing worm that spread by harvesting email addresses from infected machines. It then used an SMTP engine to send itself to addresses found, the company said.

A polymorphic virus changed slightly with each infection, according to the company. It was being sent from several locations including the US, UK and Australia.

McAfee's Bell stressed that companies needed more than just anti-virus software to protect themselves from these threats, which were getting more sophisticated.

Desktop firewalls would prevent a viruses' mailing engine from generating traffic out of a single machine and clogging up a corporate network, he said.

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 






Product Reviews

Star Rating
Safend Protector is an offering that is less of a suite of products and more of a unified application.
Star Rating
Blink is an endpoint security product that functions as a network protector.
Star Rating
EndPointSecurity installs a small footprint agent on the machine.
Star Rating
GuardianEdge Device Control is a component of the more robust GuardianEdge Data Protection Platform.
Star Rating
Lumension offers a pair of products, Sanctuary Application Control and Sanctuary Device Control, that work in...
Product Reviews now available on iTnews.com.au

TopTopics
(3039) -  microsoft
(3037) -  telstra
(2098) -  network
(1937) -  broadband
(1739) -  apple
(1667) -  security
(1547) -  mobile
(1121) -  data
(1117) -  internet
(1110) -  blackberry
(1067) -  intel
(989) -  ibm
(981) -  researchers
(854) -  windows
(848) -  vmware