BleepingComputer.com: MS04-011: MYTOB.AR - New MEDIUM RISK version

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

MS04-011: MYTOB.AR - New MEDIUM RISK version Be careful with "non-delivery" email

#1 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

  Posted 30 May 2005 - 05:36 PM

Trend and Secunia Virus Information have issued MEDIUM RISK alerts for MYTOB.AR

Click these urls below for more information:

MYTOB.AR - Secunia alert MEDIUM RISK

TREND MICRO - MEDIUM RISK

MYTOB.CU - Symantec

W32/Mytob.bh - McAfee (DAT 4502)

Quote

As of May 30, 2005 3:08 AM (PDT/GMT-7:00), TrendLabs has declared a MEDIUM risk alert in order to control the spread of WORM_MYTOB.AR. TrendLabs has received several infection reports indicating that this worm is currently spreading in Australia, China, Hongkong, India, Japan, Korea, Philippines, Taiwan, and the United States.

Similar to other MYTOB variants, this memory-resident worm propagates by sending a copy of itself as an attachment (file size is around 29,868 to 29,882 bytes) to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.


Quote

Subject: (any of the following)
• {Random}
• *DETECTED* Online User Violation
• *IMPORTANT* Please Validate Your Email Account
• *IMPORTANT* Your Account Has Been Locked
• *WARNING* Your Email Account Will Be Closed
• Account Alert
• Email Account Suspension
• Important Notification
• Notice of account limitation
• Notice: **Last Warning**
• Notice:***Your email account will be suspended***
• Security measures
• Your email account access is restricted
• Your Email Account is Suspended For Security Reasons

Attachment: (any combination of the following file names and extension names)

File name:
• {random}
• account-details
• document
• document_full
• email-doc
• email-info
• info
• information
• info-text
• instructions
• your_details

Extension name:
• BAT
• CMD
• EXE
• PIF
• SCR
• ZIP

This post has been edited by harrywaldron: 30 May 2005 - 05:37 PM


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users