|
December
2004
|
|
|
|
|
|
November
2004.
|
-
W32.Sober.I[J] aka Sober.I[J]:uses its own
SMTP engine. Spreads by sending itself as email
attachment to addresses collected on the infected
computer. Email subject varies and will be in English
or German. Attachment will have a .bat, .com, .pif,
.scr, or .zip file extension. Most of the times
even a double extension.
|
|
|
|
October
2004.
|
|
|
-
W32.Mydoom.AG aka Mydoom.AG: uses its own
SMTP engine to send itself to the email addresses
that it finds on the infected computer. Also spreads
through popular peer-to-peer networks. Attachment
extension is .bat, .cmd, .com, .exe, .pif, .scr,
or .zip.
|
|
|
|
|
|
|
|
September
2004.
|
|
|
-
W32.Blakmal.C aka Nyxem.D - MyWife.C:a mass-mailing
worm. Uses its own SMTP engine to send itself to
contacts in MSN Messenger, Yahoo Pager, and addresses
found in files with .htm or .dbx extensions. Uses
Windows Media Player to mask itself. Tries to delete
security software and system files.
|
-
W32.Mydoom.T[R] aka Mydoom.T[R]: uses its
own SMTP engine to send itself to all the email
addresses that it finds. Attachment extension is
.bat, .cmd, .com, .exe, .pif, .scr, or .zip. Possible
second extension is .doc, .txt, .htm, or .html.
Drops and executes a backdoor, that listens on TCP
port 5422.
|
|
August
2004.
|
|
|
|
|
|
|
|
July
2004.
|
-
W32.Mydoom.M[O] aka Mydoom.M[O]: uses its
own SMTP engine to send itself to all the email
addresses that it finds. Attachment extension is
.bat, .cmd, .com, .exe, .pif, .scr, or .zip. Possible
second extension is .doc, .txt, .htm, or .html.
Drops and executes a backdoor, that listens on TCP
port 1034.
|
|
|
|
|
|
June
2004.
|
|
|
|
May
2004.
|
|
|
-
W32.Sober.G aka Sober .G:new variant of
W32.Sober aka Sober. Uses its own SMTP engine to
spread itself. Email sender address is spoofed,
the subject varies, and it will be in either English
or German.
|
|
|
|
|
|
|
|
April
2004.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
March
2004.
|
|
|
|
|
|
|
-
W32.Blakmal aka Nyxem - MyWife:a mass-mailing
worm. Uses its own SMTP engine to send itself to
contacts in MSN Messenger, Yahoo Pager, and addresses
found in files with .htm or .dbx extensions. Uses
Windows Media Player to mask itself. Tries to delete
security software and system files
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
February
2004.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
January
2004.
|
|
|
|
|
|
|
|
|
|
|
-
W32.Dumaru.Y aka Dumaru.Y: various threats.
Uses it's own SMTP engine for spreading, has backdoor
capacities, a keylogger and attempts to steal personal
information.
The email has the following characteristics:
Subject: Important information for you. Read it
immediately !
Attachment name: myphoto.zip
|
|
|
|
|