Threat Description



Category: Malware
Platform: W32
Aliases: Mabutu, I-Worm.Mabutu.a, W32.Mota.A@mm


Mabutu is a mass-mailing worm which spreads in short and simple emails with infected attachments.

Mabutu comes with an IRC-controlled backdoor component.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

Mabutu arrives in a UPX-packed dropper with the main component as a DLL inside. The main DLL is 49152 bytes in size and is not packed.

System Infection

Upon execution Mabutu copies itself to the Windows Directory as [random character] TWAIN.EXE and drops a DLL, which is the body, as [random character] TWAIN.DLL. The DLL file is added to the registry as

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]  "winupdt" = "%WindowsDir%\RUNDLL32.EXE [random character] TWAIN.DLL,_mainRD"  

%WindowsDir% represents the Windows folder name, for example C:\Windows on Windows XP systems.

Mabutu keeps its configuration data in an scrambled data file called cfg.dat in the Windows Directory.

Email Propagation

Mabutu collects email addresses from various places. It checks Windows Address Book, MSN Messenger Buddy list, Outlook Express mailboxes and files with the following extensions: .WAB, .HTM, .HTML, .TXT

Using its own SMTP engine Mabutu sends infected messages to the collected addresses.

Subject is one of:

Hi  Hello  Important  Hello  I'm in love  Sex  Wet girls  I'm nude  Fetishes  gutted  Ok cunt  

Attachment names:

britney  jenifer  photo  creme_de_gruyere  

with extensions .{JPG|TXT}[lots of spaces] .SCR or .ZIP.

The message body is either a file path, collected from Kazaa Shared Folder and My Document folders, or one of the following strings:

the_details  the_document  the_message  

The mailing routine tests if there is connection to the Internet by connecting to If the user has a screen saver the worm waits until it starts then it activates its mass-mailing code.


The payload in Mabutu is an IRC-controlled backdoor. The backdoor connects to one of the many predefined IRC servers and after joining a channel it awaits for commands from its creator. Using these commands the attacker can get information from the worm (eg. number of sent infected emails, OS version, etc) and remotely start the mass-mailing routine.

Mabutu has the capability to update itself by downloading and activating a DLL from a predefined web location.


Detection for this malware was published on July 27th, 2004 in the following F-Secure Anti-Virus updates:

Detection Type: PC
Database: 2004-07-27_01

Description Details: Katrin Tocheva, July 29th, 2004
Technical Details:Gergely Erdelyi, July 29th, 2004


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More