Skip to main content

Worm:W32/Mytob.A

Classification

Category:

Malware

Type:

Worm

Aliases:

  • Worm:W32/Mytob.A

Summary

Worm:W32/Mytob.A is a worm that has functionality similar to the MyDoom worm family functionality. This worm includes code to spread over a network by exploiting the known LSASS vulnerability.

Removal

Technical Details

In addition to propagating, Mytob.A is also able to function as an IRC bot.

The worm is a PE executable file 42512 bytes long, packed with FSG file compressor.

Installation

When run, the worm copies under %SYSTEM% directory using the name 'msnmsgr.exe' and creates a mutex named 'D66'.

It will then alters the registry entries to ensure that it gets started when a user logs on or the system is restarted:

  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
  • [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  • [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
  • [HKCU\SYSTEM\CurrentControlSet\Control\Lsa] "MSN" = "msnmsgr.exe"

Payload

The worm tries to connect to an IRC channel at a predefined address using TCP port 6667. An attacker who knows channel password can instruct the created bot to execute the following actions:

  • Request worm uptime
  • Request worm version
  • Shutdown worm
  • Download and execute files
  • Delete files
  • Update worm

Propagation (email)

The worm spreads by sending its infected attachment to email addresses found on an infected computer. email addresses are harvested from Windows Address Book (WAB) and from files with the following extensions:

  • htm
  • sht
  • php
  • asp
  • dbx
  • tbb
  • adb
  • wab
  • pl

The worm avoids sending emails to email addresses that contain any of the following substrings:

  • accoun
  • acketst
  • admin
  • anyone
  • arin.
  • be_loyal
  • berkeley
  • borlan
  • bugs
  • certific
  • contact
  • .edu
  • example
  • feste
  • fido
  • foo.
  • fsf.
  • gold-certs
  • google
  • .gov
  • gov.
  • help
  • hotmail
  • iana
  • ibm.com
  • icrosof
  • icrosoft
  • ietf
  • info
  • inpris
  • isc.o
  • isi.e
  • kernel
  • linux
  • listserv
  • math
  • .mil
  • mit.e
  • mozilla
  • msn.
  • mydomai
  • nobody
  • nodomai
  • noone
  • nothing
  • ntivi
  • page
  • panda
  • postmaster
  • privacy
  • rating
  • rfc-ed
  • ripe.
  • root
  • ruslis
  • samples
  • secur
  • sendmail
  • service
  • site
  • soft
  • somebody
  • someone
  • sopho
  • submit
  • support
  • syma
  • tanford.e
  • the.bat
  • unix
  • usenet
  • utgers.ed
  • webmaster
  • your

The email message is composed from randomly chosen subject line, body text and additional parts. The worm has a selection of attachment names that it uses for its attachment. The subject of infected emails is selected from the following variants:

  • Error
  • Status
  • Server Report
  • Mail Transaction Failed
  • Mail Delivery System
  • hello
  • hi

The attachment name is composed using the following predefined keywords:

  • body
  • message
  • test
  • data
  • file
  • text
  • doc

The extension for the filename can be one of the following:

  • bat
  • cmd
  • exe
  • scr
  • pif

For example:

  • body.scr

Propagation (Exploit)

The worm spreads to remote computers using LSASS vulnerability. It contacts remote computers on TCP port 445, exploits the vulnerability and copies its file to a remote system.

Variants

Mytob.B is a minor variant of Mytob.A that includes functionality from the MyDoom family of email worms and IRC-bots.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.