Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
TekSavvy
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

After Mydoom, meet Doomjuice

There’s a third Mydoom out there and it’s called Doomjuice.

Its attack program started yesterday but unlike Mydoom A, it’s not after SCO and it’s not carried by email, says F-Secure which found the first version.

Rather, it ‘infects’ machines already polluted with Mydoom.A and its sole purpose is to carry out a DDoS (Distributed Denial-of-Service) attack on microsoft.com.

“To locate machines with the backdoor open, Doomjuice scans random IP addresses by trying to connect to TCP port 3127,” says F-Secure here.

“If the port is open the worm sends itself in a specially crafted package that makes the Mydoom.A infected machine to execute the file thus infecting it with Doomjuice too.”

After penetrating the system, Doomjuice copies itself to the Windows System Directory as ‘intrenat.exe’ that’s in turn added to the registry as:

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunGremlin HKCUSOFTWAREMicrosoftWindowsCurrentVersionRunGremlin

Between February 8th and 12, “the worm will wait for up to 365 seconds,” says F-Secure. “After the 12th it will start the attack right away.

“In order to overload www.microsoft.com the worm starts 16-80 parallel threads that connect to the web site and try to download the main page in an infinite loop.

“One of Doomjuice’s payloads is that it drops the source code of Mydoom.A in a bzip2 compressed TAR archive. The file is dropped the root of all hard drives and the user’s profile directory as ’sync-src-1.00.tbz’.”

HOME

2 Responses to “After Mydoom, meet Doomjuice”

  1. Reader's Write Says:

    We’re not from Norway.

    - F-Secure

  2. Reader's Write Says:

    Our apologies. We’ve removed the offending text. p2pnet

Leave a Reply

Please no Spam, flaming (attacking others), trolling, and posting off-topic. Thanks.

    Advertisements
MP3Rocket


Remove Spyware with AntiSpyware for Windows®