New MyDoom Worm Has No File, Just a URL, Exploits I.E. Hole

The Internet Patrol default featured image
Share the knowledge

The newest version of MyDoom does not even have a file attached to it, making it look even less suspect, and less worm- or virus-like.

Instead, it exploits one of the more recently discovered holes in Internet Explorer, through which clicking on a URL can cause a file to be downloaded to the unsuspecting user’s computer. Once downloaded to the user’s machine, the file executes, harvests email addresses, and starts spewing spam from the user’s computer.

The MyDoom email spam is sometimes appearing to come from PayPal, bearing a message which says “Congratulations! PayPal has successfully charged $175 to your credit card. Your order tracking number is A866DEC0, and your item will be shipped within three business days.

“To see details please click this link.”

Of course, clicking the link causes the program to be downloaded to your machine.

The Internet Patrol is completely free, and reader-supported. Your tips via CashApp, Venmo, or Paypal are appreciated! Receipts will come from ISIPP.

CashApp us Square Cash app link

Venmo us Venmo link

Paypal us Paypal link

Microsoft says that if you are using XP, and you have Service Pack 2 for XP installed, that you are at “reduced risk” (how comforting).

You can read more about this here.

Get New Internet Patrol Articles by Email!

The Internet Patrol is completely free, and reader-supported. Your tips via CashApp, Venmo, or Paypal are appreciated! Receipts will come from ISIPP.

CashApp us Square Cash app link

Venmo us Venmo link

Paypal us Paypal link

 


Share the knowledge

Leave a Reply

Your email address will not be published. Required fields are marked *

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.