Linux.com

Decoding

Posted by: interiot on January 27, 2004 08:49 AM
It's UPX-compressed, and part of the exe is rot13-encoded. It looks like it goes under one of these names when trying to spread via Kazaa:

    nuke2004, office_crack, rootkitXP,
    strip-girl-2.0bdcom_patches, activation_crack, icq2004-final, winamp5


But I'm not sure why it's spread sooo incredibly fast.

The worm includes this HTTP request header:

    GET / HTTP/1.1

    Host: www.sco.com


And sure enough, sco.com is inaccessible now. So it's not completely evil.<nobr> <wbr></nobr><tt>;)</tt>

#

Return to MyDoom virus hammering Windows systems