ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

New Mydoom variants now called Bofra

highMalwareimportance 42
Full article187 words · extracted from securelist.com · click to collapse

Research

Research

10 Nov 2004

minute read

I-Worm.Mydoom.ad, which we detected yesterday, and its modification Mydoom.ae, which we detected today, have both been renamed in our antivirus databases as I-Worm.Bofra.a and .b.

These worms used the source code of Mydoom, but most virus analysts agree that they are actually a new family. And we agree with this opinion.

  • I-Worm.Mydoom.ad is renamed as I-Worm.Bofra.b
  • I-Worm.Mydoom.ae is renamed as I-Worm.Bofra.a

P.S. We have just detected another modification of this worm, which will be named I-Worm.Bofra.c.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-mydoom-variants-now-called-bofra/29883/