This new virus has been declared as MEDIUM RISK by Secunia. TrendLabs has declared a Medium risk alert in order to control this new WORM_MYTOB variant that is currently spreading in Australia and Japan.
It uses a social engineering approach where there appears to be administrative or non-delivery issues associated with email message processing. On all non-delivery messages, it's always important to never open attachments, even if it appears to be from someone you know or yourself.
MyDoom.BQ - Symantec
MEDIUM RISK at Secunia
MyTob.ED - Medium Risk Trend Micro
Diagram on how this worm spreads & potential to impact network
Email messages to block or avoid:
Subject: (any of the following)
- *IMPORTANT* Please Validate Your Email Account
- *IMPORTANT* Your Account Has Been Locked
- {random}
- Email Account Suspension
- Notice: **Last Warning**
- Notice:***Your email account will be suspended***
- Security measures
- Your email account access is restricted
- Your Email Account is Suspended For Security Reasons
Message body: (any of the following)
- Account Information Are Attached!
- Once you have completed the form in the attached file , your account records will not be interrupted and will continue as normal.
- please look at attached document.
- To safeguard your email account from possible termination, please see the attached file.
- To unblock your email account acces, please see the attachement.
- We have suspended some of your email services, to resolve the problem you should read the attached document.
- {random}
Attachment: (any of the following file names)
- {random}
- document_full
- email-doc
- email-info
- email-text
- IMPORTANT
- information
- info-text
- your_details
(any of the following extensions)
- BAT
- CMD
- EXE
- PIF
- SCR
- ZIP