SYMBOLCOMMON_NAMEaka. SYNONYMS
win.mydoom (Back to overview)

MyDoom

aka: Novarg, Mimail
VTCollection    

When executed, the worm opens up Windows' Notepad with garbage data in it. When spreading, the infectious email used to distribute the worm copies use variable subjects, bodies and attachment names.

The worm encrypts most of the strings in it's UPX-packed body with ROT13 method, i.e. the characters are rotated 13 locations to the right in the abecedary, starting from the beginning if the position is beyond the last letter.

Mydoom also performs a Distributed Denial-of-Service attack on www.sco.com. This attack starts on 1st of February.

The worm opens up a backdoor to infected computers. This is done by planting a new SHIMGAPI.DLL file to system32 directory and launching it as a child process of EXPLORER.EXE.

Mydoom is programmed to stop spreading on February 12th.

References
2025-05-01 ⋅ cocomelonc ⋅ cocomelonc
Malware development trick 46: simple Windows keylogger. Simple C example.
MyDoom Nokki RokRAT
2020-02-19 ⋅ Lexfo ⋅ Lexfo
The Lazarus Constellation A study on North Korean malware
FastCash AppleJeus BADCALL Bankshot Brambul Dtrack Duuzer DYEPACK ELECTRICFISH HARDRAIN Hermes HOPLIGHT Joanap KEYMARBLE Kimsuky MimiKatz MyDoom NACHOCHEESE NavRAT PowerRatankba RokRAT Sierra(Alfa,Bravo, ...) Volgmer WannaCryptor
2018-12-19 ⋅ Malware Traffic Analysis ⋅ Brad Duncan
MALSPAM PUSHING THE MYDOOM WORM IS STILL A THING
MyDoom
2004-04-15 ⋅ SANS GIAC ⋅ Matt Goldencrown
MyDoom is Your Doom: An Analysis of the MyDoom Virus
MyDoom
2004-01-30 ⋅ Applied Watch Technologies ⋅ Eric S. Hines
MyDoom.B Worm Analysis
MyDoom
2004-01-01 ⋅ GIAC ⋅ Srinivas Ganti
MyDoom and its backdoor
MyDoom
Yara Rules
[TLP:WHITE] win_mydoom_auto (20260917 | Detects win.mydoom.)
rule win_mydoom_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.mydoom."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.mydoom"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { ba00000000 84c0 0f84b1000000 0fbec3 }
            // n = 4, score = 100
            //   ba00000000           | mov                 edx, 0
            //   84c0                 | test                al, al
            //   0f84b1000000         | je                  0xb7
            //   0fbec3               | movsx               eax, bl

        $sequence_1 = { ba00000000 85c0 0f84ac000000 8d8538ffffff 89442404 c70424???????? e8???????? }
            // n = 7, score = 100
            //   ba00000000           | mov                 edx, 0
            //   85c0                 | test                eax, eax
            //   0f84ac000000         | je                  0xb2
            //   8d8538ffffff         | lea                 eax, [ebp - 0xc8]
            //   89442404             | mov                 dword ptr [esp + 4], eax
            //   c70424????????       |                     
            //   e8????????           |                     

        $sequence_2 = { c745d805040003 0fb645d7 8845ec c744240805000000 8d45d8 89442404 893424 }
            // n = 7, score = 100
            //   c745d805040003       | mov                 dword ptr [ebp - 0x28], 0x3000405
            //   0fb645d7             | movzx               eax, byte ptr [ebp - 0x29]
            //   8845ec               | mov                 byte ptr [ebp - 0x14], al
            //   c744240805000000     | mov                 dword ptr [esp + 8], 5
            //   8d45d8               | lea                 eax, [ebp - 0x28]
            //   89442404             | mov                 dword ptr [esp + 4], eax
            //   893424               | mov                 dword ptr [esp], esi

        $sequence_3 = { 74ef 84db 7ff1 0fbe45f3 c1e008 }
            // n = 5, score = 100
            //   74ef                 | je                  0xfffffff1
            //   84db                 | test                bl, bl
            //   7ff1                 | jg                  0xfffffff3
            //   0fbe45f3             | movsx               eax, byte ptr [ebp - 0xd]
            //   c1e008               | shl                 eax, 8

        $sequence_4 = { b800000000 e9???????? 8b830c040000 800801 c744240402000000 8b4304 }
            // n = 6, score = 100
            //   b800000000           | mov                 eax, 0
            //   e9????????           |                     
            //   8b830c040000         | mov                 eax, dword ptr [ebx + 0x40c]
            //   800801               | or                  byte ptr [eax], 1
            //   c744240402000000     | mov                 dword ptr [esp + 4], 2
            //   8b4304               | mov                 eax, dword ptr [ebx + 4]

        $sequence_5 = { 57 48 f2ae 55 ff967cb00000 }
            // n = 5, score = 100
            //   57                   | push                edi
            //   48                   | dec                 eax
            //   f2ae                 | repne scasb         al, byte ptr es:[edi]
            //   55                   | push                ebp
            //   ff967cb00000         | call                dword ptr [esi + 0xb07c]

        $sequence_6 = { 891424 e8???????? 31d2 8915???????? }
            // n = 4, score = 100
            //   891424               | mov                 dword ptr [esp], edx
            //   e8????????           |                     
            //   31d2                 | xor                 edx, edx
            //   8915????????         |                     

        $sequence_7 = { c20c00 c7042480000000 e8???????? a3???????? 85c0 }
            // n = 5, score = 100
            //   c20c00               | ret                 0xc
            //   c7042480000000       | mov                 dword ptr [esp], 0x80
            //   e8????????           |                     
            //   a3????????           |                     
            //   85c0                 | test                eax, eax

        $sequence_8 = { 8b4518 89442404 893424 e8???????? ba00000000 e9???????? 8b420c }
            // n = 7, score = 100
            //   8b4518               | mov                 eax, dword ptr [ebp + 0x18]
            //   89442404             | mov                 dword ptr [esp + 4], eax
            //   893424               | mov                 dword ptr [esp], esi
            //   e8????????           |                     
            //   ba00000000           | mov                 edx, 0
            //   e9????????           |                     
            //   8b420c               | mov                 eax, dword ptr [edx + 0xc]

        $sequence_9 = { 85d0 7547 85f6 750c 8b0d???????? 85c9 7546 }
            // n = 7, score = 100
            //   85d0                 | test                eax, edx
            //   7547                 | jne                 0x49
            //   85f6                 | test                esi, esi
            //   750c                 | jne                 0xe
            //   8b0d????????         |                     
            //   85c9                 | test                ecx, ecx
            //   7546                 | jne                 0x48

    condition:
        7 of them and filesize < 114688
}
Download all Yara Rules