What Was Mydoom? Still the Fastest, Twenty-Two Years On
Subject: Error. Or Mail Delivery System. Or Mail Transaction Failed. Body: The message contains Unicode characters and has been sent as a binary attachment. Or: Mail transaction failed. Partial message is available. Attachment: a zip, or a file with two extensions, the second one .exe, .scr, .pif or .cmd.
It looked like a bounce. Everyone had seen a thousand bounces. Everyone opened it.
That was 26 January 2004, a Monday. By the end of the day it was the fastest-spreading email worm ever recorded, and it still is.
What was Mydoom?
A Windows email worm, also catalogued as Novarg and Shimgapi, that arrived as an attachment, harvested every email address it could find on the machine, and mailed itself to all of them from a forged sender. It also copied itself into the shared folder of the KaZaA file-sharing client under names like winamp5 and office_crack, for anyone who preferred to download their infection.
It did three other things, and each of them is worth more than the spreading:
- It opened a backdoor on TCP port 3127 (and the range up to 3198) that accepted and ran uploaded executables. This stayed open after the worm stopped mailing.
- It carried a date. From 1 February 2004, every infected machine was to begin a denial-of-service flood against
www.sco.com. The B variant, three days behind, addedwww.microsoft.comfor 3 February. - It skipped addresses. Anything at a university, at Microsoft, at the antivirus vendors, at certain government domains, was deliberately left off the send list.
That last one is the tell. Whoever wrote it did not want the people who could analyse it to receive a copy. This was not a teenager's science project.
How fast
The number usually quoted is that at its peak one in every ten, or one in every twelve, emails in the world carried Mydoom, depending on which filtering company's figure you take. MessageLabs, which saw the traffic across its customer base, reported 1.8 million intercepted copies in 168 countries within two days. Some estimates put it at a quarter of all email traffic on the worst day.
The two figures are not the same measurement, which is why they differ. One is a proportion of all messages passing a filter; the other is a count of infected messages stopped by one company. Neither is a count of infected machines, which nobody has. What is not disputed is the rank: it beat Sobig from the previous August and ILOVEYOU from 2000, and no email worm since has beaten it. Twenty-two years, and the record stands.
Why nothing has beaten it
Not because nobody tried. The spring of 2004 was the busiest season in the history of email worms: Bagle and Netsky and Mydoom's own variants fighting each other for the same machines, with the Netsky and Bagle authors leaving insults for each other in the code. Sasser followed in May. Every one of them was fast. None of them was as fast as the first Mydoom, and after 2004 the conditions that made it possible went away.
Mail providers started stripping executable attachments by default. Desktop antivirus started updating hourly instead of weekly. Windows XP Service Pack 2 shipped that August with the firewall on. And the people writing malware for money worked out that a worm which makes the news is a worm that gets cleaned up, and moved to quieter methods. The record stands partly because Mydoom was good and partly because the sport was discontinued.
The target
SCO Group was, in early 2004, suing IBM over claims that Linux contained SCO's Unix code, and threatening Linux users with licence fees. It was the least popular company in the open-source world by a wide margin. So when the worm's payload turned out to be a DDoS against sco.com, the first theory was the obvious one: a Linux partisan had written it.
SCO put up $250,000 on 27 January for information leading to the author's arrest. Microsoft, after the B variant added its own site, matched it on the 29th. On 1 February, sco.com went offline and stayed offline; SCO moved its site to a new address rather than fight it. Microsoft's site, with rather more infrastructure behind it, stayed up.
Neither reward was ever paid.
The B variant, and the hosts file
Mydoom.B, which appeared on 28 January, did one thing the first version had not: it rewrote the machine's hosts file so that the addresses of the antivirus companies, Microsoft's update servers and a list of security sites resolved to nothing. An infected machine could not fetch the tool that would clean it. It was a small change and it was the beginning of a habit; blocking the cure became standard in the malware that followed.
B spread far less than A, because by then everyone was looking. It did not need to. The machines A had already taken were still listening on port 3127.
Nothing personal
Inside the binary was a string that was not displayed to anyone and served no function:
sync-1.01; andy; I'm just doing my job, nothing personal, sorry
It is the reason the Linux-partisan theory did not last. A worm written from conviction does not apologise. A worm written for hire might, and the more people looked at Mydoom the more it looked like a job. The backdoor on port 3127 turned every infected machine into an open spam relay, and within weeks the relays were being sold. The SCO attack could have been the point, or it could have been a headline to hide the point under. The consensus that formed, and has never been overturned, is that Mydoom was built by professionals in the Russian-speaking spam business, and that the DDoS was the part meant to be noticed.
Nobody knows who Andy is. Nobody has ever been charged.
It stopped when it said it would
Mydoom.A stopped mailing itself on 12 February 2004, as coded. The B variant ran to 1 March. The backdoors did not close; there was no instruction telling them to, and for months afterward any machine that had not been cleaned was a port 3127 listener waiting for someone with an executable and an IP list.
Someone came. Doomjuice appeared on 9 February and spread purely through those backdoors, needing no email at all. It also did something no worm had done before: it dropped a copy of Mydoom's source code onto every machine it infected. Whether that was a gift to the next author or an attempt to make prosecution impossible by putting the source in ten thousand places, nobody has said.
The famous damage figure, $38 billion, comes from mi2g, a consultancy whose estimates were produced by a proprietary model and were disputed at the time by nearly everyone who was asked. It is repeated because it is large. It should be read as a number someone published, not as a number anyone measured.
It was polite about it. That is the part that does not sit right.
Further reading
- F-Secure — Mydoom virus description and the January 2004 weblog entries, the contemporaneous analysis.
- Symantec Security Response — W32.Mydoom.A@mm writeup, January 2004.
- CERT Coordination Center — Incident Note IN-2004-01: W32/Novarg.A Virus, 30 January 2004.
- MessageLabs — intelligence reports, January and February 2004.
- Robert Lemos, CNET — MyDoom virus declared worst ever, 28 January 2004.
EXHIBIT 0030 — MYDOOM
We put it on a shirt. A brass pneumatic mail-tube station, drawn as an engraving, door swung open, one carrier capsule emerging with a paper tag tied to it. On the tag, in typewriter lettering: andy; I'm just doing my job, nothing personal, sorry.
Callouts: STILL THE FASTEST ON RECORD. IT LEFT PORT 3127 OPEN. SCO.COM, 1 FEBRUARY. SUBJECT: MAIL DELIVERY SYSTEM.
Nothing personal. It said so in the code.
That's the whole idea.