Netskope Threat Labs

Mydoom

ATP Sandbox Adv. HeuristicsAV

Mydoom is a mass mailing worm from 2004 whose emails used variable subjects, bodies, and attachment names to slip past users scanning their inboxes. When executed it opened Windows Notepad filled with garbage data, and its packed body encrypted its strings with ROT13 to hinder analysis. The worm opened a backdoor on infected machines by planting a DLL and launching it as a child process of Explorer, and it launched a denial of service attack against www.sco.com, with its spreading designed to stop on February 12.

First seen
May 2022
Last seen
October 2026
MyDoom
Alert Name
Dropped:Generic.Mydoom.2A762AA6
Dropped:Generic.Mydoom.4F321279
Dropped:Generic.Mydoom.5713DF4B
Dropped:Generic.Mydoom.9714A2F5
Dropped:Generic.Mydoom.A5D45570
Dropped:Generic.Mydoom.B01D51E3
Dropped:Generic.Mydoom.E6ED4AFA
Dropped:Generic.Mydoom.FA2A3036
Dropped:Win32.Mydoom.3.Gen@mm
Dump:Win32.Mydoom.L@mm