White Papers

Carrytone / I-Worm.Taripox.b (F-Secure)

Overview December 26, 2001

NAME: Carrytone

ALIAS: I-Worm.Taripox.b

Carrytone is a mass-mailer that uses a new technique to spread. The worm body is 40 kilobytes in size and it was written in C. It works properly on Windows NT based systems only.

For spreading it implements a simple SMTP proxy that listens on port 25 (standard SMTP port) on the infected machine. When the worm is started it fetches the SMTP server name from the user's e-mail settings then it modifies the HOSTS file so that the SMTP server's address points to the localhost where the worm is listening. This way when the user sends an e-mail his/her e-mail client will connect to the worm instead of the real mail server. After receiving the connection the worm relays all the commands and replies between the client and the real mail server until it gets the reply to SMTP DATA command that marks the beginning of the e-mail data. At this point it inserts a copy of itself into the message.

The attachment name it uses is composed from the recipient's name and a '.doc.pif' extension.

Click through to alert text for disinfection information.

Further White Paper Details
PublisherF-Secure File FormatHTML
Date PublishedDecember 2001 Downloads4
FormatWhite Papers   
Topics
    N/A
Thin clients switch on digitally excluded

Thin clients switch on digitally excluded

Case study: Digital inclusion project tackles social exclusion in Liverpool more

Renault goes multilingual

Renault goes multilingual

Case study: Translation tech turns docs into 23 languages… more


Quick Sitemap Links: