Suvarna Garge (Editor)

Nimda

Updated on
Edit
Like
Comment
Share on FacebookTweet on TwitterShare on LinkedInShare on Reddit
Type
  
Multi-vector worm

Operating system(s) affected
  
Windows 95 – XP

Point of origin
  
China (alleged)

Written in
  
C++

Nimda httpsiytimgcomvi6PY4eQLTGTUhqdefaultjpg

Technical name
  
Avast: Win32:Nimda Avira: W32/Nimda.eml BitDefender: Win32.Nimda.A@mm ClamAV: W32.Nimda.eml Eset: Win32/Nimda.A Grisoft: I-Worm/Nimda Kaspersky: Net-Worm.Win32.Nimda or I-Worm.Nimda McAfee: Exploit-MIME.gen.ex Sophos: W32/Nimda-A Symantec: W32.Nimda.A@mm

Author(s)
  
Multiple authors; one serving prison time

Nimda dozrastelmi dialogue baahubali telugu prabhas rana anushka tamannaah


Nimda is a file infecting computer worm. It quickly spread, surpassing the economic damage caused by previous outbreaks such as Code Red. Nimda utilized several types of propagation techniques and this caused it to become the Internet’s most widespread virus/worm within 22 minutes.

Contents

The worm was released on September 18, 2001. Due to the release date, exactly one week after the attacks on the World Trade Center and Pentagon, some media quickly began speculating a link between the virus and Al Qaeda, though this theory ended up proving unfounded.

Nimda affected both user workstations (clients) running Windows 95, 98, NT, 2000 or XP and servers running Windows NT and 2000.

The worm's name origin comes from the reversed spelling of "admin".

F-Secure found the text "Concept Virus(CV) V.5, Copyright(C)2001 R.P.China" in the Nimda code, suggesting its country of origin.

Nimda decapitation machine 1440p


Methods of infection

Nimda was so effective partially because it—unlike other infamous malware like the Morris worm or Code Red—uses five different infection vectors:

  • Email
  • Open network shares
  • Browsing of compromised web sites
  • exploitation of various Internet Information Services (IIS) 4.0 / 5.0 directory traversal vulnerabilities. (Both Code Red and Nimda were hugely successful exploiting well known and long solved vulnerabilities in the Microsoft IIS Server.)
  • Back doors left behind by the "Code Red II" and "sadmind/IIS" worms.
  • References

    Nimda Wikipedia