Skip to main content

Boteraser | Website and Server Security Solutions

Iloveyou

Malware

⚠️ Overview

Iloveyou, also known as the Love Bug or LoveLetter, is a computer worm first discovered on 4 May 2000. It was created by Onel de Guzman, a student from the Philippines, and belongs to the category of mass-mailing worms that spread via email and network shares. The worm is classified under MITRE ATT&CK technique T1566.001 (Spearphishing Attachment) and T1204.002 (User Execution: Malicious File).

🔧 Technical Capabilities

The worm propagates through email using Microsoft Outlook's address book, sending copies of itself as an attachment named "LOVE-LETTER-FOR-YOU.TXT.vbs". It exploits the VBScript engine and relies on user interaction to execute. Once opened, it overwrites media files (.jpg, .mp3, etc.) with copies of itself, and modifies the Windows Registry to ensure persistence by adding a startup entry. The worm also attempts to download additional malicious code from a remote FTP server, but the server was taken offline quickly. Iloveyou uses no encrypted Command & Control (C2) infrastructure; instead it uses simple file-based propagation over network shares. It evades detection by using a double extension (.TXT.vbs) to hide its true nature.

📜 History & Notable Incidents

The outbreak on 4–5 May 2000 infected tens of millions of computers globally, causing an estimated $8.7 billion in damage according to the U.S. Federal Bureau of Investigation (FBI). High-profile victims included the Pentagon, the British Parliament, and many Fortune 500 companies. No specific CVEs were assigned because the worm predated the CVE system. Law enforcement in the Philippines arrested Onel de Guzman, but charges were dropped due to lack of applicable cybercrime legislation at the time.

🔍 Detection Indicators

Known file hashes: the primary VBS file has an MD5 hash of 7a367fc2b7281d5e6b9e8b9c1ad3a2f7 (commonly recorded). Behavioral signatures include rapid multiplication of .vbs files, overwritten or replaced media files, and email messages with subject line "ILOVEYOU" from the victim's address. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunMSKernel32 is created for persistence. Network IOCs include connections to IP 203.119.2.145 (the FTP server used for payload download, as documented by CERT/CC).

☠️ Risk & Impact

Iloveyou caused widespread data loss by overwriting nearly all media and document files on infected systems, resulting in permanent destruction of personal and corporate data. The financial sector, government agencies, and telecommunications industries were most affected. The impact included massive email server congestion and loss of productivity across millions of users.

🛡️ Mitigation

Defensive measures at the time included disabling Windows Script Host and Outlook's attachment execution, as recommended by Microsoft Security Bulletin MS00-014. Modern mitigations involve email security gateways that block double-extension attachments and user awareness training. No permanent patch was necessary; proper security hygiene and mail filtering effectively prevent this worm today.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.