Main Menu
Home
Bookmark
Contact Us



 
I-Worm.Mimail. Viruses Information

Name: I-Worm.Mimail.
Category: Viruses
Description: Details
I-Worm.Mimail.a
Mimail.a is an internet worm spreading via infected emails. The worm itself is a Windows PE EXE file about 12KB is size when compressed by UPX, the decompressed size is about 30KB.
Infected messages contain the following text:
From: admin@%fake email address%
where %fake email address% is different every time.
Subject: your account %rnd str%
where %rnd str% is different every time.
Body:
Hello there,

I would like to inform you about important information regarding your email address. This email address will be expiring.
Please read attachment for details.

---
Best regards, Administrator
---
Attach: message.zip
The attached ZIP archive contains the "message.html" file. When opened this HTML file drops the FOO.EXE file (worm copy) into the "Downloaded Program Files" directory and runs it. To drop and execute this EXE file the worm exploits a vulnerability in Internet Explorer. This allows a Java script in the HTML file to get access to disk files without any prompts or warning messages.


Installation
During installation the worm copies itself to the Windows directory under the name "videodrv.exe" and registers this file in the system registry autorun key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
VideoDriver = %WinDir%videodrv.exe
The worm also creates the following files in the Windows directory:
exe.tmp - worm in HTML file
zip.tmp - worm's HTML file in ZIP archive (method "stored" - no compression).
eml.tmp - list of emails found on infected machine
To create ZIP archives the worm uses its own ZIP file format supporting routine.


Spreading
To send out infected messages the worm uses a built in SMTP engine.
To get victim email addresses the worm opens files in "Shell Folders" and "Program Files" and scans them for email-like text strings.
Other
The Mimail worm looks for the "e-gold" managing application (electronic currency, see http://www.e-gold.com), grabs information from the application form/window and stores this data in the c:tmpe.tmp" file. This file is then sent to four email addresses that belong to the worm's author.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Backdoor.SdBot.ge
ADI.143
Macro.Word.Tele-Se
VLAD.MonAmi.99
Bailey.27
Trojan.PKZ300
Macro.Word.Epidemi
Trojan-PSW.Win32.Lineage.b
Win95.S
HLLP.Tomsk.850


 


© 2006-2008 spyware32.com - Privacy Policy