PDA

Click to See Complete Forum and Search --> : **HeadsUp** Mimail.D


Und3ertak3r
November 2nd, 2003, 11:08 AM
I would recommend also reading the following thread.. Found Here (http://www.antionline.com/showthread.php?s=&threadid=250493)

This Heads up is posted due to the the severity rating being Cat 3..

This information from Symantec found Here (http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.d@mm.html)
Description:
W32.Mimail.D@mm is a variant of W32.Mimail.C@mm that spreads by email. It is packed with UPX.

The email has the following characteristics:

Subject: don't be late! [random string of letters]
Attachment: readnow.zip

Technical details: (part of)

Payload:
Large scale e-mailing: Sends email messages using its own SMTP engine
Causes system instability: Sends data to fethard.biz and fethard-finance.com in an attempt to perform a Denial Of Serivce
Distribution

Subject of email: don't be late! [random string of letters]
Name of attachment: readnow.zip
Size of attachment: 10,912


When W32.Mimail.D@mm is executed, it does the following:


Copies itself as %Windir%\cnfrm.exe.


--------------------------------------------------------------------------------
Note: %Windir% is a variable. The worm locates the Windows installation folder (by default, this is C:\Windows or C:\Winnt) and copies itself to that location.
--------------------------------------------------------------------------------


Adds the value:

"Cnfrm" = "%Windir%\cnfrm.exe"

to the registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run



AKA and Variants
W32/Mimail@mm [McAfee] W32.Mimail.A@mm, W32.Mimail.C@mm




BTW: I think I have unwittingly classified this Worm as Spam on my mail system.. .. and have manualy deleted the crud from the ISP's Server..

spools.exe
November 2nd, 2003, 05:08 PM
thanks for the heads up

Und3ertak3r
November 2nd, 2003, 10:34 PM
And another variant:

Version E: link to Symantecs info page

http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.e@mm.html

W32.Mimail.E@mm is a variant of W32.Mimail.D@mm that spreads by email. It is packed with UPX.

The email has the following characteristics:

Subject: don't be late! [random string of letters]
Attachment: readnow.zip

Cheers

gore
November 3rd, 2003, 12:36 AM
Oh no! A virii! Wait.... *looks at Boxes* Oh, there all *NIX except for one that isnt even on... *whipes forehead* Whew! That was close! Glad thats over!

lol, Yea I had too. This is just getting pathetic, is there some virii competition going on that I was not informed of? Seems to be a new one every week. And anything that makes Windows crash like these......Is usually installed by default ;) Buahahahahaha.