"Smart" worm slaps around net users

By Patrick Gray
04 August 2003 11:10 AM
Tags: worm, virus, computer, associates, mimail, mailer, mass, user
Yet another mass mailing worm is spreading the Internet by using social trickery to thwart security.

Virus researcher with Computer Associate's, Hamish O'Dea, told ZDNet Australia  that while the new MiMail worm is technically of the "garden variety", or no-frills, type it's still managing to sucker in a lot of users through its use of social engineering.

"It's fairly prevalent . . . it's definitely in the top five," he said.

Perhaps one of the reasons for the success of the worm is the adaptive "From" address, he says. The message appears to come from the e-mail address admin@recipient.ccc where "recipient.ccc" is the targeted user's domain name.

"The support@microsoft ones seem to work pretty well too," he said, referring to viruses that spoof an e-mail address of the software giant.

The MiMail message, with the subject of "Your Account", plus a variable string of text, tells the user that their mail account is about to expire, and asks them to read the attachment.

"It actually comes in a zip file and it's HTML," O'Dea said.

If a user extracts the HTML file from the zip file and loads it, the worm will activate by exploiting a vulnerability in Internet Explorer. It then acts as a typical mass mailer, scouring the user's system for e-mail addresses that it can use to propagate to.

O'Dea understands why some people have been fooled by the trickery. After all, HTML is a normal file format for a message. "I get more amazed by people opening executables that claim to be pictures," he said.

He says it's definitely one of the smartest viruses out there.

The numbers confirm it. Mail filtering company MessageLabs has intercepted over 38,000 copies of the worm, however O'Dea says it should melt away fairly quickly.

"It's not going to hang around like Klez or something like that," he said.

Advertisement

Talkback 1 comments

    Yet another virus that doesn't ...Anonymous -- 12/08/03

    Yet another virus that doesn't affect Macs. You get what you pay for......

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured