1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Sneaky virus poses as email from sysadmin

Discussion in 'News' started by Phil, Aug 4, 2003.

  1. Phil
    Honorary Member

    Phil Gigabyte Poster

    One of the sneakiest viruses to date began spreading rapidly across the Internet this weekend.

    Mimail, which poses as an email from a potential victim's own sysadmin or ISP, suggests that a user's email account is about to expire.

    Potential victims are urge to open an attachment message.zip, containing a copy of the virus.

    Users who unzip the file find another innocent-looking HTML file inside, named 'message.html'.

    This file contains an embedded EXE file, when opened in vulnerable versions of Internet Explorer, will drop an executable named foo.exe and run it. More information on the IE MHTML vulnerability used here can be found in an April 2003 advisory by Microsoft.

    rest of story
    Certifications: MCSE:M & S MCSA:M CCNA CNA
    WIP: 2003 Upgrade, CCNA Upgrade


    Share This Page