ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mimail worm tops virus chart

Ina Fried CNET News.com

Published: 04 Aug 2003 08:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new Windows mass-mailing virus, which disguises itself as a file sent by a computer user's network administrator, began infecting systems on Friday and quickly rose to the top of the virus charts on Monday.

The worm, which is being dubbed "Mimail", attempts to exploit a vulnerability in Internet Explorer that allows a script to be executed by an infected computer. The worm then tries to use that script to mass email itself, potentially clogging mail servers or slowing down networks, according to antivirus company Symantec.

The worm spread widely on Friday, with the bulk of messages affecting computers in the US, according to data from UK email provider MessageLabs. The firm bases its figures on the number of copies of the worm stopped by its customers' email servers around the world. On Friday, MessageLabs stopped more than 25,000 copies of Mimail, and after an expected drop-off over the weekend, collected more than 10,000 copies by 13:00 BST on Monday. These figures put Mimail at the top of MessageLabs' virus charts, ahead of Klez and Yaha.

The arrival of Mimail comes amid heightened fears that a large-scale attack on the Internet could be looming. The US federal government warned this week that a widespread flaw in Windows could be used to generate an attack.

The email that carries the worm has "your account" in the subject line, according to Symantec, and the body reads, "Hello there, I would like to inform you about important information regarding your email address. This email address will be expiring. Please read attachment for details."

It is then signed "Best regards, Administrator" and contains an attachment labeled "message.zip" that carries the malicious code.

In its method, the mimail bug is somewhat similar to other mass-mailing worms, said Sharon Ruckman, a senior director at Symantec Security Response. What's trickier than usual, she said, is the way the email that carriesthe worm tries to get people to open the attachment.

"The social engineering aspect (is) a lot more serious," Ruckman said. "You believe it was the administrator from your own domain, whether that is your company or your ISP."

Also of note, Ruckman said, is that the mass emailing code is contained in an HTML file, a type of file not normally associated with executing programs. Ruckman recommended that corporations either delete the attachments at the server level or block messages with the "your account" subject line.

ZDNet UK's Matthew Broersma contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
77 out of 129 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment