Content
W32/Misodene.a@MM
- Type
- Virus
- SubType
- E-mail worm
- Discovery Date
- 04/26/2004
- Length
- 200,702 Bytes
- Minimum DAT
- 4354 (04/28/2004)
- Updated DAT
- 4354 (04/28/2004)
- Minimum Engine
- 5.1.00
- Description Added
- 04/27/2004
- Description Modified
- 04/28/2004 9:48 AM (PT)
Tab Navigation
Characteristics
The following characteristics are associated to the this detection:
- harvests email addresses from the victim machine
- contains its own SMTP engine to construct outgoing messages
- email arrives as an attachment
Mail Propagation
Messages are constructed using the virus' own SMTP engine. They bear the following characteristics:
From:
spoofed (using harvested email addresses)
Subject:
Qui sabe el Pentagono sobre usted (What the Pentagon knows about you)
Body:
?Crees que estas a salvo del Pentagono de los E.U?
Mira estos datos y te asombraras.Do you believe you are safe from the Pentagon of the E.U?
Just look these data and you will be surprisedPassword: 123
Attachment:
(XLS extensions with several spaces to hide the EXE extension)
System Changes:
When executed, the following message box appears:
The following files are dropped:
| En Cuba no hay libertad de expresión | Empty file |
| Michael Jackson.ppt(several spaces).exe.exe | Copy of original file |
| sub.sub | Subject line of email |
| att1.att1 | File attachment name |
| msg.msg | Email message body |
| Casper9247.exe | Dropped file |
| Mina4652.exe | Copy of original file |
| red.mda | Empty file |
| Red7324.exe | Copy of original file |
| PentagonSecret.xls(several spaces).exe | Copy of original file |
| SMTP.ocx | Third party SMTP utility |
Symptoms
Presence of the dialogue box shown above
Method of Infection
This worm spreads by email, constructing messages using its own SMTP engine.
Removal
Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- W32/Bertad.a@MM
Characteristics
Characteristics -
The following characteristics are associated to the this detection:
- harvests email addresses from the victim machine
- contains its own SMTP engine to construct outgoing messages
- email arrives as an attachment
Mail Propagation
Messages are constructed using the virus' own SMTP engine. They bear the following characteristics:
From:
spoofed (using harvested email addresses)
Subject:
Qui sabe el Pentagono sobre usted (What the Pentagon knows about you)
Body:
?Crees que estas a salvo del Pentagono de los E.U?
Mira estos datos y te asombraras.Do you believe you are safe from the Pentagon of the E.U?
Just look these data and you will be surprisedPassword: 123
Attachment:
(XLS extensions with several spaces to hide the EXE extension)
System Changes:
When executed, the following message box appears:
The following files are dropped:
| En Cuba no hay libertad de expresión | Empty file |
| Michael Jackson.ppt(several spaces).exe.exe | Copy of original file |
| sub.sub | Subject line of email |
| att1.att1 | File attachment name |
| msg.msg | Email message body |
| Casper9247.exe | Dropped file |
| Mina4652.exe | Copy of original file |
| red.mda | Empty file |
| Red7324.exe | Copy of original file |
| PentagonSecret.xls(several spaces).exe | Copy of original file |
| SMTP.ocx | Third party SMTP utility |
Symptoms
Symptoms -
Presence of the dialogue box shown above
Method of Infection
Method of Infection -
This worm spreads by email, constructing messages using its own SMTP engine.
Removal -
Removal -
Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A