The risk assessment of this threat is classified as High-Outbreak by McAffe.
This is a mass-mailing and peer-to-peer file-sharing worm that bears the following characteristics:
- contains its own SMTP engine to construct outgoing messages
- contains a backdoor component (see below)
- contains a Denial of Service payload
The virus arrives in an email message as follows:
From: (Spoofed email sender)
Subject: (Varies, such as)
Error
Status
Server Report
Mail Transaction Failed
Mail Delivery System
hello
hi
Body: (Varies, such as)
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.
Attachment: (varies [.bat, .exe, .pif, .cmd, .scr] - often arrives in a ZIP archive) (22,528 bytes)
examples (common names, but can be random)
doc.bat
document.zip
message.zip
readme.zip
text.pif
hello.cmd
body.scr
test.htm.pif
data.txt.exe
file.scr
Do not open the attachment file and delete the email immediately.
O Clubeinvest.com informa que nenhuma da informação
aqui facultada deverá ser entendida como conselho ou recomendação
de qualquer tipo de transacção ou investimento.