The worm spreads in UPX packed form. The unpacked worm body is 24608 bytes in size and was written in C language.
Email Spreading
The virus sends two types of messages. One of them is sent with an infected attachment with the following text:
Hi Greg its Wendy. I was shocked, when I found out that it wasn't you but your twin brother!!! That's amazing, you're as like as two peas. No one in bed is better than you Greg. I remember, I remember everything very well, that promised you to tell how it was, I'll give you a call today after 9. I'm so thankful to you, for acquainted me to your brother. I think we can do i t on the next Saturday all three together? What do you think? O yes, as you wanted I've made a few pictures check them out in archive, I hope they will excite you, and you will dream of our new meeting... Wendy. Attachment: wendy.zip
The other message when sent by the virus does not contain any attachment but the worm has reportedly been seeded with the following text and an attachment called 'test.exe':
Hi Greg its Wendy. I was shocked, when I found out that it wasn't you but your twin brother!!! That's amazing, you're as like as two peas. No one in bed is better than you Greg. I remember, I remember everything very well, that promised you to tell how it was, I'll give you a call today after 9. I'm so thankful to you, for acquainted me to your brother. I think we can do i t on the next Saturday all three together? What do you think? O yes, as you wanted I've made a few pictures check them out in archive, I hope they will excite you, and you will dream of our new meeting... Wendy. Attachment: wendy.zip
This message is meant to scare and confuse the recipient and probably to hurt the reputation of the organizations mentioned in the mail.
The worm collects email addresses from files on the infected computer. It recursively searches through the user's document folders and looks into all the files whose extension is not on the following list:
Hi Greg its Wendy. I was shocked, when I found out that it wasn't you but your twin brother!!! That's amazing, you're as like as two peas. No one in bed is better than you Greg. I remember, I remember everything very well, that promised you to tell how it was, I'll give you a call today after 9. I'm so thankful to you, for acquainted me to your brother. I think we can do i t on the next Saturday all three together? What do you think? O yes, as you wanted I've made a few pictures check them out in archive, I hope they will excite you, and you will dream of our new meeting... Wendy. Attachment: wendy.zip
Using its own SMTP engine it sends emails with the malicious attachment. To find the SMTP server of the target email address the worm does an MX lookup using a predefined public DNS server.
System Infection
When started, Mimail.L first copies itself to the Windows Directory as 'svchost.exe'. This copy is added to the registry as
Hi Greg its Wendy. I was shocked, when I found out that it wasn't you but your twin brother!!! That's amazing, you're as like as two peas. No one in bed is better than you Greg. I remember, I remember everything very well, that promised you to tell how it was, I'll give you a call today after 9. I'm so thankful to you, for acquainted me to your brother. I think we can do i t on the next Saturday all three together? What do you think? O yes, as you wanted I've made a few pictures check them out in archive, I hope they will excite you, and you will dream of our new meeting... Wendy. Attachment: wendy.zip
to make sure the worm is started when Windows starts.
The worm creates several temporary files in the Windows directory:
Hi Greg its Wendy. I was shocked, when I found out that it wasn't you but your twin brother!!! That's amazing, you're as like as two peas. No one in bed is better than you Greg. I remember, I remember everything very well, that promised you to tell how it was, I'll give you a call today after 9. I'm so thankful to you, for acquainted me to your brother. I think we can do i t on the next Saturday all three together? What do you think? O yes, as you wanted I've made a few pictures check them out in archive, I hope they will excite you, and you will dream of our new meeting... Wendy. Attachment: wendy.zip
Payload
Computers infected with Mimail.L perform Distributed Denial-of-Service attacks on the following sites:
Hi Greg its Wendy. I was shocked, when I found out that it wasn't you but your twin brother!!! That's amazing, you're as like as two peas. No one in bed is better than you Greg. I remember, I remember everything very well, that promised you to tell how it was, I'll give you a call today after 9. I'm so thankful to you, for acquainted me to your brother. I think we can do i t on the next Saturday all three together? What do you think? O yes, as you wanted I've made a few pictures check them out in archive, I hope they will excite you, and you will dream of our new meeting... Wendy. Attachment: wendy.zip

Mimail.L also contains this text which is never shown:
Hi Greg its Wendy. I was shocked, when I found out that it wasn't you but your twin brother!!! That's amazing, you're as like as two peas. No one in bed is better than you Greg. I remember, I remember everything very well, that promised you to tell how it was, I'll give you a call today after 9. I'm so thankful to you, for acquainted me to your brother. I think we can do i t on the next Saturday all three together? What do you think? O yes, as you wanted I've made a few pictures check them out in archive, I hope they will excite you, and you will dream of our new meeting... Wendy. Attachment: wendy.zip