Skip to main content

Email-Worm:W32/Mimail.J

Classification

Category:

Malware

Type:

Email-worm

Aliases:

  • Mimail.J

Summary

Mimail.J is an email worm which disguises itself as an email from Paypal on-line payment service and tries to steal credit card information. It arrives with the subject "IMPORTANT" and attachment named www.paypal.com.pif.

Except from some textual content the worm's code is almost exactly the same as Mimail.I

Mimail.I: https://www.f-secure.com/v-descs/mimail_i.shtml

Removal

Technical Details

Mimail.J was found on November 17th, 2003. As Mimail.J is packed with a non-modified version of UPX, it is a recompiled version with minimal changes in its code. It arrives in email that looks as follows:

From: "PayPal.com" Do_Not_Reply@paypal.com Subject: IMPORTANT Attachment: www.paypal.com.pif Dear PayPal member, We regret to inform you that your account is about to be expired in next five business days. To avoid suspension of your account you have to reactivate it by providing us with your personal information. To update your personal profile and continue using PayPal services you have to run the attached application to this email. Just run it and follow the instructions. IMPORTANT! If you ignore this alert, your account will be suspended in next five business days and you will not be able to use PayPal anymore. Thank you for using PayPal.

Please note that messages received with a subject "Problems with your PayPal account" and attachment named InfoUpdate.exe were seeded by Mimail author. The worm does not use this subject and attachment name when spreading from an infected computer.

The address collection routine is the same as in the previous variant.

The mail spreading routine is the same as in the previous variant.

Payload

Like Mimail.I: The worm displays a fake Paypal form. The form closely resembles the look of PayPal's website. This way the worm tries to fool the users to enter their credit card information, which is mailed to certain email addresses.

This new variant, in addition, asks for personal information in a form like shown below:

System Infection

Same as in Mimail.I

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.