Skip to navigation
Latest News

PayPal scamming worm asks for bank details

By Matt Whipp

Posted on 14 Nov 2003 at 15:37

Sophos has alerted users of a new variant of the Mimail virus, which is designed to appear as a PayPal email.

Graham Cluley, senior technology consultant at Sophos, said Mimail variants were not being used by different authors, unlike the various authors of the Blaster virus. 'We believe the Mimail viruses were written by the same person, or group of people. Just as one of the previous versions attacked anti-spam websites - leading you to believe that these might be spammers themselves - this is another criminal activity to make money.'

Mimail-I arrives as an email with the subject line: 'YOUR PAYPAL.COM ACCOUNT EXPIRES' and the attachment 'www.paypal.com.scr',

The text of the email warns that your PayPal account will shortly expire because of 'a new security policy' and requests that you renew it by running the attachment. The attachment opens a series of dialog boxes that ask you for information including full credit card number, PIN, expiry date, and even the CVV code (the additional three-digit security code on the back of your card). The dialog boxes include the PayPal logo, to add further credence to the requests.

The information is then sent off to the author. Cluley said that he was still awaiting the report on exactly where this information was being sent, but cautioned: 'I assume [the author] is using some kind of email front. It wouldn't make sense to use graham dot cluley at sophos etc.'

The worm copies itself to svchost32.exe and gathers email addresses on the infected computer in a file called el388.tmp and sends itself on to them. Additionally it makes edits to the Registry so that it is run each time the machine is rebooted.

Cluley warns the worm is already in the wild, with reports coming in from the UK, South Africa, Australia and New Zealand. He said users should make sure their antivirus systems are up to date and, of course, not to indulge in proffering bank details on request. Additionally, corporates should configure their email gateways to block executable attachments. Sophos released virus identities for Mimail-I early this morning, he said.

For more information, visit the Sophos website.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.