|
This virus constructs messages using its own SMTP engine. Target email addresses are harvested from files with the following extensions on the victim machine:
.ADB .ASP .CFG .CGI .DBX .EML .HTM .MDX .MMF .MSG .NCH .ODS .PHP .PL .SHT .TBB .TXT .UIN .WAB .XML
The virus spoofs the sender address by using a harvested address in the From: field.
|