This virus constructs messages using its own SMTP engine. Target email addresses are harvested from files with the following extensions on the victim machine:
.ADB
.ASP
.CFG
.CGI
.DBX
.EML
.HTM
.MDX
.MMF
.MSG
.NCH
.ODS
.PHP
.PL
.SHT
.TBB
.TXT
.UIN
.WAB
.XML
The virus spoofs the sender address by using a harvested address in the From: field.
Updated On: 04.03.28