Home Malware Programs Worms Frethem

Frethem

Posted: September 6, 2007

Frethem is a family of mass-mailing worms that arrive in an infected email attachment. When the receiver opens the attachment, Frethem copies itself to the user's Startup folder as 'setup.exe', so it can launch every time the Windows load up. Frethem uses a MIME header vulnerability and an IFRAME vulnerability so that the attached file is run automatically when the email is viewed on unpatched Microsoft email clients. Frethem collects email addresses from the Windows Address Book and files with '*.DBX' extensions. Frethem uses its own mailing engine send infected messages.

Related Posts

Loading...