The Ins and Outs of JunkMail roy g biv / defjam RT Fishel / defjam -= defjam =- since 1992 bringing you the viruses of tomorrow today! About the authors: roy g biv: former DOS/Win16 virus writer, author of several virus families, including Ginger (see Coderz #1 zine for terrible buggy example, contact me for better sources ;), and Virus Bulletin 9/95 for a description of what they called Rainbow. Co-author of world's first virus using circular partition trick (Orsam, coded with Prototype in 1993). Designer of world's first XMS swapping virus (John Galt, coded by RT Fishel in 1995, only 30 bytes stub, the rest is swapped out). Author of world's first virus using Thread Local Storage for replication (Shrug, see Virus Bulletin 6/02 for a description, but they call it Chiton), world's first virus using Visual Basic 5/6 language extensions for replication (OU812), world's first Native executable virus (Chthon), and world's first virus using process co-operation to prevent termination (Gemini). Author of various retrovirus articles (eg see Vlad #7 for the strings that make your code invisible to TBScan). Went to sleep for a number of years. This is my sixth virus for Win32. It is the world's first virus using polymorphic SMTP headers. I'm also available for joining a group. Just in case anyone is interested. ;) RT Fishel: I don't write virus, I write code for people to use in their virus. JunkMail brings to you some new techniques for e-mail speading. If you read RFC 822 carefully, you will see a description about comments that are allowed to appear in headers. These comments must be enclosed in () characters and can contain any characters in the ISO-8859-1 character set. If you use these comments to obfuscate the MIME headers, then you might bypass some AV e-mail scanners. :) Here is an example JunkMail e-mail before obfuscation: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary=WIFVHABY --WIFVHABY I received this file from you yesterday evening. I think it was sent without you knowing by the Aliz virus. The filename was changed but it looked like an important video inside. You should look at this file to see what it is. The attachment might open automatically. This is normal behaviour. If you see a prompt to Open or Save the email then choose Open. If the attachment is blocked by Outlook 2002 then see http://support.microsoft.com/support/kb/articles/q290/4/97.asp --WIFVHABY Content-Type: text/html Content-Transfer-Encoding: quoted-printable