- Discovered:
- April 2, 2003
- Updated:
- February 13, 2007 11:45:12 AM
- Also Known As:
- Win32.Cult.F [CA]
- Type:
- Worm
- Systems Affected:
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
W32.HLLW.Cult.C@mm is an email worm that has backdoor capabilities. It uses its own SMTP engine to send itself to randomly generated recipient names at these domains:
- email.com
- earthlink.net
- roadrunner.com
- yahoo.com
- msn.com
- hotmail.com
The email message has the following characteristics:
Subject: Hi, I sent you an eCard from BlueMountain.com
Message:
Hi , I sent you an eCard from Blue-Mountain.com To view your eCard, open the attachment
If you have any comments or questions, please visit http:/ /www.bluemountain.com/customer/index.pd
Thanks for using BlueMountain.com.
Attachment: BlueMountaineCard.pif
This threat is compressed with ASPack.
Antivirus Protection Dates
- Initial Rapid Release version April 2, 2003
- Latest Rapid Release version September 28, 2010 revision 054
- Initial Daily Certified version April 2, 2003
- Latest Daily Certified version September 28, 2010 revision 036
- Initial Weekly Certified release date April 2, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
- Wild Level: Low
- Number of Infections: 50 - 999
- Number of Sites: More than 10
- Geographical Distribution: Low
- Threat Containment: Easy
- Removal: Moderate
Damage
- Damage Level: Medium
Distribution
- Distribution Level: High
Writeup By: Yana Liu







