Categorized | Antivirus

“Here you have” worm

An email worm that appears to be a decade-old throwback was spotted yesterday and widely reported.

The subject line on the email was “Here you have” or “Just For you.”

The body of the email was:

“Hello:

“This is The Document I told you about, you can find it Here. http://www (dot) sharedocuments (dot) com/library/PDF_Document21.025542010.pdf

“Please check it and reply as soon as possible.
“Cheers”

A second variant offered a porn movie:

“Hello:

“This is The Free Dowload Sex Movies, you can find it Here.
http://www.sharemovies.com/library/SEX21.025542010.wmv

“Enjoy Your Time.
“Cheers”

The URL in the email actually led to a screen-saver (.scr) file on a site that has been taken down.

“Here you have” worm and the power of social engineering

Francis Montesino, manager of malware processing at GFI-Sunbelt’s Clearwater labs commented:

“The worm is pretty much is the same as all the other e-mail worms I’ve encountered in the past. I guess this just got more attention because of the scope of the infection.

“It’s another demonstration perhaps of how powerful a technique social engineering still is:
– It uses an interesting e-mail subject and wording.

– it contains a link that pretends to point to a pdf or wmv but in reality an executable which has the icon of a PDF.”

Sunbelt Detection: Trojan.Win32.Generic!BT

Here are names assigned by other anti-virus companies.

Tom Kelchner

View full post on Sunbelt Blog

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago