Friday, September 10, 2010

Blast from the Past: "Here You Have" Email Worm Circulating

Evil Email Worm

Here's a "blast from the past".  It's like it's 2001 all over again!  There's an email worm ( and not kidding here ) circulating that uses the good old infection method of sending emails with malicious executables to all the people in your address book!

It arrives in emails with a subject like "Here You Have", or something similar to it.

In the email, there's a link to a malicious download - with text that's made to look like it's a link to a pdf, or a video.  If a user clicks on it, the malware winds up in the Windows folder.  The file name winds up CSRSS.EXE and that's a file name for a legitimate file in Windows.

Body Examples

Hello:

This is The Document I told you about,you can find it Here.
hxxp://www.SomeFakeWebsite/library/PDF_Document21.025542010.pdf

Please check it and reply as soon as possible.

Cheers,

or

Hello:

This is The Free Dowload Sex Movies,you can find it Here.

hxxp://www.AnotherFakeWebsite/library/SEX21.025542010.wmv

Enjoy Your Time.

Cheers,

At that point it tries sending itself to everyone in your Outlook address book.

Who says that the good old "tried and true" methods of spreading malware don't work any more?  I suppose if fashion from the 70's can come back, it's not too big a leap to have old spammers tactics rear their ugly heads from time to time.

When the first few came through the CudaMail system, they were quickly analyzed and are now being caught and blocked, but for non-CudaMail customers, make sure you keep an eye on your inbox, and stick with "safe emailing" practices with regard to clicking on anything!