Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

'Here you have' threat subsides, but comeback possible

The first wave of the "Here you have" virus seems to have run its course with removal of the malicious file from the site from which it was being downloaded, but keep an eye out for follow-up versions.

"Here you have" threat subsides, but comeback possible

The first wave of the "Here you have" virus seems to have run its course with removal of the malicious file from the site from which it was being downloaded, but keep an eye out for follow-up versions.

The top 10 'most wanted' spam-spewing botnets

It's an old-school e-mail virus that used the same subject line as the 2001 Anna Kournikova virus and has the same impact --  forwarding the e-mail to entries in Outlook address books.

The message inside prompts readers to go to a Web site, where victims are then urged to download a file that appears to be a PDF but is actually a .scr executable that infects the victim's machine.

"The files to which the links attempted to connect were taken offline rather quickly," says the F-Secure security blog, "so it was not widespread in Europe where it was too early in the morning to snare anybody. In the USA, several big companies noticed the worm moving through their systems."

But SANS Institute's Internet Storm Center says the virus could make a second attempt. "The original file seems to have been removed," the blog says, "so further infections from the initial variant should not occur, but new variants may well follow."

In its initial state, the spam used at least two messages within the e-mail to lure victims, according to a McAfee Labs blog. One reads, "This is The Document I told you about, you can find it Here. Please check it and reply as soon as possible." The other reads, "This is The Free Dowload Sex Movies, you can find it Here. Enjoy Your Time."

Business-to-business transmission of the virus seemed inconsequential because most e-mail filters caught the mailings as suspicious, F-Secure says. But within companies where filtering is not as common, the virus spread widely in many cases, the company says.

Read more about wide area network in Network World's Wide Area Network section.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: F-Secure, LAN, McAfee, SANS Institute
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: anti-malware, f-secure, SANS Institute, security, virus
Latest Blog Posts
Whitepapers
  • Restore control, Reinforce security & Reduce Cost
    Uncontrolled print environments and practices present a serious risk to the profit and security of your organisation. IT is under pressure to protect sensitive information, secure devices, and improve the way they manage the entire fleet. To gain better control, your organisation needs to implement plans that meet industry regulations while also increasing productivity, lowering costs, and providing users with more flexible imaging and printing solutions. Read more.
    Learn more »
  • CSO Security Buyers Guide 2011
    Welcome to the 2011 /2012 CSO Security Buyers Guide CSO is keeping security professionals ahead of the evolving threats and challenges to their businesses. This resource for security professionals assists you in finding leading IT security vendors by their products and solutions. Happy Browsing! The 2011 CSO Buyers Guide team
    Learn more »
  • Stella Travel Services embarks on a strategic refresh of print operations
    Stella Travel Services embraces Managed Print Services (MPS) to deliver savings, centralise and consolidate print operations in order to gain control of print costs and streamline IT support. Read more.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments