'Here You Have' Email
Last Updated: 2010-09-09 21:49:06 UTC
by Marcus Sachs (Version: 2)
We are aware of the "Here you have" malware that is spreading via email. As we find out more, we'll update this diary.
Update: 2010-09-09 21:28 UTC (JAC) There are several good writeups on the behavior of this malware see some of the references below. The spam contains a link to a document, the link looks like it is to a PDF, but is, in fact, to a .SCR file and served from a different domain from what the link appears to point to. The original file seems to have been removed, so further infections from the initial variant should not occur, but new variants may well follow. The .SCR when executed downloads a number of additional tools, one of which appears to attempt to check in with a potential controller. The name associated the controller has been sink-holed. The malware attempts to deactivate most anti-virus packages and uses the infected user's Outlook to send out its spam.
References:
http://www.virustotal.com/file-scan/report.html?id=fedb7b404754cf85737fb7e50f33324b84eb4c0b98024c7d3302039a901b04b7-1284058335#
http://www.threatexpert.com/report.aspx?md5=2bde56d8fb2df4438192fb46cd0cc9c9
http://www.threatexpert.com/report.aspx?md5=bd9208edf44d0ee32b974a2d9da7bc61
http://www.avertlabs.com/research/blog/index.php/2010/09/09/widespread-reporting-of-here-you-have-virus/
---------------
Marcus H. Sachs
Director, SANS Internet Storm Center
Jim Clausing
FOR408 coming to central OH in Sept, see http://www.sans.org/mentor/details.php?nid=22353

Diary Archives
The audit firm use McAfee and McAfee added detection as of today. The audit firm said it disabled McAfee. McAfee's writeup for this non-PDF infection is at http://home.mcafee.com/VirusInfo/VirusProfile.aspx?key=275352#none
It appears to require local administrator rights to do its thing since it installs into %WINDIR%. "Least privilege" stops another one even if the AV vendors can't.
FWIW, we tested it against the six anti-malware systems we use. Bitdefender and Kaspersky on the proxy server both stopped the download if the link was clicked.
Every engine we have enabled on Forefront for Exchange let the email go right through because it was just a link. The Sophos email gateway did the same because it was just a link. These systems update every hour.
The two engines on the proxy server marked it as:
Bitdefender: Gen:Trojan.Heur.rm0@fnBStPoi
Kaspersky: Suspicious:HEUR:Trojan.Win32.Generic
The actual link in the email is below. It says it's a PDF link but it's a .SCR link.
http: // members . multimania . co . uk / yahoophoto / PDF_Document21_025542010_pdf . scr
The text was:
--------------------------------------------------------------------------
Subject: Here you have
Hello:
This is The Document I told you about,you can find it Here. http://www . sharedocuments.com/ library/ PDF_Document21.025542010.pdf
Please check it and reply as soon as possible.