SUBSCRIBE

โ€˜Here you haveโ€™ e-mail worm spreads quickly

Security experts have warned of a fast-spreading e-mail worm, the first large outbreak of this type in nearly a decade.

The worm appears in e-mail messages with the subject โ€œHere you have,โ€ and contains what seems to be a link to an Adobe Systems Inc. PDF file. In fact the link takes the victim to a Web page hosted on the members.multimania.co.uk domain that then tries to download a screensaver (.scr) file. If the user agrees to installing that file, he is then infected by the worm, which mails itself to his e-mail contacts.

The worm is similar to theย ILoveYou or love bug that spread in 2000 and the Anna Kournikova worms, which hit users in 2001, and is a type of malware that has not been a major problem since around 2002, according to David Cowings, a senior manager with Symantec Corp. Security Response. โ€œIt looks like weโ€™ve had a resurgence of mass-mailing worms,โ€ he said.

In fact, โ€œHere you haveโ€ is the same subject line used by the Anna Kournikova worm.

This latest worm seems to do nothing more than send itself out, using the victimโ€™s contact list, Cowings said. โ€œIt appears to be mailing itself to all of the mailing lists that are in someoneโ€™s contacts. It may also go to individuals,โ€ he said. The worm appeared to be affecting Outlook e-mail users, but itโ€™s not clear if it is also affecting users of other mail programs.

The body of the e-mail typically says something like, โ€œHelloโ€ฆ this is the document I told you about, you can find it here.โ€ Because the worm is spreading via contact lists, the e-mail often comes from someone the victim knows.

Symantec started blocking the worm at around 10:30 a.m. Pacific Time Thursday and quickly stopped 65,000 messages, according to Cowings. The number soon ballooned beyond that, but the worm may now have a hard time spreading, because the malicious screensaver file on multimania.co.uk appears to have been taken down, Cowings said.

Multimania.co.uk is a free website hosting service run by Lycos.

In an alert sent out to customers Thursday, McAfee Inc. recommended blocking .scr files at the Internet gateway. โ€œMcAfee has received confirmation that some customers have received large volumes of spam containing a link to malware, a mass-mailing worm identified as VBMania,โ€ the note reads. โ€œThe symptom reported thus far is that the spam volume is overwhelming the email infrastructure.โ€

Tech Jobs

Categories