Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against 'Here you have'/W32.VBMania Worm

Subscribe

Check Point Reference: CPAI-2010-269
Date Published:
Severity:
Source: Check Point Malware Research Team
Protection Provided by: Security Gateway
  • R71
  • R70
IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Microsoft Windows clients
Vulnerability Description
VBManiaA, also referred to as 'Here you have' worm, is a mass-mailing worm that appears in e-mail messages with the subject "Here you have". The message contains a link to a Web page that hosts a crafted screensaver (.scr) file. If the user agrees to download that file, he is then infected by the worm, which mails itself to the user's e-mail contacts.

Worms are malicious programs that spread themselves without any user intervention and have a self-replicating behavior. A Worm may consume a large amount of system resources and cause the machine to become unreliable. Some Worms may be used to compromise infected machines and download additional malicious software. 
Vulnerability Details
VBMania is received as part of spam email. When executed, it will enumerate addresses in an infected hosts contact list and sends itself via email. This malware also has capabilities to spread via autorun and can spread to network shares or removable drives.

Protection Overview
The protection is able to detect and block the VBMania Worm propagation.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05Protection taband select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway: R70/R71

How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > Application Intelligence > Malware Traffic > Worms.
2. In the right pane, double-click the following protection:

Worm: VBMania

3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect), and apply Additional Settings
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries: 

Attack Name: Malware Traffic
Attack Information: Worm: VBMania

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > SMTP2, and select the Keyword Matching protection group.
3. Click SMTP Subject Keyword Match (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. In the 'SMTP keywords to use for searching email subjects' enter 'Here you have'.
6. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: SMTP Keyword Matching
Description: SMTP Subject Keyword Match