Thursday August 21, 2008 7:19 AM AEST
Latest Comments
"The protection software currently popular is very specialised in what it protects from. Until a ..."
by John Challinor | Aug 20, 2008 9:11 PM
 
"Cyberwar is a natural progression now that computers control the infrastructure of society and ..."
by John Challinor | Aug 20, 2008 8:52 PM
 
"I came across a new RHOIUM Card that safeguards payment information so that there is no private ..."
by James Buffet | Aug 19, 2008 1:18 PM
 
"I'd suggest that people just not go back to any website that puts advertising dollars ahead of ..."
by Ivan Voshe | Aug 19, 2008 12:13 PM
 
"spyware"
by maryam | Aug 19, 2008 6:08 AM

Bogus Microsoft Update page appears in wild

  • Email a Friend
  • Print Page
Bogus Microsoft Update page appears in wild
By Jack Rogers
Feb 11, 2008 9:59 AM
Tags: "microsoft | security" | "fake | microsoft | threat" | "fake | microsoft | update" | "
The slightly modified URL takes the victim to a fake Microsoft Update “welcome” page that prominently features an urgent notice telling the visitor to install a “critical Windows XP/2000/2003/Vista update!” Install is mispelled on the bogus update page (“intall”), F-Secure reported.

An “Urgent Install” button appears in the fake notice, next to a prompt reading “Get critical update (obligatory).”  Users who click on the button receive a file labeled WindowsUpdateAgent30-x86-x64.exe, which installs a trojan-dropper on the victim's PC. F-Secure said the bogus update page is a “fast flux” site and uses a wide range of IP addresses attached to the “cfm48.com" portion of the URL.

The security research firm said in its blog posting that the malicious program delivered via the trojan dropper is a previously identified piece of malware known as Backdoor:W32/Agent.CVU.

Last month, McAfee researchers warned of a MySpace phishing campaign in which users received “friend” requests that attempt to infect them with malware disguised as a Microsoft update.

Users clicking on the profile of the person trying to befriend them were sent to a page overlaid with a bogus Windows pop-up box promising automatic Windows updates, which, when clicked on, installed a malicious mix of trojans on the victim's PC.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Patch Management Whitepapers