Saturday July 4, 2009 1:52 PM AEST
 
Latest Comments
"Thank you "
by Dr. Holub | Jul 4, 2009 11:17 AM
 
"Agree that wireless hotspots are an easy way for hackers to gather information from connected ..."
by Patrick Hooper | Jul 3, 2009 4:06 AM
 
"Katarzyna what has this got to do with Symantec?? "
by PaulC | Jul 2, 2009 12:55 PM
 
"Hi Nadim, I'm the chief marketing officer at Ounce Labs, and I disagree with your statement. ..."
by Jennifer Sullivan | Jun 30, 2009 11:56 PM
 
"noobs!"
by webappsec | Jun 30, 2009 4:53 PM

Fake Microsoft patch spam

  • Email a Friend
  • Print Page
Fake Microsoft patch spam
By Sue Marquette Poremba
Jul 3, 2008 10:05 AM | 5 Comments
Tags: Microsft | Patch | Spam | Fake
A new spam attack falsely alerts users to download a Microsoft patch in an attempt to install malicious malware.
A new spam attack falsely alerts users to download a Microsoft patch, but when responded to, the user is directed to a page that installs malware on the user's computer.

According to a report from Websense, the message tells users that their Windows version is vulnerable to a critical security issue and directs them to a download page.

The link actually uses an open redirect to a legitimate shopping site. From there, the redirect forwards users to a URL with a pop-up box, instructing the user to click “yes” to start the download, Dan Hubbard, CTO at Websense told SCMagazineUS.com on Wednesday.

“It's a deception attack, where it is made to look like a Microsoft update and the user has to take action, rather than an exploit where the user gets infected without saying yes to the download,” Hubbard said.

The downloaded malware infects the computer with a backdoor that can be exploited by hackers.

However, Hubbard added, the spam is easy to spot because Microsoft does not send email notifications about patch updates.

One of the more interesting aspects to this spam, Hubbard said, is the actual root of the domain name used – it will take the user to the Secret Service website.

“We believe they are doing that because some security products only look at the top level domain name, rather than look at the whole name,” Hubbard explained. “In this case, the security product would see it was going to the Secret Service and let it go.”

Avivah Litan, Gartner vice president and distinguished analyst, added that this is just more proof that the bad guys are getting smarter.

“The people sending out the spam are figuring out how to avoid the filters or reputation systems,” she said.  

It is just one more instance that shows the need for stronger authorisation on the Internet, she said.

“We need a TSA for the Internet.”

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Comments: 5
Is this news? The Websense report is from June 6
SC Magazine - comments icon Posted by G-manJul 4, 2008 8:54 PM
KEEP ME On Your List for Updates
SC Magazine - comments icon Posted by Chaz ChllersJul 5, 2008 10:52 PM
The fake program hit me yesterday, July 05. would not let me close program. Had to manually shut down to reboot. than use my filters to remove it. Looks very official from MS. I believe I am free of it at this time. One more note, it cane in my computer from an "American legion" looking official sight.
SC Magazine - comments icon Posted by TomJul 7, 2008 1:16 AM
this microsoft spam that i can get rid off. can someone help?
SC Magazine - comments icon Posted by eddyJul 7, 2008 1:52 PM
this microsoft spam that i can get rid off. can someone help?
SC Magazine - comments icon Posted by eddyJul 7, 2008 1:52 PM
Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Exclusive Data Centre - Sponsored Content by Microsoft
 
Patch Management Whitepapers