On TechRepublic: Linux desktops have tanked: Get over it
BNET Business Network:
BNET
TechRepublic
ZDNet

October 14th, 2008

Fake Microsoft Patch Tuesday malware campaign spreading

Posted by Dancho Danchev @ 3:00 pm

Categories: Anti Virus, Botnets, Hackers, Malware, Microsoft, Passwords, Patch Watch, Spam and Phishing

Tags: Security, Cybercrime, Social Engineering, Patch Tuesday, Dancho Danchev

Fake Microsoft Update EmailMalicious attackers are once again taking advantage of event-based social engineering attacks, and are currently mass mailing fake notifications for Microsoft’s Patch Tuesday, attaching a copy of Trojan.Backdoor.Haxdoor, next to a legitimately looking PGP signature which is, of course, fake too :

“We received some questions from customers about an e-mail that’s circulating that claims to be a security e-mail from Microsoft. The e-mail comes with an attached executable, which it claims is the latest security update, and encourages the recipient to run the attached executable so they can be safe. While malicious e-mails posing as Microsoft security notifications with attached malware aren’t new (we’ve seen this problem for several years) this particular one is a bit different in that it claims to be signed by our own Steve Lipner and has what appears to be a PGP signature block attached to it. While those are clever attempts to increase the credibility of the mail, I can tell you categorically that this is not a legitimate e-mail: it is a piece of malicious spam and the attachment is malware. Specifically, it contains Backdoor:Win32/Haxdoor.”

Is timing everything when it comes to the success rate of such malware campaigns? Not necessarily.

Despite the touch points aiming to improve the trust factor, like mentioning a real Microsoft employee, spoofed FROM field as securityassurance AT microsoft.com, next to the PGP signature, given the fact that the emails aren’t personalized and that spam outbreaks spreading malware by capitalizing on Microsoft’s brand have cyclical pattern, namely, they re-appear every year (2005, 2007, 2008) the average end user is supposed to have a basic security awareness of this tactic. More info on the campaign :

Furthermore, this backdoor opens several TCP ports that allow remote attackers to connect to the comprmised PC and execute files, steal information from it, or upload and download files. The attachment’s file name varies, but uses the convention KBxxxxxx.exe, where xxxxxx is a random 6-digit number. Below are some of the file names we’ve seen, and are being used:

KB199250.exe
KB246586.exe
KB535548.exe
KB572906.exe
KB763412.exe

Compared to the recent targeted malware attack against U.S schools, and the massive fake CNN news items campaign taking advantage of client-side vulnerabilities, this one is definitely going to have a lower success rate - no matter the timing.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 67 Talkback(s)
interesting
Using Linux, I downloaded these whatever they are things from the link provided.

First thing I notice is the file name changes randomly each time I save the file.

Secondly, and this is t... (Read the rest)
Posted by: pgit Posted on: 08/05/09 You are currently: a Guest | | Terms of Use
owning a computer  Monosdeja | 10/14/08
It doesn't always take an email.  Zogg | 10/15/08
You'd have to be dumb  owen35ny | 10/15/08
You think so?  liquidglow | 10/15/08
Mother in law with similar problem here...  914four | 10/15/08
A guy on the street ask to upgrade your wallet...  tom123_z | 10/15/08
to be more precise...  linuxoverwindows | 11/04/08
Yes, I do think so...  Major Havoc | 10/16/08
Watch what you said.  Grayson Peddie | 10/16/08
Watch what you said.  Major Havoc | 10/17/08
And yet -  zclayton2 | 10/16/08
RE: It doesn't always take an email  ccfman2004 | 10/17/08
it dont take mac mail...  linuxoverwindows | 11/04/08
Another issue is what to do...  deowll | 10/17/08
thats pretty paranoid  linuxoverwindows | 11/04/08
LoL  liquidglow | 10/15/08
Not EVERYBODY is a computer whiz, Monosdeja  drprodny | 10/15/08
...giving our Moms Linux Netbooks  tom123_z | 10/15/08
actually I agree  deowll | 10/17/08
owning a computer  cynic8 | 10/15/08
You think you are being critical but...  deowll | 10/17/08
owning a computer  ccybuch | 10/15/08
I'd blame the criminals and not blame the victoms.  Grayson Peddie | 10/16/08
Because we are stupid?  deowll | 10/17/08
Not all want to measure up to Monosdeja's standard!  bruce4ta | 10/18/08
Lol, the English!  chaiguy1337 | 10/15/08
RE: Lol, the English!  Milz | 10/15/08
The Rush Limbaugh / Bill O'Reilly Theory of Malware  jonkers | 10/15/08
The clown's Theory of Caring  tm2guy@... | 10/17/08
Why  jonkers | 10/18/08
Wonderful!  *nixFan | 10/24/08
SPECTACULAR!  bmerc | 10/30/08
Excellent response, bmerc!  jonkers | 11/02/08
LOL the English  tburnakis | 10/15/08
Um, English 101 is a college course.  deowll | 10/17/08
LOL, The English  Wolf4Fun | 10/17/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  cyberrab@... | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  hsaidi@... | 10/15/08
Dude, edit that link  seanferd | 10/16/08
I agree.  Grayson Peddie | 10/16/08
RE: Dude, edit that link  richdave | 10/17/08
PCLinuxOS...  pgit | 08/05/09
interesting  pgit | 08/05/09
RE: Fake Microsoft Patch Tuesday malware campaign spreading  mwestmo1 | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  lethal9x | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  ConnieS | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  clovenlife | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  NerdHerd007 | 10/15/08
Malware  Mahegan | 10/15/08
It's particularly amusing...  zdnet@... | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  FRXL | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  ma66dd@... | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  ma66dd@... | 10/15/08
windows 98 reference means it's bogus  marcus_compton@... | 10/15/08
WARNING: It's dangerous to read this !  tom123_z | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  rlovoy | 10/15/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  madchef_666 | 10/16/08
Not surprising  seanferd | 10/16/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  cattails321 | 10/16/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  cattails321 | 10/16/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  ccfman2004 | 10/17/08
Joking right?  tm2guy@... | 10/17/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  PhotoGene47 | 10/17/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  deowll | 10/17/08
RE: Fake Microsoft Patch Tuesday malware campaign spreading  hforman@... | 10/20/08
idiots  Mectron | 10/23/08
Like the Fake Patch Tuesday email  tracy anne | 10/24/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here