The Crabby Host Archives
Search:     Advanced search
* Home
The Crabby Host Archives  |  Crabby eCommerce Business Center  |  Social Networking: Blogs, MySpace and Other Venues  |  Topic: MySpace Profile + Fake Microsoft Patch = Malware Cocktail 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: MySpace Profile + Fake Microsoft Patch = Malware Cocktail  (Read 74 times)
The Tavern Wench
Administrator
Cranky Crab
*

Karma: -1313
Offline Offline

Posts: 2682


Stupidity is its own punishment.


« on: January 13, 2008, 12:24:45 PM »

Source: Security Watch  Published:  January 11, 2008 5:15 pm  Author:   Ryan Naraine
----------------------------------------------------------------


Anti-virus researchers at McAfee are tracking a nasty new malware attack targeting millions of users on the popular MySpace social networking site.

The latest exploit combines a rigged MySpace profile with a fake Microsoft security patch to lure Windows users into downloading malicious executables.

Here's the attack scenario, as explained by a McAfee official:

Attackers send new "friend requests" to MySpace users. When clicking on the person's picture or name link to view their profile, it shows a profile page overlaid with what looks like a legitimate Windows "Automatic Updates" pop-up box.
A Windows user who is tricked into clicking on or near the pop-up receives a request for a file download masked as a Microsoft update called "updateKB890830.exe" from a server that includes "winxpupdate.microsoft" in its name.



The executable file masquerading as a Microsoft patch is acually a true malware cocktail.

Once installed and run, it opens a backdoor on the compromised machine and proceeds to download more downloaders, Trojans and a remote control tool from multiple servers.

The downloaded files are coming from servers located in Malaysia and the Ukraine.

McAfee has notified both MySpace and Microsoft but, at the time of writing, the booby-trapped MySpace profile was still live and serving up the malicious file.
Logged
Pages: [1] Go Up Print 
The Crabby Host Archives  |  Crabby eCommerce Business Center  |  Social Networking: Blogs, MySpace and Other Venues  |  Topic: MySpace Profile + Fake Microsoft Patch = Malware Cocktail « previous next »
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Valid XHTML 1.0! Valid CSS!