Peaches Posted September 29, 2009 Report Share Posted September 29, 2009 Sep28, 2009 Fake Windows Live Malware spreads via email by Joey Costoya (Advanced Threats Researcher) Trend Micro threat analysts recently snagged an email pushing a bogus Windows Live Messenger residing in http://{BLOCKED}s-live-msn.serveftp.com/Windows_Live_9.0_beta.exe (detected as WORM_VB.PAB). The .EXE file is, of course, not the "real" Windows Live Messenger but a bot that reports to an IRC-based C&C with the following details about the infected system: Server: {BLOCKED}s.rvsanmiguel.com Server IP: {BLOCKED}.{BLOCKED}.110.141 Port: 6767 Serverkey: m4s3rvp4ssz Channel: #s3k4nt Chankey: m4n0sp4z Details & screenshots read trendlabs - http://blog.trendmicro.com/ Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.