Fake Windows Live Malware Spreads Via Email


Recommended Posts

Sep28, 2009

Fake Windows Live Malware spreads via email

by Joey Costoya (Advanced Threats Researcher)

Trend Micro threat analysts recently snagged an email pushing a bogus Windows Live Messenger residing in http://{BLOCKED}s-live-msn.serveftp.com/Windows_Live_9.0_beta.exe (detected as WORM_VB.PAB). The .EXE file is, of course, not the "real" Windows Live Messenger but a bot that reports to an IRC-based C&C with the following details about the infected system:

Server: {BLOCKED}s.rvsanmiguel.com

Server IP: {BLOCKED}.{BLOCKED}.110.141

Port: 6767

Serverkey: m4s3rvp4ssz

Channel: #s3k4nt

Chankey: m4n0sp4z

Details & screenshots read trendlabs - http://blog.trendmicro.com/

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...