eWeek Security Watch
Advertisement
Advertisement
January 11, 2008 5:15 PM

MySpace Profile + Fake Microsoft Patch = Malware Cocktail



MySpace Profile + Fake Microft Patch = Malware Cocktail Anti-virus researchers at McAfee are tracking a nasty new malware attack targeting millions of users on the popular MySpace social networking site.

The latest exploit combines a rigged MySpace profile with a fake Microsoft security patch to lure Windows users into downloading malicious executables.

Here's the attack scenario, as explained by a McAfee official:

Attackers send new "friend requests" to MySpace users. When clicking on the person's picture or name link to view their profile, it shows a profile page overlaid with what looks like a legitimate Windows "Automatic Updates" pop-up box.

A Windows user who is tricked into clicking on or near the pop-up receives a request for a file download masked as a Microsoft update called "updateKB890830.exe" from a server that includes "winxpupdate.microsoft" in its name.

MySpace Profile + Fake Microft Patch = Malware Cocktail

The executable file masquerading as a Microsoft patch is acually a true malware cocktail.

Once installed and run, it opens a backdoor on the compromised machine and proceeds to download more downloaders, Trojans and a remote control tool from multiple servers.

The downloaded files are coming from servers located in Malaysia and the Ukraine.

McAfee has notified both MySpace and Microsoft but, at the time of writing, the booby-trapped MySpace profile was still live and serving up the malicious file.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/12437

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise