Thursday, April 9, 2009

Fake Microsoft Email Alert Delivers Malware

Emails claiming to be a security warning from Microsoft have been being blasted out for days. They appear to be from “Microsoft Windows Security Team” (or some variation) and informs you that “your network is showing signs of being infected” with the ever popular Conficker worm. There are also multiple variations with the subject line such as: Infection Alert (Incident#: Randomized), Conficker Infection Alert (Incident#: Randomized), Security Breach (Incident#: Randomized), Microsoft Alert (Incident#: Randomized), Microsoft Alert (Case#: Randomized).
Here is an example of the message:
Once you click on the link you are redirected to a fake website as follows:



Following the given instructions you are prompted to download the file setup.exe:




This type of campaign has been seen in the past but I expect this version to achieve higher infection rates due to the recent media heightened interest surrounding the Conficker worm. This is a great example of the latest improvements in social engineering tactics, by means of using current news topics to gain the readers trust and attention. AppRiver is currently blocking all know versions of this message.

0 comments: