« PaulMccartney.com Gets Lucky | Main | Malware Exploits Conficker Interest »
Tuesday
07Apr2009

Conficker, Rogue AV, and Microsoft Security Spoof

To continue capitalizing on Conficker fears, scammers are now distributing scareware via an email disguised as official correspondence from Microsoft Security. The bogus email reads:

Dear Windows User,

Starting April 1st 2009 the 'Conficker' virus started infecting Windows users very quickly.
Microsoft was advised by your Internet provider that your system is showing signs of being infected.

In order to prevent further infection we advise running a full antispyware scan on your computer.

We are giving all effected Microsoft Customers with a free tool to remove the infection from their system.

Please visit the Microsoft System Security Scan website by clicking here <http://MScustsupport.microsoft.com.support.microsoft27.REMOVED.cc> to start scanning your computer.

The scan will complete in under a minute and will prevent your information from being compromised.
We appreciate your prompt cooperation.

Sincerely,
Microsoft Windows Agent 200 (Dalton)
Windows Net Security Dept.
Email Reference Number: DCanHukZ

A quick look at the source code for the site reveals the attackers intentions:

clearInterval(prcnt_interval);
$(".file_scanner").html("Scan complete. 527 threats was found!");
setTimeout("pop2()",1000);

The end result looks like this:

Clicking anywhere on the page starts the download for setup.exe, a rogue spyware scanner. Fortunately, detection is good, as can be seen in these VirusTotal results.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>