Sep28
6:00 am (UTC-7)   |   by Joey Costoya (Advanced Threats Researcher)

Trend Micro threat analysts recently snagged an email pushing a bogus Windows Live Messenger residing in http://{BLOCKED}s-live-msn.serveftp.com/Windows_Live_9.0_beta.exe (detected as WORM_VB.PAB). The .EXE file is, of course, not the “real” Windows Live Messenger but a bot that reports to an IRC-based C&C with the following details about the infected system:

Server: {BLOCKED}s.rvsanmiguel.com
Server IP: {BLOCKED}.{BLOCKED}.110.141
Port: 6767
Serverkey: m4s3rvp4ssz
Channel: #s3k4nt
Chankey: m4n0sp4z

Click for larger view

Figure 1. Sample spam email

The said bot’s primary function seems to be MSN spamming. As of this writing, the C&C channel is currently idle, as it has not yet issued commands. Apart from MSN spamming, the said bot was also designed to spread via USB autorun and P2P networks like Kazaa and Limewire.

Windows Live Messenger users should thus refrain from clicking the malicious URL spreading via email to avoid infection. Trend Micro Smart Protection Network already blocks the malicious URL and detects the fake Windows Live Messenger as WORM_VB.PAB.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




8 Responses to “Fake Windows Live Malware Spreads via Email”

  1. Samuel Says:

    malicious attack are getting more sophiscated

Trackbacks

  1. TrendMicro (TrendMicro)
  2. rukku (RK )
  3. jespinhara (joaquim espinhara)
  4. PerimeterNews (Jonathan Thomas)
  5. iia_security (Terry)
  6. Malware disfrazado de una descarga de Windows Live Messenger, messenger es gratis
  7. Falso Windows Live malware se propagaba a través de correo electrónico