Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Fake Windows Support Spam Brings Forth an Info-Stealer

    This is probably the type of support one wouldn’t want to have.

    Spammed email messages were found pretending to come from Microsoft Windows Support and claiming that Microsoft Service Pack 1 and Service Pack 2 have been discovered to have an error that can damage the computer’s software or even the hardware.

    Fake Windows Support spam
    Figure 1. Spammed messages purporting to come from Windows Support

    These messages encourage users to download and install a file in order to fix the problem. When users click the download button they are redirected to a site and are asked to download a file which Trend Micro detects as TROJ_DLOADER.CUT.

    Downloaded malware
    Figure 2. User is prompted to download a malicious file

    TROJ_DLOADER.CUT connects to a certain URL to download another malicious file, which in turn is detected by Trend Micro as TSPY_BANKER.MCL. TSPY_BANKER.MCL monitors the affected user’s online transactions and steals banking related information.

    Not too many TSPY_BANKER variants have been reported to be related to notable attacks recently, and this incident may pretty much mark the end of the hiatus. Users are advised to ignore spammed messages and, more importantly, to never click links embedded in these messages.

    Trend Micro users are protected from this attack by the Smart Protection Network, as the related files, spam, and URL are already detected and blocked.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    4 Responses to “Fake Windows Support Spam Brings Forth an Info-Stealer”

    Trackbacks

    1. Matt Cutts on Spam
    2. microsoft_cares (Matthew Arkin)
    3. Capn_YoAsse (John©™ )
    4. Fake Windows Support Spam Brings Forth an Info-Stealer - All About Virus


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice