Subscribe to RSS feeds


Jul26
by Jasper Pimentel (Advanced Threats Researcher)

No, that’s not a typo. The title for this blog entry is really “Updating VVindows”, with a double V instead of a W. If you’ve noticed that the word “Windows” was written with two Vs instead of a W, then good for you. Chances are, you won’t be easily fooled by VVINDOWSUPDATE.COM

According to Sunbelt’s Blog, there is a newly registered domain name called VVINDOWSUPDATE.COM. Created last July 9, this site apparently wants to trick people into thinking that it’s the actual update site for Windows (which is actually http://www.update.microsoft.com). Although there are no pages on the site yet, it’s highly possible that VVINDOWSUPDATE.COM can be used for future web threat attacks.

Here’s some related info on the domain:



Domain Name: VVINDOWSUPDATE.COM

Registrant:
SSS Inc.
Ivan P Sidorov ********@spywaresoftstop.com)
Mira 1-90
Moscow
Karachaevo-Cherkesskaya Respublika,333444
RU
Tel. +543.87987665

Creation Date: 09-Jul-2007
Expiration Date: 09-Jul-2008

Domain servers in listed order:
ns2.vvindowsupdate.com
ns1.vvindowsupdate.com




It seems suspicious that the registrant is in Russia, don’t you think?

As a safety measure, before clicking on any link claiming that it’s a Windows update site, check for the URL. It should be http://www.update.microsoft.com.




One Response to “Updating VVindows”

  1. Kidz Rage ! » Updating VVindows Anyone ? Says:

    [...] via Trend Micro Blog [...]



© Copyright 2008 Trend Micro Inc. All rights reserved. Legal Notice