Chinese Internet Security Response Team (GMT +0800)

Microsoft Critical Live Update?

[Post on : February 8, 2008 15:42 | Category : Trojan | by : smallmo] Reship : Original

We received spams that masqueraded as Microsoft Critical Live Update. The file "WindowsUpdateAgent30-x86-x64.exe" was downloaded from fake Microsoft Update site.

The spams are as the following:


Subject: Microsoft Critical Live Update
Body:
Open in new window


The screenshot of fake Microsoft Update site:

Open in new window

The URL of this fake site:
http://<removed>.update.microsoft.com.asp63.net/windowsupdate/v6/


The size of "WindowsUpdateAgent30-x86-x64.exe" is 43,008 bytes.
MD5 hash:883678a8077bd3805324e5156efc2c1b
Kaspersky detects it as Trojan-Dropper.Win32.Agent.eet.

Reference:

F-Secure: Spotted in the Wild: Rogue Microsoft Update Site