Calendar Of Updates: Malware SPAM: KB910721 officexp-KB910721-FullFile-ENU.exe - Calendar Of Updates

Jump to content


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Malware SPAM: KB910721 officexp-KB910721-FullFile-ENU.exe Block this domain using Hosts file or blocklist

#1 User is offline   Donna 

  • Guinea Pig???
  • PipPipPipPipPipPipPipPipPip
  • View blog
  • Group: Admin - Site
  • Posts: 17,374
  • Joined: 11-October 03


Users Awards

  Posted 22 June 2009 - 09:39 PM

Sophos reported "Fake Microsoft Security Alert - KB910721" (spam) last week. It's still in the wild trying to trick recipients of the email to click the malicious links and to download a malicious update for Outlook Express and Outlook email programs:

Attached Image: 6_23_2009_3_31_23_AM.png

Attached Image: 6_23_2009_3_33_23_AM.png

Attached Image: 6_23_2009_3_33_46_AM.png

When opening the fake Microsoft URL, Opera browser is able to prevent the page in loading and continue to flag it as "Fraud" site when I proceed to load the page:

Attached Image: 6_23_2009_3_35_24_AM.png

Firefox and IE8 browsers with malware or fraud detections failed to block the fake page (reported now!)

Attached Image: 6_23_2009_3_41_25_AM.png

The fake Microsoft alert will automatically open PDF reader:

Attached Image: 6_23_2009_3_36_40_AM.png

18 out of 41 malware scanner will detect the malicious file:

Attached Image: 6_23_2009_5_32_57_AM.png
http://www.virustotal.com/analisis/988e317...a2e8-1245699634

If you are using Hosts file, OpenDNS, Blocklist, you should block the bad domains: 11hilf.com and illihil.com

Attached thumbnail(s)

  • Attached Image: 6_23_2009_3_41_45_AM.png


#2 User is offline   dgsjsj 

  • Dies Lunae
  • PipPip
  • Group: Member - Registered
  • Posts: 63
  • Joined: 12-June 09

Posted 23 June 2009 - 10:23 AM

Donna Hi.
Thanks for the information we have recently discussed a very similar news.
http://www.ikarus-so...com/content.htm
http://news.drweb.co...&c=5&p=0&lng=en
Send link to your message IKARUS Security Software GmbH
They do not show on the detector
http://www.virustotal.com/analisis/988e317...a2e8-1245699634

This post has been edited by dgsjsj: 23 June 2009 - 10:33 AM


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic