(openPR) Köln, 1. Juli 2008 - Die Websense Security Labs haben mit Hilfe ihrer ThreatSeeker-Technologie in den letzten Tagen eine beträchtliche Zahl von Spam-Mails entdeckt, mit denen Anwender dazu gebracht werden sollen ein angeblich kritisches Microsoft Security Update herunterzuladen. Folgen Anwender dem in der Mail angegebenen Link, werden sie auf eine Webseite umgeleitet, von der schadhafter Programmcode auf ihren Rechner geladen wird. Die Auswirkung: Auf dem infizierten System wird eine Hintertür für weiteren Schadcode geöffnet.
Websense weist ausdrücklich darauf hin, dass Microsoft niemals Security Updates per E-Mail verschickt.
In seinen Security Labs beobachtet Websense, ein internationaler Experte für Internet-Sicherheit, pro Stunde mehrere Millionen Websites und analysiert, wie sich neue Bedrohungen aus dem Internet verhalten und auswirken.
Detaillierte Informationen, wie man diese Attacke erkennt und verhindert, gibt es unter http://securitylabs.websense.com/content/Alerts/3122.aspx. Hier sind auch Screenshots mit weiteren Details zu finden.
Die gesamte E-Mail-Nachricht der Websense Security Labs im Wortlaut:
Onslaught of fake Microsoft patch spam
Websense Security Labs ThreatSeeker Network has discovered a substantial number of spam messages utilizing a reliable social engineering trick that lures users to download a Microsoft critical security update.
The message uses an open redirect at the legitimate shopping site shopping.***.com; the redirect forwards users to a malicious URL offering to download a malicious executable. The malicious hostname is a lengthy one embedding 62 characters, and uses the sub-domain update.microsoft.com. Users who open this file will have their desktop infected with a Backdoor.
Here is what the redirect looks like inside the spam messages: hXXp://shopping.***.com/go.nhn?url=hXXp%3A%2F%2Fupdate%2Emicrosoft%2Ecom%2E%2Enet
An interesting trait of this particular attack is that the malicious top level domain is pointing to the government site of the United States Secret Service - The Electronic Crimes Tasks Forces Web site in an apparent attempt to work around IP reputation-based systems.
Websense Messaging and Websense Web Security customers are protected against this attack.
To view the details of this alert Click here:
http://securitylabs.websense.com/content/Alerts/3122.aspx

