Allegedly from Microsoft, this email purports to be a “private” update to protect against security threats. The attached file KB089510.exe is made to look like a real Microsoft Knowledge Base file, but is really the trojan Backdoor.Haxdoor.
From Symantec: Backdoor.Haxdoor is a Trojan horse that opens a back door on the compromised computer and allows a remote attacker to have unauthorized access. It also logs keystrokes, steals passwords, and drops a rootkit that also runs in Safe mode, making this threat difficult to remove.
What’s more, this bozo even included a PGP signature to try and raise the authenticity level. And guess what, googling KB089510.exe finds absolutely nothing. And surprise, surprise, the sending IP of 91.195.136.11 is in Russia!
Subject: Security Update for OS Microsoft Windows
Dear Microsoft Customer,
Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium, Microsoft Windows XP, Microsoft Windows Vista.
Please notice, that present update applies to high-priority updates category. In order to help protect your computer against security threats and performance problems, we strongly recommend you to install this update.
Since public distribution of this Update through the official website http://www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all Microsoft Windows OS users.
As your computer is set to receive notifications when new updates are available, you have received this notice.
In order to start the update, please follow the step-by-step instruction:
1. Run the file, that you have received along with this message.
2. Carefully follow all the instructions you see on the screen.
If nothing changes after you have run the file, probably in the settings of your OS you have an indication to run all the updates at a background routine. In that case, at this point the upgrade of your OS will be finished.
We apologize for any inconvenience this back order may be causing you.
Thank you,
Steve Lipner
Director of Security Assurance
Microsoft Corp.
—–BEGIN PGP SIGNATURE—–
Version: PGP 7.1
KAMLL1U2PC8QVTOYF2HVBSIQV6PA1P6U0T4T0TJIABJE6I9DGTED3DD37HY4QWK76
3B32TNGYIKY949D31341QBYH7EZMBLT0YRQVE1E6WALD8C9M84RNRU813KNS48H1M
8NPVJ0K46D7V3W42GTSNBWAZ5QBMFN955W0Y8EEX0GACA6XSLFTU4X4IKNDR7XIPC
XH8VJ6GCZ5IBSAJA1P4A8RABTY4T1243WVA8TUFZ4JV1MS58TF690154O45ZXKH8K
GA8EAIM9DFZ0VB8OP9ASHI4U3VVUELETCIZ==
—–END PGP SIGNATURE—–