Sponsored by..

Wednesday 27 August 2008

"Bank of America Installation and Upgrade Warning."

The bad guys are busy today, here's another fake bank "upgrade" leading to malware, following on from this one.

Subject: Bank of America Installation and Upgrade Warning.
From: "Bank Of America Update Service Department"
Date: Wed, August 27, 2008 2:23 pm

Attention All Bank of America Customers.
Security & Fraud Protection Update.

At Bank of America, were committed to keeping your information confidential and
secure, and we take that responsibility very seriously.
Our Fraud detection solution helps to protect your business against the risk of
fraudulent transactions alerting you to potential risks.
We have developed the following protection tools to insure you confidentiality.

You can download the latest security pack from our Customer Service Department>>

Sincerely, Jodie William.
2008 Bank of America Corporation. All rights reserved.
This leads to a very convoluted URL with an executable Setup_BankofAmericaclientno4508832.exe - virus detection for this one is a bit poor. Malware is identified variously as TR/ATRAPS.Gen (AntiVir & WebWasher), DeepScan:Generic.Malware.dld!!.083539B0 (BitDefender) and one or two others come up with a generic detection.

Incidentally, the URLs used in both attacks are incredibly long and convoluted.. and not terribly convicincing.

Avoid these "bank certificates" at all costs.

No comments: