Trojan Disguised as Microsoft Patch
Another new Trojan, Xombe/Downloader-GJ, attempts to fool people by claiming to be a critical patch from Microsoft. It has a downloader component which will attempt to retrieve a Trojan file from a predetermined website. According to the anti-virus vendors' website, the site has now been disabled.
The subject of the email is "Windows XP Service Pack 1 (Express) - Critical Update", with sender email as "firstname.lastname@example.org". The attachment is named as "winxp_sp1.exe" (4,096 KB).
According to Microsoft, they will not send patches via email. If you receive such emails, be wary as most likely it is attempting to trick you to execute some malware.
For more information on this Trojan, please refer to the following:
An interesting article on "Account takeover leading to identity theft":
This article discussed the threat on how hackers can retrieve your personal information from various means leading to identity theft.
Jan 10th 2004
1 decade ago