| View previous topic :: View next topic |
| Author |
Message |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5860
|
Posted: Wed Sep 05, 2007 12:57 am Post subject: trendmicroinc.cn - A Phishing Site? |
|
|
It took me a while but I'd say http://trendmicroinc.cn is a phishing site.
The domain looked a little odd so I checked with McAfee http://www.siteadvisor.com/sites/trendmicroinc.cn which said it was a phishing site.
I then looked at the site, links were ok, pages loaded fine seemed ok. I downloaded a file from the site TMASInstall_EN_US.exe which Microsoft ForeFront said was TrojanDropper:Win32/Malf.gen (I suspect it may be a false positive but I may be wrong, I'll run it later today) but I couldn't see how it was a phishing site.
That's when I went to download a "trial" and found this http://trendmicroinc.cn/us/products/sb/antispyware-for-smb/download/index.php?productID=63 which must be the phishing page.
I thought it worth a mention.
Tetak
|
|
| Back to top |
|
 |
faith_michele
PIRT Handler
 Joined: Dec 26, 2005 Posts: 2638
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1810 Location: Japan
|
|
| Back to top |
|
 |
tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5860
|
Posted: Wed Sep 05, 2007 12:15 pm Post subject: |
|
|
I don't think I submitted it to PIRT or MIRT, I wanted to see what other people thought before I did.
I've added the file to the malware listserv. _________________ Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.
Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1810 Location: Japan
|
Posted: Thu Sep 06, 2007 7:23 am Post subject: |
|
|
The site seems to have been disappeared.
|
|
| Back to top |
|
 |
faith_michele
PIRT Handler
 Joined: Dec 26, 2005 Posts: 2638
|
Posted: Thu Sep 06, 2007 7:41 am Post subject: |
|
|
That is good.
The blog was a good response by Trend Micro.
|
|
| Back to top |
|
 |
|
|