<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; BeastPWS-C</title>
	<atom:link href="http://www.darknet.org.uk/tag/beastpws-c/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Thu, 18 Mar 2010 08:50:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Fake Microsoft Patch &#8211; BeastPWS-C</title>
		<link>http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/</link>
		<comments>http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/#comments</comments>
		<pubDate>Wed, 31 May 2006 03:32:08 +0000</pubDate>
		<dc:creator>Tiago Faria</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[BeastPWS-C]]></category>
		<category><![CDATA[fake-patch]]></category>
		<category><![CDATA[gouki]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows-virus]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/</guid>
		<description><![CDATA[If you receive a e-Mail alert of a new patch for your Windows XP OS, think again before opening the link present on the message.
The spammed emails, which purport to come from patch@microsoft.com, claim that a vulnerability has been found &#8216;in the Microsoft WinLogon Service&#8217; and could &#8216;allow a hacker to gain access to an [...]]]></description>
			<content:encoded><![CDATA[<p>If you receive a e-Mail alert of a new patch for your Windows XP OS, think again before opening the link present on the message.</p>
<blockquote><p>The spammed emails, which purport to come from patch@microsoft.com, claim that a vulnerability has been found &#8216;in the Microsoft WinLogon Service&#8217; and could &#8216;allow a hacker to gain access to an unpatched computer&#8217;.</p></blockquote>
<p><div align="center">
<script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_ad_channel ="4027562844";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div></p>
<p>The link on the e-Mail will redirect to a non-Microsoft site where you will download a trojan named <strong>BeastPWS-C</strong>, &#8220;which is capable of spying on the infected user and stealing passwords.&#8221;</p>
<blockquote><p>When first installed the Trojan horse displays a bogus message, which reads: &#8216;Microsoft WinLogon Service successfully patched&#8217;. In actual fact, the malware is secretly logging keystrokes and sending them to an email address belonging to the hacker.</p></blockquote>
<p><div align="center">
<script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
google_alternate_ad_url = "http://www.darknet.org.uk/google_adsense_script.html";
google_ad_width = 336;
google_ad_height = 280;
google_ad_format = "336x280_as";
google_ad_type = "text";
google_ad_channel ="4027562844";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "df6f0b";
google_color_url = "df6f0b";
google_color_text = "000000";
//--></script>
<script type="text/javascript"
  src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div></p>
<p>Well, I wouldn&#8217;t mind receiving this &#8216;Microsoft&#8217; e-Mail and mail-bomb that looser&#8217;s e-Mail address <em>(yeah, the good old mail-bomb attack still works).<br />
</em></p>
<p>For future reference, people need to remember that Microsoft doesn&#8217;t send hotfixes using attachments and not to deploy this patch on their WSUS servers.</p>
<p><strong>Source:</strong> <a href="http://www.net-security.org/secworld.php?id=4009">NHS</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C+http://bit.ly/2o0lim+from+@THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;title=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;title=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;t=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/&amp;title=Fake+Microsoft+Patch+%E2%80%93+BeastPWS-C" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/05/fake-microsoft-patch-beastpws-c/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
