AndyCanfield:I like to compare the text of the link with the actual link. I saved this one. The text of the link, which is visible, shows:
http://update.microsoft.com/microsoftofficeupdate/...
but the actual link (just mouse over the link text to see it in Firefox) points to
http://update.microsoft.com.1llijk.com/microsoftofficeupdate/
which is in the "1llijk.com" domain, very different. But nicely obfuscated.
Actually, I've seen them with similar but varied names for the actual domain, and the traces show the DNS listed here in the US. I've sent some emails for supporting evidence to some security folks I know.
To the OP, I did exactly the same thing, emailing everyone in our company, and changing the link to point to Google. Granted, I put a hair more at the top, saying DO NOT CLICK THESE LINKS, DELETE THESE EMAILS, ASK IT FOR MORE INFO, etc.
Very impressive wave otherwise, coordinated and wide-spread, with a massive amount of coverage in a very short period of time, based on my conversations with folks.
morbiuswilters: Oh, and this entire thread is pointless, flamebait spam. Heckuva job, drachy...
Prepare for a life in hell, a thankless job where you service the dregs of society. Kinda like being a hooker that works in a crack house.
"we don't appreciate political/nationalist/technology flamebaiting here, please do not do this" and this is why mods shouldn't be able to permanently delete threads... some of us can't read the historical entries and see what the problem was...