SophosLabs has detected a server upgrade malware campaign.

The message says that there will be an upgrade on October 16 and it encourage users to run a procedure about SSI certificates. It instructs the user to download a file, save it on his computer, and then run it.

At the time of posting the article at Sophos, the file was called patch.exe. It is detected as Troj/Zbot-IV. Sophos gateway products will block this file.

The domain name where the file can downloaded is registered in Russia.

Source: Sophos