Infesting you with Virus News
 

News

Contributed by: Aurelija
Date: November 10, 2008
Aurelija
7
Vote
0

Spammers Attack on Facebook… Again?!

 

facebook-customized-img.jpgWell, it seems that Facebook is going to be one of the most targeted websites these days. Cyber-criminals are constantly choosing this social networking site as the enticement to trick their potential victims. This time security experts at Websense Security Labs inform everybody about the Koobface social networking worm being spread on Facebook.

This threat comes with an email purportedly sent from Facebook. The email reveals that infected user accounts are being used to post messages to Facebook friends lists. The user is prompted to watch the video of him or her. This link uses a Facebook open redirector.

Below you can see a screenshot of a sample email:

facebook_spam_email_pub.png

As soon as the recipient clicks on the provided link, he or she will be redirected multiple times. Finally, the victim is navigated to the website masquerading as YouTube that serves a malicious Trojan downloader.

Here you can see a screenshot of this malicious website that is serving the Trojan downloader:

FacebookWormEndingPagePub.png

How does the whole system work? The Facebook link directs to a malicious account hosted at Geocities.com. The malicious Geocities account includes an obfuscated JavaScript link to http://lost[REMOVED]/js/js.js, which goes to http://off3[REMOVED]/go/fb.php. Then, the .php file next redirects to either http://youtube-spyvi[REMOVED]/?schk=&keat= or http://youtube-x[REMOVED]/?ch=&ea=. These sites serve the malicious "flash_update.exe" (SHA1: 62689f89f1c5f6df10f4c7096772468d4c8e458a) file.

According to anti-virus software company Symantec, the Trojan works by executing a worm called W32.Koobface.A that searches for cookies on the user's machine. If the worm finds the appropriate Facebook cookie, it modifies the users account settings and profile - adding links to malicious sites to trick others into installing the invader. Installing the fake upgrade allows the worm to work its magic and access files on the victim's machine while destroying their Facebook account.

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 17, 2010
March 17, 2010
Found this list of godaddy domain name coupons, I got a domain for my dog - ha $6.91 Domain... more..
March 17, 2010
Three guys were having a beer in a bar in London. They were all relative newly-weds and they were talking... more..
more comments..
rss
Home > E-mail > Spammers Attack on Facebook… Again?!