- Number 1 with PC news -
 

News

Aurelija
6
Vote
0

Social Networking Sites under Spammers’ Attack: Spoofed Orkut Emails!

Contributed by: Aurelija
Date: 2008-11-17

orkut-logo.jpg

Spammers and other cyber-criminals are increasingly using social networking sites to spread their malicious content. Recently we have informed you about new spam campaigns targeting Hi5 and Facebook web sites. This time researchers from Websense Security Labs have discovered a new malicious social-engineering spam campaign being spread as official emails from Orkut web site.

Orkut is a Web 2.0 social networking site run by Google. The service states that it was designed to help users meet new friends and maintain existing relationships. Everybody can join Orkut with their Google account and start creating their profile and communicating with friends. This social networking site is one of the most popular social networking sites in Latin America (the most visited in Brazil) and the second most visited site in India.

The spam message that potential victims receive appears to be from the domain google.com. The spoofed email informs recipients that their Orkut account is being investigated and will be terminated within 72 hours. If they don't want their account to be closed users are prompted to click on the provided link and follow the necessary instructions.

Below you can see a screenshot of a sample email:

orkut_spam.PNG

After clicking on the provided link, the user will get a malicious executable file installed in his or her computer. This is a Trojan Downloader called "regulamento_orkut.exe" (SHA1:8eb1366d580aeab38d00a5c32835006c3648b8f3). The problem with this executable is that it has a very low detection by anti-virus software. Moreover, when run, this malicious executable file will download one more malicious file "fax.exe (SHA1: 8e1df3d55a778550affea7c5216e58a55beaf979). The second malicious file copies itself to multiple locations on the infected machine with different names. It will also add itself to startup and monitor browser activities so as to steal user information.

Below you can see a screenshot showing the malicious "fax.exe" downloaded onto the infected computer:

orkut_alert.PNG

Once more everybody is warned to look with suspicion at any unsolicited emails and links that recipients are prompted to follow. The best solution in this situation would be to delete any similar emails even without reading them. In case you think that the received email is not part of spam campaign, you must be 100% sure of its legitimacy before clicking on any of the provided links or attached files. Of course, you should also don't forget to keep anti-spam filters and anti-virus software up-to-date.

http://www.pc1news.com/downloads/registry-medic-960.html

User Comments

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Latest Comments

2009-01-04 09:38:26
I need to change reg value for a local user ......... Plz help more..
2009-01-03 15:53:35
I removed all autorun.inf files from my system, found no otorun files or folders but still the virus... more..
2009-01-02 13:45:14
Larry, Wow! I can't believe it. We will look into this on Monday. Have a good weekend... more..
2009-01-02 10:25:30
The author obviously has no understanding of how memory is managed in a virtual memory system. To improve... more..
2008-12-31 07:59:11
please how to desiable local group policies in gp more..
more comments..
rss
Home > E-mail > Social Networking Sites under Spammers’ Attack: Spoofed Orkut Emails!