Anti Virus Softwares

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label facebook. Show all posts
Showing posts with label facebook. Show all posts

Wednesday, 4 August 2010

PhacePhish: New Facebook Attack gives a One-Two Punch

Posted on 00:42 by Unknown
Tonight I had a message from one of my Facebook friends who was concerned that someone may have hacked her Facebook account. She was worried that she might get a virus by looking at the links they had posted on her behalf. I assured her not to worry -- if her Facebook account was sending links to other people's walls, she probably already had a virus. After digging a bit deeper, I'm not so sure.

The "One-Two" punch of this current Facebook attack is similar to some of the spamming malware. Some of the messages it sends are to generate profit for the cybercriminal, and some of the messages are to infect more users to build the criminal's delivery network.

Here is the first type of message -- the "profit" message:



This reminds me of a current "work at home mom" trend that some of my other friends are engaging in. There really is a weight loss multi-level marketing scheme right now where the participants are encouraged to make a website telling about "the plan" and then are told that making money is as easy as following the plan yourself, and posting your weight loss reports to all your Facebook friends. (Hope your happy and skinny, DG, I wouldn't know, I blocked you on facebook as soon as you started that crap!)

What happens if you follow the link? The link doesn't go to my friend's weight loss page. It goes to an Acai Berry affiliate sales "news" page that is supposed to look like a real "news" site that just happens to be featuring a story about the miracle of the Acai Berry.



Clicking anywhere on the "news" page takes you first to an affiliate tracker page:

tracker.cpaprosperity.net/affe?offer_id=500&aff_id=1161

and then to the sales page for their diet plan:

acaioptimum.com/?afil=az1007

The diet scam page is hosted by Black Rock Hosting on the IP address 64.38.201.205.

That was the "One" . . . here comes the "Two" of our One-Two Punch:



What's the other important purpose for Facebook besides getting your friends to join your Multi-Level Marketing Weightloss plan? Sending stupid videos to one another, right? Everyone knows that when one of your friends posts a link, you are required to immediately click on it, and the click the "Like" button. This is how people know that we are their friends. We "Like" all their stupid videos.

(Actually, I'm a big Facebook fan. My family communicates like crazy with it, and I enjoy sharing pictures with my friends and playing Bejeweled Blitz. But this is the part where I'm supposed to be all sarcastic...)

So, when my friend BG posted this message to all of her friends' walls, what would happen if they clicked on it?

The first thing is that it sends you to a website called "securitymeassures3.co.tv". That page is going to call some Javascript to find out what country you are in:



If you are in the US, you then load the webpage "explororjones.com/deel/deeus/"

If you are anywhere else in the world, you then load the webpage "explororjones.com/deel/deeint/"

Either way, the page that loads looks like this:



WAIT! How did I get logged out of Facebook? (you are supposed to say to yourself...) then you quickly type in your userid and password for Facebook on this other page, which is actually at "explororjones.com"

ExplororJones is hosted on that excellent Netherlands hosting company Worldstream. I don't recall Facebook moving their operations there. When a webpage that isn't really the company you are trying to log in to tries to convince you to login on the fake web page we call that phishing.

That's why I'm calling this particular attack "PhacePhish" - most phishing attacks start with a spam message that sends you a scary reason that you really need to log in to your bank RIGHT NOW. This one starts with a spammy Facebook message instead.

Sooo...does my friend have a virus?

No, its very very probable that my friend clicked on a "funny baby" or some other leading video on one of her friends' Facebook posts, believed she was logged out of Facebook, and logged back in, giving her password to the criminals. The criminals then can login as my friend and repost the message on all of their facebook pages. If they fall for it, then they'll tell their friends, and they'll tell their friends, and they'll tell their friends, and pretty soon we'll all be skinny and rich! Happy ending!

I'd call my friend and tell her all of this, but its 3:00 AM. I'll let her sleep a bit more while the criminals spread their message through her Facebook account. Wonder if the Facebook guys are awake . . . hmmmmmmmm....
Read More
Posted in facebook, phishing | No comments

Tuesday, 1 June 2010

VirtualJihad against Facebook

Posted on 11:38 by Unknown
On May 20th, a group who claim to be motivated by various "Freedom of Expression" announced that they were holding "Everybody Draw Mohammad Day". As everyone knows by know, on September 30, 2005, a Danish newspaper chose to publish several cartoons of the Prophet Mohammed, including one of the prophet with his turban containing a bomb, which was drawn by Kurt Westergaard. This was the first many Westerners learned of the Islamic tradition that the prophet should never be depicted. The controversy has continued since then, with various papers reprinting the cartoons, and various Islamic nations then banning those papers, or calling for acts of violence against their editors. In January of 2010, Westergaard's home was broken into by an Islamic man who chopped through his door with an axe and desired to kill him with a knife.

The current "Everybody Draw Mohammed Day" craze was not inspired by Westergaard, but rather by death threats against the SouthPark artists, Matt Stone and Trey Parker, who depicted the Prophet Mohammed wearing a bear suit. Seattle-based cartoonist Molly Norris ran a cartoon suggesting that May 20th, be declared "Everybody Draw Mohammed Day" sponsored by "Citizens Against Citizens Against Humor or CACAH", which she has now retracted by scribbling notes on her own cartoon:



Unfortunately for Molly, many folks took her seriously, creating a special website to receive their submitted drawings, and more relevantly to our topic today, they also created a Facebook group, "Everybody Draw Mohammed Day."




The creation of the Facebook Group lead to several national bans of Facebook, including bans by Pakistan, Bangladesh, and the United Arab Eremites. The UAE and Saudi Arabia both made "line item veto" bans blocking only the offending group on Facebook, while the first two banned the entire website. (Update: Pakistan lifted their "blanket" ban on May 31st after Facebook actually censored the offending group.)




Pakistani media reported that "hacking fraternities" were being formed to "take revenge" on the "blasphemous companies". Pakistani residents have reported receiving SMS text messages encouraging them to participate in DDOS attacks. The website "drawmohammed.com" has also been repeatedly defaced by Islamic hackers since this event began.

Perhaps the most outrageous response has been the encouragement to download the attack tool that is being spread to help people DDOS.

The Google Group "Muslims United" was created May 19th and has been actively attacking "offensive" websites. The main banner proclaims the site to be the "Anti-Draw-Muhammad (P.B.U.H.) -DAY", and currently has 1800 messages. Several of these relate to the "virtualjihad.net" website, where the DDOS tool is included.





VirtualJihad.net was registered on May 19th from the website "www.secsupport.com", a reseller for Directi's PublicDomainRegistry.com.

The website is hosted on the IP, 75.126.169.149, hosted by SoftLayer.com, right here in the USA.

The tool has a pull-down menu, allowing the user to choose whether he wants to attack "www.muhammadture.com", "www.drawmuhammadday.com", or "www.facebook.com".

Their website claims they have 34,306 people actively attacking with their tool at this time. The organizers, using the email "info@virtualjihad.net", claim to be reachable via MSN, GoogleTalk, or Skype as well as email.
Read More
Posted in facebook, pharmaceuticals | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • From Russia, With Love . . . new Postcard spam spies on your PC
    Isn't it nice to have friends who send you postcards? The UAB Spam Data Mine is especially fortunate in that way. Beginning the evenin...
  • Happy New Year! Here's a Virus! (New Year's Postcard malware)
    I've been busy this week looking at the various defacements (see ComputerWorld , and ABC News ) and other cyber attacks (see yesterday...
  • Tempting Photo Attachments Lead to Fake AV
    One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, fo...
  • A Prominent American Express Phish
    Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has ju...
  • Fake AV Malware Hits the Android
    Mobile Defender - the last line of protection Having studied malware delivered by spam for the past seven years, it is a fairly rare event f...
  • When Parked Domains Still Infect - Internet.bs and ZeroPark
    Last night I was discussing the Kelihos botnet with some friends. There had been several previous attempts to “Kill Kelihos” and I decided ...
  • Cross Brand Intelligence and Phishing
    While there is certainly a reason to shut down any site imitating your company as fast as possible, we have to always consider what the impl...
  • Anonymous, #OpBankster, and the Too Many Nancy's Problem
    The current Anonymous "#OpBanksters" seems to have very little in common with the original operation by the Anonymous Portuguese g...
  • Vista Security Features
    BitLocker Drive Encryption A Real-world Windows Vista BitLocker Tip BitLocker Drive Encryption BitLocker Drive Encryption Frequently Asked Q...
  • 2008: Looking back on a Year of Spam and Malware
    Happy New Year! As we get ready for the New Year, there are quite a few security folks making predictions for 2009. I think my friend Dan...

Categories

  • Blogs
  • Calendar
  • china
  • Communities
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • Drivers
  • email
  • Excel 2007
  • facebook
  • fake av
  • Features
  • Firewall
  • Gadgets
  • gumblar
  • Hardware
  • Hotmail
  • IE7
  • Internet Explorer 7
  • koobface
  • law enforcement
  • malware
  • Microsoft
  • Outlook
  • pharmaceuticals
  • phishing
  • PowerPoint 2007
  • public policy
  • Ready Boost
  • ReadyBoost
  • Security
  • Sidebar
  • Software
  • spam
  • Tutorials
  • twitter
  • twitter malware
  • USB
  • Virtual PC
  • Vista
  • waledac
  • Wallpaper
  • Websites
  • Windows
  • Windows Live
  • Windows Vista
  • Word 2007
  • zbot

Blog Archive

  • ▼  2013 (17)
    • ▼  November (1)
      • Tempting Photo Attachments Lead to Fake AV
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (93)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (7)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (109)
    • ►  December (7)
    • ►  November (17)
    • ►  October (12)
    • ►  September (10)
    • ►  August (23)
    • ►  July (14)
    • ►  June (3)
    • ►  May (8)
    • ►  April (6)
    • ►  March (2)
    • ►  February (3)
    • ►  January (4)
  • ►  2007 (37)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  April (2)
    • ►  March (2)
    • ►  February (2)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile