For those of you that use Facebook

Status
Not open for further replies.

SagaLore

Elite Member
Dec 18, 2001
24,036
21
81
One of my friends must have clicked a bad link, got themselves infected, which then sent more bad links to everyone. :p I just wrote up an article on it:

http://www.antisource.com/arti...ebook-yuotube-koobface

Today I received an odd message in Facebook. It came from a friend of mine and sent to many people at once. It was littered with spelling and grammar mistakes, with a link to some obscure youtube lookalike. But it is not youtube.

Subject: Hallo.
Message:

Whhat a shame,, you got so busted!!
[link]

(I have removed the domain so people don't accidentally click the link)

That was it. If you click it, you're brought to a page that looks like this:

[screenshot]

Except that it will use the name of the Facebook member that allegedly sent you the message, along with their profile picture. You'll notice that on this fake page the title is misspelled with YuoTube :: Broadcast Yourself :: Video post by (FB member name).

The page is hosted on a server with IP address 94.112.62.161, which is registered to the Czech Republic. For any admins that allow Facebook access at their company, I advise blocking this IP address on the firewall.

You are required to install "Adobe Flash Player 10.37". If you click anywhere on the page, you are then prompted to download setup.exe from the site. It is exactly 30,720 bytes in size - its MD5 hash is 3b0c0c5ace8390f6160471ef8012863c. I uploaded this to VirusTotal, and as of right now the antivirus vendors detect it as:

eSafe: Suspicious File
F-Secure: Suspicious:W32/Malware!Gemini
Kaspersky: Net-Worm.Win32.Koobface.es
Artemis: Generic!Artemis
Microsoft: Worm:Win32/Koobface.I
NOD32: a variant of Win32/Koobface.NAO
Panda: Suspicious file
Sophos: W32/Koobfa-Gen
Symantec: Suspicious.MH690.A
TrendMicro: PAK_Generic.001

This is a worm that is spread by social engineering with social networking sites, such as Facebook and Myspace. More info about the worm itself can be found here:

http://www.kaspersky.com/news?id=207575670
 

OUCaptain

Golden Member
Nov 21, 2007
1,522
0
0
I click suspicious links as much as I walk into side alley bars with crack whores standing outside

Thats why I managed to make it 4 years with no anti virus program.
 

LikeLinus

Lifer
Jul 25, 2001
11,518
670
126
Originally posted by: OUCaptain
I click suspicious links as much as I walk into side alley bars with crack whores standing outside

Thats why I managed to make it 4 years with no anti virus program.

So, how exactly do you know that you don't have a trojan? Oh, you don't if you don't use anything. Stupid.
 

Red Squirrel

No Lifer
May 24, 2003
70,674
13,836
126
www.anyf.ca
lol it's like those stupid msn viruses. I've had to block members of my family because they have me in their MSN and got their PC infected so I get sent advertisements from them.
 

OUCaptain

Golden Member
Nov 21, 2007
1,522
0
0
Originally posted by: LikeLinus
Originally posted by: OUCaptain
I click suspicious links as much as I walk into side alley bars with crack whores standing outside

Thats why I managed to make it 4 years with no anti virus program.

So, how exactly do you know that you don't have a trojan? Oh, you don't if you don't use anything. Stupid.

Sorry, let me clarify. I don't run antivirus all the time. I'll install avg if something funny is going on then remove it once I solve the funnyness. So far, haven't been infected in 4 years.

and you're stupid
 
Status
Not open for further replies.