Archive for the ‘Social Networking’ Category

Invitation card means trouble

March 11th, 2010

Our Director of Marketing got this nice piece of spam today:

Subject: Jessica would like to be your friend on hi5!

I set up a hi5 profile and I want to add you as a friend so we can share pictures and start building our network. First see your invitation card I attached! Once you join, you will have a chance to create a profile, share pictures, and find friends.

Attachment:  Invitation Card.zip

Forgive my lack of interest for social networking sites, at first I though hi5 was a highway down in the States ;-)

But no, it actually is a (virtual) place to hang out with your friends.

Back to the spam, the invitation card from Jessica comes as a zip file attached to the email.

When unzipped you will see this:

Why the Chrome icon? Not sure? But what the bad guys want you to believe is that this is a PDF file.

In reality it is an executable (.EXE); they added a lot of blank spaces in the file name to make it less obvious:

This file is malware (full VirusTotal detection here).

Spam campaigns can be very targeted or just a large attempt – en masse – with the hope of getting a few innocent people fall for it. Whether it’d be a file attachment or a URL in an email, the bad guys want you to open that file or click on that link. They know their sole chance of success relies on the end user making the bad decision.

Emails coming even from people you may know can be spoofed easily. For example the sender in that case is: invitations@hi5.com, which looks totally legitimate. Despite good spam filters and AV protection, such emails can make it through, so please exercise caution and report them immediately to help protect other users.

Jerome Segura

  • Posted in Social Networking, scams
  • |
  • (0) comments
  • |
  • Add your comments

Xbox forum spam leads to malware, drugs

December 31st, 2009

Did you get an Xbox for Christmas? Have you been going on forums to share stuff with other users?

Well, beware of fake accounts posting links to external sources.

The following XBOX site (xbox360achievements.org) contains a lot of spam:

myx1

Here is an example of social engineering: it has nothing to do with the XBOX but it’s a ‘nude video’. Lots of people are going to click on that one.

myx2

You are redirected to another site: {removed}sextape.blogspot.com
(By the way, blogspot does redirect to an awful lot of malware hosts)

myx3

Which opens another page: the{removed}vid.cn/broadcast/no.php?v=Sex+Tape

myx4

The ‘flash player’ is in fact a Trojan.

Virus Total report here. 

When those spam posts in the XBOX forum are not redirecting to malware, they link to ‘pharmaceutical’ websites:

pharm

Forum webmasters have a responsibility in the content that is being posted. Advanced Google searches can identify a lot of spam. That is how a lot of security researchers find malicious links, simply by googling!

Below is an example of a search to display all pages containing the word ‘nude’ on that particular site. Feel free to use any keyword that is typically used in spam (it involves porn, drugs etc.)

search

Below are some of the bogus accounts posting links to malicious sites:

hacked

It should be easy to terminate them and prevent innocent users from being exposed to malicious content.

Jerome Segura

  • Posted in Exploits, Social Networking
  • |
  • (0) comments
  • |
  • Add your comments

Anatomy of Twitter social engineering

September 27th, 2009

I can immediately tell when someone who is following me on Twitter is not genuine (especially if it’s a hot girl half naked).

The social engineering on Twitter is getting much better these days. It used to be a profile with just one tweet: a spam URL. Now, the profile actually looks legit with regular updates that give you the feeling this is a real person there.

Such as “Lucia756 is making pancakes!! :) ”

twat

You could not be any more wrong. These profiles are automated, they are fake, and their sole purpose is to make you click on a link that redirects to either exploits, phishing pages, or Adware.

thwats

In this case, it is Adware with the webfetti toolbar, AKA FunWebProducts, MyWebSearch, CursorMania, SmileyCentral, Zwinky, MyWay Searchbar, etc…  is that a long list or what?

webfetti

I think I’m going to keep my Twitter profile public… Such things are very annoying… but they allow me to blog about malware practices that will affect many users out there.

Jerome Segura

  • Posted in Social Networking
  • |
  • (0) comments
  • |
  • Add your comments

More XXXblackbook spam on Twitter

August 30th, 2009

There has been a wave of automated followers on Twitter promoting the adult dating site xxxblackbook.

Social engineering tricks are used, such as your regular newspapers’ headlines.

tw

The link redirects you to an adult site, as mentioned above. Not sure this will help you if you are unemployed….

tw2

I’m seriously considering locking up my Twitter account now…

Jerome Segura

  • Posted in Social Networking
  • |
  • (0) comments
  • |
  • Add your comments

Twitter raids

August 26th, 2009

You know sometimes I forget how much hatred there is in our world.

There are people out there that plan attacks against individuals, companies, or popular websites as part of their daily activities.

They get together and plan ‘raids’ on IRC channels. In the pic below, if you click on the ‘visit this page’ you get redirected to a horrible rickrolling page. Why are there such sick people out there?

tweet

This site aims at attacking Twitter. It teaches you how to create Bots and other things to become a hacker.

(Warning! offensive language)

tweet3

This screen below shows a Bot written in Perl which purpose is to retweet every tweet mentioning a certain keyword.

tweet2

What can I say? I’ve noticed Twitter has been very slow at times lately and I’m sure it gets abused a lot on a daily basis.

I think such reminders are good every once in a while to keep your guards up.

Jerome Segura

  • Posted in Social Networking
  • |
  • (0) comments
  • |
  • Add your comments

A rather raunchy linkedin profile

August 25th, 2009

The popular social networking site linkedin is constantly the victim of fake profile pages.

Check this one out though, and tell me there truly is nothing you can do to weed out a ‘fake’ profile.

Warning! Offensive language.

linkedin

And the free sex clips redirect to this page which serves both Windows and Mac Trojans.

sitestube.com/xplaymovie.php?id=45145

linkedin2

File detection on Virus Total:

vt

Jerome Segura

Malware ID: 621696054e4d31d03ce13467ba22b53d.zip

  • Posted in Social Networking
  • |
  • (0) comments
  • |
  • Add your comments




Location

You are currently browsing the archives for the Social Networking category.




ParetoLogic, a Microsoft Certified Partner

 

RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site
Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • URL Clearing House
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (4)
  • Botnets (3)
  • Conferences (4)
  • DDos (1)
  • Exploits (48)
  • Fake codecs (38)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (2)
  • Mac security (15)
  • Malware Trends (69)
  • Phishing (8)
  • Podcast (1)
  • ransomware (5)
  • Research (46)
  • Rogue software (53)
  • Rootkits (2)
  • scams (9)
  • Social Networking (6)
  • Uncategorized (118)
  • Wireless Security (2)
  • world map (1)



 
 
 
Microsoft is a registered trademark of Microsoft Corporation in the United States and/or other countries.

© 2010 ParetoLogic Inc.