Categorized | CA Technologies

Facebook Password Has Been Changed…NOT!

We’ve already seen spam campaign theme that uses one of the famous Social Networking sites, Facebook. Like, Facebook Password Reset Confirmation, New login system, and Facebook updated account agreement.

CA ISBU came across an active spam email campaign containing a malware as file attachment, as seen on [Figure 1]. The spam mail informs the recipient that their password is not safe and it has been changed automatically by Facebook. It requires recipients to check the attachment containing the new password.

                   

                                                                  [Figure 1 - Fake Facebook email]

The email contains the Subject: Facebook. The new password to your account. N8601

The email contains the Body:

——————————————————————————————————–

Dear user of FaceBook.

Your password is not safe!
To secure your account the password has been changed automatically.

Attached document contains a new password to your account and detailed information about new security measures.

Thank you for attention,
Your Facebook

——————————————————————————————————–

Other emails may contain the following Subjects:

  • Facebook password has been changed.
  • Facebook Support. Personal data has been changed! ID#####
  • Password has been changed. ID####

The email contains a malicious zipped file attachment with the filename New_Password_IN#####.zip and New_Password_NU####.zip. This file is detected by CA as a Win32/Bredolab variant.

***where ##### is 4 or 5 random number.

Again, we advise users to beware of these kinds of emails, avoid executing attachments coming from unsolicited emails and ensure that your CA Security Products are updated with the latest signatures.

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago