Categorized | Antivirus

Warning About Spam Fake, Not from Facebook

Facebook is undoubtedly the highest-profile social networking site around with more than 500 million active users, half of whom log in on any given day. It shouldn’t be a surprise therefore that its name is now being used for scams—even for things that don’t have anything to do with social networking.

Earlier this week, we received fake email messages that purportedly came from Facebook. These spammed messages, written in very bad English, warned users that their IP addresses were sending numerous spammed messages to different email addresses.

The spammed message also says that Facebook thoughtfully provided a freeware tool to stop the user from spamming others. Opening the tool, which the message calls FB IPsecure, shows:

Unsurprisingly, however, the tool is actually a malicious file. It is a ZeuS variant Trend Micro detects as TSPY_ZBOT.XXT. Given that malicious attachments are a favored way of spreading ZeuS variants, this isn’t really new. In terms of behavior, nothing separates this particular variant from others that are in the wild today.

Trend Micro products protect users by detecting the malicious file as well as by detecting and blocking this particular spammed message from landing in users’ inboxes. We also advise all users to be very careful about opening attachments from unknown people in general, as these are frequently malicious and may cause harm and infect their systems. In particular, messages that supposedly come from reputable sites like Facebook but contain plenty of grammatical and spelling mistakes should be treated as very suspicious.

– Merianne Polintan (Anti-spam Research Engineer) on TrendLabs | Malware Blog – by Trend Micro

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago