Categorized | Antivirus, Emsisoft

Warning: Surprise spam trojan on Facebook

Emsisoft - Ever received messages from your Facebook friends containing a notice or invitation, such as an invitation to visit a particular site, added with an interesting message, like “Hey watch this, so cool!”? In most cases, the recipient of the message will be happy to follow it, especially if the message was sent by one of your best friends, which you trust. However, did you ever think that it could be sent by an intruder, spam, or even viruses?

Like yesterday, one of my friends received a “surprise” from Facebook, but then soon realized that his computer was now infected with the trojan, as well as making it a “spam machine.”

As you can see, the site was not the original of Facebook, but “hxxp://facebook-surprise-kjeg.tk/”. Through social engineering techniques, the author deliberately makes the site look like the original one, of course, to give users a false sense of security.

And when the mouse is hovering at that page, it would seem that it is a link that leads to the file “suprise.exe” (hxxp://facebook-surprise-kjeg.tk/surprise.exe). The file itself is using an icon that similar to the default icon of image file:

Once the user runs the file, it will only display a “gift” image like this:

But, without realizing it, a Trojan infecting the computers in the background.

Apparently, it all comes from a message that he received on his Facebook account. The messages look like this: “I got u surprise www.nyhelyofedoerej.blogspot.com.”

When the link is clicked it will lead to an account on Blogspot, and then it is redirected again to hxxp://facebook-surprise-kjeg.tk/.

Once the file “surprise.exe” is executed, it will then monitor all user activity, by injecting itself to the active browser, such as Internet Explorer or Mozilla Firefox. If the user tries to login into his Facebook account, the malware will record the username and password, to be used to spamming to every friend on the Facebook account. Users can find out by looking at the folder “sent”.

Interestingly, the author tells us what he was doing behind the scenes (or he forgot to remove the debug string?). These messages will appear when we run the debugger, or DebugView to monitor debug output. We obtain the following log when the malware is trying to login into the facebook account:

And the following when the trojan did spam to all friends in the Facebook account:

Before doing spam, it performs the GET request to address “ddk1000.org/ab/setup.php?act=fb_get” to obtain data used for spam, such as subject, message body, and the malicious url that is used for spam. The data is a string like this:

<data>3000|140000|Hello|I got u surprise |My Dear Friend u should look for |I have surprise for u
[www.ebyqerapinylyrato.blogspot.com|www.udenaqylinabig.blogspot.com|www.kuopyqupisee.blogspot.com|
www.sebafelumunynuly.blogspot.com|www.sypupolufoigirisyc.blogspot.com|www.ogyohanofaeqis.blogspot.com|
www.juyeliadileqaq.blogspot.com|www.gyseuodysecu.blogspot.com|www.pucoriiukiylyfo.blogspot.com|
www.yycugecuisehe.blogspot.com|www.nyhelyofedoerej.blogspot.com|www.teejoubiimanuh.blogspot.com|
www.timeteobyqufousy.blogspot.com|www.ooapetyuqatoda.blogspot.com|www.okojylimukikap.blogspot.com|
www.milurudutyfebusab.blogspot.com]</data>

Following is the malicious site that we get from the data above (please don’t visit, some link are still active):

  • hxxp://ebyqerapinylyrato.blogspot.com
  • hxxp://udenaqylinabig.blogspot.com
  • hxxp://kuopyqupisee.blogspot.com
  • hxxp://sebafelumunynuly.blogspot.com
  • hxxp://sypupolufoigirisyc.blogspot.com
  • hxxp://ogyohanofaeqis.blogspot.com
  • hxxp://juyeliadileqaq.blogspot.com
  • hxxp://gyseuodysecu.blogspot.com
  • hxxp://pucoriiukiylyfo.blogspot.com
  • hxxp://yycugecuisehe.blogspot.com
  • hxxp://nyhelyofedoerej.blogspot.com
  • hxxp://teejoubiimanuh.blogspot.com
  • hxxp://timeteobyqufousy.blogspot.com
  • hxxp://ooapetyuqatoda.blogspot.com
  • hxxp://okojylimukikap.blogspot.com
  • hxxp://milurudutyfebusab.blogspot.com

We detect this malware as Trojan-Downloader.Win32.FraudLoad!IK.

Always stay alert and be cautious with everything you receive. And don’t forget to update your Emsisoft Anti-Malware.

Full story: Emsisoft Blog

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago