Categorized | Facebook, Quick Heal

Trojan Spreading through Facebook chat.

Facebook photos have become a new target for cyberthieves looking to direct users to malicious sites. Recently spam chat and email message were sent from compromised Facebook user account to their friend list.

The Facebook chat messages include text such as “hahahah foto” and the phony Facebook application pages. Clicking on the link, to look the photo will redirect users to a malicious page that will attempt to infect their systems with malware.

The file present itself as an image file but actually is a executable binary. If user try to view the image by double clicking it, malware will get execute.

In our control environment at Quick Heal Viruslab we executed and checked for its activity and found that it was redirecting to a website flashing message that the web browser needs to be upgraded.

Then malware established connection with remote IRC Server as below.
nick=”NEW-[USA|00|P|12397]”
username=”XP-4911″
password=”xxx”
JOIN #!nn!
testMODE [USA|00|P|88251] -ix
testPONG 22 MOTD

The malware also silently connected to below websites.
“xxxxx.ic.ac.uk”
“ale.xxxxx.com”
“verxxxxx.com”
“api.axxxxxory.info”

Anybody’s curiosity will increase after seeing such easy steps of online money making. Finally it diverts user to a page asking for paying some security deposits to them.

These all are fake notifications. The malware was trying to play a prank by such fake easy money making methods. Please avoid paying them.

Quick Heal detect this Trojan threat by “Trojan.Agent.fb”

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago