Categorized | Security

Email with new password from Facebook Support contains trojan

MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the message that your facebook account has been blocked because of spam that was sent from your account. The email indicates that the password of your account has been reset and that you should open the attached document with your new password.

Following subjects are possible – or similar:

Facebook Service. Your password has been changed. ID309
Facebook Service.Your acciunt is blocked. ID799
Facebook Support. Your password has been changed. ID991
Facebook Support. A new password is sent  to you. 920

The email is send from the spoofed address “Facebook office <donotreply.nr.6170@facebook.com>” – note that the from before the @ changes with each email – and has the following body:

This is a post notification!

A spam is sent from your Facebook account.
Your password has been changed for safety.

Information regarding your account and a new password is attached to the letter.
Read this information thoroughly and change the password to complicated one.

Thank you for your attention,
Facebook Service.

The attachedZIP file has the name Facebook_document_Nr59469.zip and contains the folder Facebook_document with inside the 60 kB large file Facebook_document.exe.

The trojan is known as Trojan.Win32.Oficla (Ikarus), W32/Trojan3.CIG (F-Prot), Trojan:Win32/Oficla.AE (Microsoft), Trojan.Sasfis (Symantec).

The following files will be created:

%Temp%.tmp
%System%\ttux.qqo
%Temp%.tmp

Several Windows registry changes will be exectued and the trojan can establish connection with the following IPs on port 80:

85.195.104.161
91.204.48.46

Data can be obtained from following URLs:

* http://pupmypzed.ru/alimp/bb.php?v=200&id=738176302&b=1711_fa&tm=1
* http://pupmypzed.ru/alimp/bb.php?v=200&id=738176302&tid=4&b=1711_fa&r=1&tm=1
* http://91.204.48.46/test/dot.exe

Virus Total permlink and MD5: 16e7189085f1135d0ee38b56928811be.

Source: mxlab – all about anti virus and anti spam

Related Posts

ttux qqo

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago