<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Facebook.com</title><link>http://pandalabs.pandasecurity.com/archive/tags/Facebook.com/default.aspx</link><description>Tags: Facebook.com</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Malware Impersonates Classmates and Facebook Websites to Deliver Password Stealing Trojan</title><link>http://pandalabs.pandasecurity.com/archive/Malware-Impersonates-Classmates-and-Facebook-to-Deliver-Password-Stealing-Trojan.aspx</link><pubDate>Thu, 12 Mar 2009 08:38:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:981</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/981.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=981</wfw:commentRss><description>&lt;p&gt;&lt;br /&gt;
  Websites  designed to look like Classmates.com and Facebook are currently being used to  distribute a password stealing Trojan, which we detect as &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=206993&amp;amp;sitepanda=particulares"&gt;Trj/Spyforms.BZ&lt;/a&gt;. &amp;nbsp;&amp;nbsp;Some of you may remember the Spyforms Malware  family from a &lt;a href="http://pandalabs.pandasecurity.com/archive/Barack-Obama_2700_s-Spam-_2600_-Malware-Campaign.aspx"&gt;previous  incident&lt;/a&gt; involving Barack Obama spam campaigns. In this most recent  incident, the malicious web links are still primarily distributed via spam  e-mails. Once clicked, the victim is presented with a realistic looking  Classmates or Facebook website.&amp;nbsp; The website  contains a fake YouTube video, which prompts a dialog stating &amp;ldquo;Please Download  correct Flash Movie Player!&amp;nbsp;  Installation: Double-click the downloaded installer.&amp;nbsp; Follow the on-screen instructions!&amp;rdquo; and  attempts to download a file named Adobemedia10.exe or Adobemedia11.exe.&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Fake Classmates.com Malware Site" border="0" height="488" src="http://support.us.pandasecurity.com/Blog/classmates.jpg" width="624" /&gt; &lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Fake Facebook Malware Site" border="0" height="486" src="http://support.us.pandasecurity.com/Blog/facebook.jpg" width="624" /&gt;&lt;br /&gt;
  &lt;br /&gt;
Once installed, the Trojan intercepts network  traffic in order to obtain ftp, icq, pop3, and imap passwords and then sends  the data back to a server in a Hong Kong based ISP (HOSTFRESH).&amp;nbsp; You may recall the last major Malware  incident involving the Hong Kong based ISP, which was one of the providers  involved in the malware distribution operation taking place inside of the &lt;a href="http://hostexploit.com/downloads/Atrivo%20white%20paper%20082808ac.pdf"&gt;Atrivo/Intercage&lt;/a&gt; network.
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=981" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Facebook.com/default.aspx">Facebook.com</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Hostfresh/default.aspx">Hostfresh</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Spyforms/default.aspx">Spyforms</category></item></channel></rss>