<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Social Media</title><link>http://pandalabs.pandasecurity.com/archive/tags/Social+Media/default.aspx</link><description>Tags: Social Media</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Koobface.DU returns to Twitter</title><link>http://pandalabs.pandasecurity.com/archive/Koobface.DU-returns-to-Twitter.aspx</link><pubDate>Fri, 10 Jul 2009 10:15:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1016</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1016.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1016</wfw:commentRss><description>&lt;p&gt;A few days ago the Koobface worm started to &lt;a href="http://blogs.zdnet.com/security/?p=3706"&gt;appear on Twitter&lt;/a&gt;.&amp;nbsp; Today, the Koobface worm returns by hijacking several  Twitter user accounts to assist in propagating the worm. &amp;nbsp;The malicious tweets start with the text &amp;ldquo;My  Home Video :)&amp;rdquo; followed by a link to one of 20 or so malicious sites.&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
    &lt;a href="http://www.flickr.com/photos/lithium-/3706927216/sizes/o/"&gt;&lt;img alt="Koobface.DU.worm | Twitter Search" border="0" src="http://farm4.static.flickr.com/3528/3706927216_99a082788d.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
  &lt;br /&gt;
  Once on the malicious site, the victim becomes assaulted  with a fake flash update and the infection starts to communicate with Facebook  and Twitter immediately after downloading two additional executables from a domain hosted in Belgium.&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3706115111/sizes/o/"&gt;&lt;img alt="Koobface.DU.worm | Flash Check" border="0" src="http://farm3.static.flickr.com/2590/3706115111_4846502252.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Fake codec site:&lt;/strong&gt;&lt;br /&gt;
  &lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3706115163/sizes/o/"&gt;&lt;img alt="Koobface.DU.worm Download " border="0" src="http://farm3.static.flickr.com/2564/3706115163_5012c2c49d.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connections:&lt;/strong&gt;&lt;br /&gt;
  &lt;br /&gt;
    &lt;a href="http://www.flickr.com/photos/lithium-/3706927296/sizes/o/"&gt;&lt;img alt="Koobface.DU.worm Connections" border="0" height="210" src="http://farm3.static.flickr.com/2562/3706927296_02ce593bc7.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
  &lt;br /&gt;
  After attempting to spread the infection on Facebook and  Twitter, the W32/Koobface.DU.worm further capitalizes on its efforts by  installing the Adware/InternetAntivirusPro Rogue Antivirus.&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3706927354/sizes/o/"&gt;&lt;img alt="Koobface.DU.worm | Rogueware" border="0" src="http://farm3.static.flickr.com/2602/3706927354_985c5d1844.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Twitter has &lt;a href="http://status.twitter.com/post/138789881/koobface-malware-attack"&gt;responded&lt;/a&gt; to the threat quickly and have already made an effort of removing the malicious tweets. We detected around 100 still active malicious tweets at the time of writing this.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Visual representation of malicious tweets:&lt;/strong&gt;&lt;br /&gt;
  
    &lt;br /&gt;
 &lt;a href="http://www.flickr.com/photos/lithium-/3706927278/sizes/o/"&gt;&lt;img alt="Koobface.DU.worm | Visual Twitter Representation" border="0" src="http://farm4.static.flickr.com/3458/3706927278_d08e0436b4.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1016" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Media/default.aspx">Social Media</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware_3A00_+Worms/default.aspx">Rogueware: Worms</category></item><item><title>Malware in Social Media</title><link>http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx</link><pubDate>Thu, 26 Feb 2009 17:17:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:972</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/972.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=972</wfw:commentRss><description>
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;A few weeks ago we talked about &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/Have-you-ever-heard-the-term-_2200_Rickrolling_22003F00_-Malware-distributors-have_2E002E002E00_.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;cyber-criminals using Digg.com to spread malware&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Today we see that the very same group responsible for the Digg.com incident was using the same tactic on YouTube through the use of YouTube&amp;#39;s Annotations feature. &lt;/font&gt;&lt;a href="http://www.youtube.com/t/annotations_about" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Video Annotations&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; is a way to add interactive commentary to videos on YouTube. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The following image displays a video using the annotations feature to guide users over to a malware ridden website:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="363" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/02/26/MWYoutube.png" style="width:700px;height:363px;" width="700" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Although the YouTube description malware is not as prevalent as the Digg.com comment abuse, it does show that Social Media websites are increasingly being used to spread Malware. We expect to see plenty of new examples similar to this throughout 2009. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Thanks to &lt;a href="http://ddanchev.blogspot.com/" target="_blank"&gt;Dancho Danchev&lt;/a&gt; for the information. &lt;br /&gt;
&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=972" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Media/default.aspx">Social Media</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/PornTube/default.aspx">PornTube</category></item></channel></rss>