<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Twitter</title><link>http://pandalabs.pandasecurity.com/archive/tags/Twitter/default.aspx</link><description>Tags: Twitter</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Rogueware campaign on Twitter continues...</title><link>http://pandalabs.pandasecurity.com/archive/Rogueware-campaign-on-Twitter-continues_2E002E002E00_.aspx</link><pubDate>Thu, 04 Jun 2009 08:13:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1003</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1003.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1003</wfw:commentRss><description>
&lt;p align="left"&gt;The Twitter Trends based  attack &lt;a href="http://pandalabs.pandasecurity.com/archive/Rogueware-Campaigns-now-blending-into-Twitter-Trends.aspx" target="_blank"&gt;we blogged about yesterday&lt;/a&gt; has expanded from just one trend to nearly  all of them! &amp;nbsp;&amp;nbsp;Over the past 24 hours,  there have been several thousand tweets targeting trending topics on Twitter and  the numbers continue to rise.&amp;nbsp;&lt;br /&gt;
 
  &lt;br /&gt;
    &lt;a href="http://www.flickr.com/photos/lithium-/3594094709/sizes/o/"&gt;&lt;img alt="@lithium" border="0" src="http://farm4.static.flickr.com/3553/3594094709_88d050b2dd.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
    &lt;br /&gt;
    &lt;strong&gt;Example Tweets:&lt;/strong&gt;&lt;br /&gt;
    &lt;br /&gt;
    &lt;a href="http://www.flickr.com/photos/lithium-/3594902566/sizes/o/"&gt;&lt;img alt="Malicious Tweets" border="0" src="http://farm4.static.flickr.com/3400/3594902566_ae651d6646.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
    &lt;br /&gt;
  As you can see from the example tweets, the cyber criminals  are targeting twitter trends in real-time.&amp;nbsp;  &amp;nbsp;&amp;nbsp;I went ahead and captured every tweet up until  about 8PM tonight and put together a Tag Cloud so that you can see what terms  were targeted more frequently.&lt;br /&gt;
  &lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3594094809/sizes/o/"&gt;&lt;img alt="Tag Cloud" border="0" height="400" src="http://farm4.static.flickr.com/3377/3594094809_c266bbb150.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
  &lt;br /&gt;
  Clicking on any of the links will put you through a series of redirects,  at which point you will arrive at a website prompting you to install a fake  Adobe Flash plugin (flash_player_plugin.exe).&amp;nbsp; If the so-called &amp;ldquo;plugin&amp;rdquo;  is installed, then the computer will be infected with &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=det&amp;amp;idvirus=207660"&gt;Adware/PrivacyCenter&lt;/a&gt;.&lt;br /&gt;
  &lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3594094885/sizes/o/"&gt;&lt;img alt="Malicious Site" border="0" height="375" src="http://farm4.static.flickr.com/3609/3594094885_642aeb28a2.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The emergence of this type of threat distribution method demonstrates  how cyber criminals are adjusting and evolving to the newer services offered on  the Internet.&amp;nbsp; It&amp;rsquo;s especially dangerous  with sites like Twitter, which offer up to the second updates (or live tweets)  of events as they unfold in real time.&amp;nbsp;  In the future, sites which promote an unfiltered and open dialog through  a global hive of users will have to think twice about the potential threats exposed  by features or even API services that they offer.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1003" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Twitter/default.aspx">Twitter</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/flash_5F00_player_5F00_plugin.exe/default.aspx">flash_player_plugin.exe</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Trends/default.aspx">Trends</category></item><item><title>Rogueware Campaigns blending in with Twitter Trends</title><link>http://pandalabs.pandasecurity.com/archive/Rogueware-Campaigns-now-blending-into-Twitter-Trends.aspx</link><pubDate>Wed, 03 Jun 2009 08:23:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1001</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1001.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1001</wfw:commentRss><description>
&lt;p&gt;&amp;nbsp;&lt;strong&gt;Update: 6/4/09 - &lt;a href="http://bit.ly/lFde3"&gt;Rogueware campaign on Twitter continues...&lt;/a&gt;&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;PhishTube Broadcast&amp;quot; became a trending topic on &lt;a href="http://www.twitter.com"&gt;Twitter&lt;/a&gt; today.  The word &amp;ldquo;tube&amp;rdquo; is a big red flag to any Threat Researcher these days, so naturally I had to investigate it. &lt;/p&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3590917121/sizes/o/"&gt;
&lt;img border="0" height="670" src="http://farm4.static.flickr.com/3401/3590917121_ce957f0097_o.jpg" width="643" /&gt;&lt;/a&gt;
&lt;p&gt;
I clicked on the section inside of the trending topics group and ironically the links in the tweets looked fishy.&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3591/3590917143_6dd61607d5_o.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
I started to investigate further and found that while there was definitely legitimate tweet traffic for the band Phish, several zombie accounts were posting hundreds of strange and highly suspicious messages. Eventually the links led me through several redirections and finally to PornTube malware websites.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3591725374/sizes/o/"&gt;&lt;img border="0" src="http://farm3.static.flickr.com/2100/3591725374_844bf2c398.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connections/Redirects leaving Twitter:&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt; &lt;img src="http://farm3.static.flickr.com/2039/3591725400_124dd0c381_o.jpg" /&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Clicking on any element inside of the PornTube page resulted in a run of the mill &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=det&amp;amp;idvirus=207660"&gt;Adware/PrivacyCenter&lt;/a&gt; infection, but the interesting part of it all is that cyber criminals are starting
to target social networking sites more than ever. In this case they
took advantage of the open dialog on Twitter and essentially blended in
with the trending topics in order to effectively trick unsuspecting
users into clicking malicious links. This technique is strikingly
similar to the Blackhat SEO tricks criminals use on search engines to
place their malicious links at the top of search results. &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;
&lt;img src="http://farm4.static.flickr.com/3638/3591938300_a44886881f.jpg" /&gt;
&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1001" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Twitter/default.aspx">Twitter</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Crypto Challenge</title><link>http://pandalabs.pandasecurity.com/archive/Crypto-Challenge.aspx</link><pubDate>Tue, 02 Jun 2009 00:41:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1000</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1000.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1000</wfw:commentRss><description>&lt;p&gt;Those of you who already &lt;a href="http://www.twitter.com/lithium"&gt;follow me&lt;/a&gt; on &lt;a href="http://www.twitter.com"&gt;Twitter&lt;/a&gt; know that every once in a while I throw together a quick, geeky puzzle for everyone to solve. After my last challenge, a few people asked me to make the next puzzle a little bit harder to solve. This meant including a few more steps and throwing in some visual elements in, as well. &lt;/p&gt;

&lt;p&gt;The Top 10 people to direct message the solution to me on &lt;a href="http://www.twitter.com/lithium"&gt;Twitter&lt;/a&gt; win a prize.&amp;nbsp; Contest ends on 6/15/2009&lt;br /&gt;&lt;/p&gt;  

I hope you all have as much fun cracking it as I did putting it together! :)&lt;br /&gt;
&lt;p&gt;  
NjggNzQgNzQgNzAgNzMgNjMgNnMgNnAgNnMgNnIgNzMgNnAgNjEgNzMgNjggNzMgNnAgNjEgNzMg
NjggNjQgNnAgNjQgNnMgNzQgNjcgNjUgNzQgNjQgNzIgNnMgNzAgNjIgNnMgNzggNjQgNnMgNzQg
NjMgNnMgNnEgNzMgNnAgNjEgNzMgNjggNzUgNzMgNnAgNjEgNzMgNjggMzIgMzIgMzAgMzggMzAg
NzMgNnAgNjEgNzMgNjggNjggNjkgNnIgNzQgNjQgNnMgNzQgNjggNzQgNnEgNnA=
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1000" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Cryptography/default.aspx">Cryptography</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Contest/default.aspx">Contest</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Twitter/default.aspx">Twitter</category></item></channel></rss>