Showing posts with label koobface. Show all posts
Showing posts with label koobface. Show all posts

Monday, November 30, 2009

Koobface Campaign Using Christmas Theme

December is knocking on the door and Christmas is becoming closer and closer. Websense warns about Koobface malware campaign that is using Christmas theme to spread bad stuff.

The Koobface Web site offers a video posted by 'SantA'. The usual ruse of requiring a codec to watch the video is used, to encourage the user to install and run a file called setup.exe (SHA1:a2046fc88ab82abec89e150b915ab4b332af924a). This file is currently detected by 16 out of 41 antivirus products according to VirusTotal.

Corresponding threat alert with sample screenshots can be read here.

Monday, November 9, 2009

Google Reader Abused By Koobface

Jonell Baltazar, Advanced Threats Researcher in TrendMicro, writes in company's blog that bad guys behind Koobface are using Google's Google Reader service to spread malicious links in social networking sites such as Facebook, MySpace, and Twitter.

"The Koobface gang used controlled Google Reader accounts to host URLs containing an image that resembles a flash movie. These URL are spammed through the said social networks. When the user clicks the image or the title of the shared content, it leads to the all too familiar fake YouTube page that hosts the Koobface downloader component", Baltazar writes.

Whole blog post can be read here.

Saturday, October 10, 2009

Eight Things About Koobface

Koobface malware has been one of the hottest names lately. Ryan Flores, Advanced Threats Researcher, has posted a list containing eight things about this social networking sites bothering pest in Trend Micro blog.

Ryan, Jonell Baltazar, Joey Costoya have also published an interesting research report of KOOBFACE named as The Heart of KOOBFACE: C&C and Social Network Propagation.

Monday, August 17, 2009

New Koobface Variant On Loose

Security company Panda Security warns in their blog of new wave of Koobface worm that is spreading in social networking site Facebook. Spam messages come with text "CooooL Video" and a web link. When the link is clicked, victim is redirected to a Koobface controlled server that routes to a fake codec site. On fake codec site victim is shown "Flash Player upgrade required" -message that tries to make user open a malicious executable file.

Source

Tuesday, August 11, 2009

Twitter Suspending Malware Affected Accounts

Twitter has released a status message in which they state that they are suspending a number of accounts that have been affected by malware. Users of compromised accounts will be sent instructions how to restore access.

Reason behind this suspending appears to be Koobface variant and hacked accounts in general, states Mashable, which received following response to their inquiry about the compromised Twitter accounts:
“Unfortunately, it appears to be a number of groups working together; some phished accounts, a sprinkling of hacked accounts — but a large percentage of accounts affected appear to have a Koobface/Win32 variant. We’re attempting to identify the precise variants affecting these folks but have been pushing out notifications to those affected as is.”