PDA

View Full Version : New Facebook Virus


CellThree
October 30th, 2009, 03:56 PM
I received the email stated below yesterday, ESET SS didn't pick anything up. I'm running ESET SS 4.0.314 with the latest updates on Win7 RC using Thunderbird as my email client.
I didn't open the attachment as it was obviously a fake.

Just wondering if this is covered in the new definitions file or overlooked?

-{ Quote: "
735,000 Facebook users hit with massive bot b...

A massive bot-based attack has been hitting Facebook users, with nearly three-quarters of a million users receiving fake password reset messages, according to security researchers.

The attack, which began Monday afternoon, according to e-mail security vendor Cloudmark, targets Facebook users with a spoofed message that claims recipients' Facebook passwords have been reset as a security measure.

The messages, which come bearing subject lines such as "Facebook Password Reset Confirmation," include a file attachment that supposedly contains the new password.

In fact, the attached .zip file includes a Trojan downloader, dubbed "Bredlab" by some antivirus companies, "Bredolab" by others. The downloader grabs a variety of malware from hacker servers, including fake security software, or "scareware," and installs attack code and rogue antivirus applications on the compromised PCs.

Multiple security companies, including Symantec, Trend Micro, MX Lab and Websense, have put out warnings about the attack campaign.

"This variant of Bredolab connects to a Russian domain and the infected machine is most likely becoming part of a Bredolab botnet," said Shunichi Imano, a security researcher at Symantec, in a post to the firm's security blog.

Jamie Tomasello, Cloudmark's abuse operations manager, said today that her company alone has detected nearly three-quarters of a million phony Facebook messages since Monday, and nearly 250,000 in the last 24 hours. "Our count continues to go up, and is at about 735,000 now," said Tomasello. "It's a pretty high volume."

According to Tomasello, both desktop clients and ISPs that use Cloudmark to filter potentially malicious mail have reported receiving the fake Facebook e-mail." }-

Source : http://www.itbusiness.ca/it/client/en/home/news.asp?id=55081

Marcos
October 30th, 2009, 04:11 PM
Have you submitted it to Virus Total to see how many AVs actually detect it? Bredolab variants are detected by ESET so if you come across an undetected sample, submit it to samples[at]eset.com for analysis.

Scotto
October 30th, 2009, 10:03 PM
I got that facebook password reset email last night.
I thought it looked sus but let it through Mailwasher and when it went through to Outlook Express, ESS V3 caught it and deleted it.
According to ESS V3 it was a variant of Win 32/Kryptik.AZE trojan.
Have a great day,
Scotto.

ESS V3 3.0.694.0

cssoz
October 31st, 2009, 02:20 AM
-{ Quote: "I got that facebook password reset email last night.
I thought it looked sus but let it through Mailwasher and when it went through to Outlook Express, ESS V3 caught it and deleted it.
According to ESS V3 it was a variant of Win 32/Kryptik.AZE trojan.
Have a great day,
Scotto.

ESS V3 3.0.694.0" }-

glad you're one of the smart people who use the latest of NOD32 v3 or v4

Marcos
October 31st, 2009, 02:41 AM
Basically in this case it doesn't matter what version of the program is used, Bredolabs are detected fine by v2 as well as v3/v4. As for detection ratio, it's equal in v3 and v4, the latter has improved cleaning, however.

CellThree
November 1st, 2009, 02:29 PM
-{ Quote: "Have you submitted it to Virus Total to see how many AVs actually detect it? Bredolab variants are detected by ESET so if you come across an undetected sample, submit it to samples[at]eset.com for analysis." }-

I wish I still had it. I had already deleted the email then saw the article a little while later. I was surprised it didn't pick up. Next time I'll remember to submit it!

Thanks