Results 1 to 10 of 10

Thread: Facebook Virus

  1. #1
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801

    Angry Facebook Virus

    I recently spotted this on Facebook. Somebody pmed me saying "I got u surprise
    Code:
    hxxp:/REMOVED
    via Facebook mobile. I decided to check it out. It redirected my to a webpage (
    Code:
    REMOVED/
    ) which was blank except in the centre where it was written "Download photoalbum". I clicked on it and found that it was a download link to a file called photo.exe which is around 712.5 KB in size. Apparently undetectable by my NIS 2011 real-time, it got 14 detections when I uploaded it to VirusTotal on suspicion. When I tried running the file, SONAR picked it up and deleted it.

    VirusTotal reports HERE.

    P.S. The above links are for informational purposes only. @Mods: If there's any problem with me posting the links here, please feel free to remove them.
    Last edited by leofelix; 01-07-2011 at 05:34 AM. Reason: link removed for security reason

  2. #2
    Neo
    Neo is offline
    Experienced User
    Overall activity: 3.0%

    Join Date
    Jun 2010
    Posts
    1,494
    Liked
    90 times
    Points
    8,697
    thasts a very common way to spread trojan through FB
    Love me , Hate me but you just can't Ignore me

  3. #3
    Newbie
    Overall activity: 0%

    Join Date
    Dec 2009
    Location
    Babel Island
    Posts
    75
    Liked
    0 times
    Points
    2,073
    14 of 43 (32.6%) told that it was a malware and Norton couldn't detect in real time. Wow!
    "Insanity is doing the same thing over and over again and expecting different results." - Albert Einstein

  4. #4
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Read about this virus a while back, one of the new cross platform ones. Still requires root/sudo under Linux.

    Please next time, hxxp and quote it if you're linking. Thanks.
    pacman -Syyu life not found in sync db

  5. #5
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801
    @hellnoire: Can you tell me where you read about the virus? I wanna read it too. And do I have to do hxxp for malicious links only or for all links?

  6. #6
    Rookie
    Overall activity: 7.0%

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,138
    Liked
    24 times
    Points
    44,879
    The site now redirects to a new site when the user click download a file name surprise.exe

    Virustotal link : http://www.virustotal.com/file-scan/...a21-1293510261

    ESET, Kaspersky and Norton didn't detect. Submitted to avast virus lab.
    Thoughts are like a never ending ocean where it is deep, endless and dangerous

  7. #7
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645
    Just ignore it and hit the delete message button - problem solved. Most of the time this type of social engineering attack is usually needs user-assistance, ( user-assisted attacks ). No need to argue whether you AV detected it or not. It's not a Facebook virus, it does uses Facebook as a medium to disseminate those trojan agents, using its internal features and capitalizing on human's trust. Be vigilant! tc...
    "Stars and the Sun"


  8. #8
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    Let's report it on WOT guys!!

    Screw Google! Ask me!


  9. #9
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801
    @ceyfer: Yes, one should hit the delete button. But I decided to download it. It helps when I'm testing anti-malware stuff..

  10. #10
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Links bringing to malware removed for security reasons.

    Next time, go and report malware directly to antivirus vendors, please.

    The security of our members is VERY IMPORTANT

    no further links to malware will be tolerated

    Thank you for understanding.

    Thread closed
    Last edited by leofelix; 01-07-2011 at 05:40 AM.
    Roger and out

 

 

Similar Threads

  1. Replies: 10
    Last Post: 01-04-2012, 04:59 PM
  2. 'May God always bless..' Facebook virus hoax spreads !!!!
    By INDRANIL in forum Spyware/Viruses
    Replies: 5
    Last Post: 08-28-2011, 09:34 PM
  3. Have virus from Facebook ???
    By kimlanvn in forum Spyware/Viruses
    Replies: 6
    Last Post: 04-23-2011, 12:09 AM
  4. Fake facebook email with virus
    By richie1913 in forum Spyware/Viruses
    Replies: 9
    Last Post: 03-27-2010, 10:15 PM
  5. Replies: 16
    Last Post: 12-12-2008, 06:55 PM

Tags for this Thread

All times are GMT +8. The time now is 09:06 AM.