Results 1 to 5 of 5
Like Tree3Likes
  • 3 Post By Ceyfer √

Thread: Facebook-profile-photo malware | Analysis

  1. #1
    Guest
    Overall activity: 54.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,006
    Liked
    710 times
    Points
    47,645

    Angry Facebook-profile-photo malware | Analysis


    A friend of mine had sent me a facebook photo icon. During my initial analysis, I found out that it was not a simple Facebook icon, the file itself is using a double extension trick and it is indeed an executable file rather than a simple image icon. Well, this trick has been here for some time, but still, it is pretty effective for some trigger-happy users. So make sure to uncheck hide extensions for known file types to detect any malicious file by advance.

    See the potentially dangerous file extensions!
    Code:
        .EXE  (machine language)
        .COM  (machine language)
        .VB   (Visual Basic script)
        .VBS  (Visual Basic script)
        .VBE  (Visual Basic script-encoded)
        .CMD  (batch file - Windows)
        .BAT  (batch file - DOS/Windows)
        .WS   (Windows script)
        .WSF  (Windows script)
        .SCR  (screen saver)
        .SHS  (OLE object package)
        .PIF  (shortcut to DOS file plus code)
        .HTA  (hypertext application)
        .JAR  (Java archive)
        .JS   (JavaScript script)
        .JSE  (JScript script)
        .LNK  (shortcut to an executable)

    The malware is a trojan downloader which is stubbornly the hardest to detect of all the trojan variants. Mainly, because it only acts as file downloader manager which creates a backdoor gate for the real malicious payload. Some AV only treat the trojan agent as a legitimate file, thus escaping the detection pattern and later flag it once it comes in contact with the real payload or only during post execution.


    VirusTotal Analysis
    Here's the analyses: 8/ 41 (19.5%)
    Code:
    BitDefender - 7.2 - 2011.06.20 - Gen:Trojan.Heur.aqW@XcQsPlmi 
    F-Secure - 9.0.16440.0 - 2011.06.20 - Gen:Trojan.Heur.aqW@XcQsPlmi 
    GData - 22 - 2011.06.20 - Gen:Trojan.Heur.aqW@XcQsPlmi 
    Ikarus - T3.1.1.104.0 - 2011.06.20 - Gen.Trojan.Heur 
    Kaspersky - 9.0.0.837 - 2011.06.20 - UDS:DangerousObject.Multi.Generic 
    McAfee - 5.400.0.1158 - 2011.06.20 - Artemis!4EC9AB3272F2 
    McAfee-GW-Edition - 2010.1D - 2011.06.20 - Heuristic.BehavesLike.Win32.Downloader.J 
    Sophos - 4.66.0 - 2011.06.20 - Mal/Generic-L 
    
    MD5: 4ec9ab3272f247067e086b7b2d902d50
    SHA1: 1b62a8ffdec885daa796b74fb3c4f6853fe6462c
    SHA256: 31366d1a65816daf9112460e28a2f6d3d5464528fbb4089afb24dec99963a52b
    File size: 7680 bytes
    Scan date: 2011-06-20 10:16:17 (UTC)
    ThreatExpert
    Code:
    http://www.threatexpert.com/report.aspx?md5=4ec9ab3272f247067e086b7b2d902d50
    Summary of the findings: Downloads/requests other malicious files from Internet.


    The Microsoft Malware Protection Center (MMPC)

    Code:
    https://www.microsoft.com/security/portal/Submission/SubmissionHistory.aspx?SubmissionId=D410FFAC-7CC4-44C9-A94B-AA3BEA82A1E9
    Detection Status: TrojanDownloader:Win32/Willsienod.A
    Last edited by Ceyfer √; 06-20-2011 at 08:31 PM. Reason: bug fixes!
    "Stars and the Sun"


  2. #2
    Experienced User
    Overall activity: 0%

    Join Date
    Oct 2009
    Location
    Sri Lanka
    Posts
    331
    Liked
    41 times
    Points
    36,121
    Thanks for valuable information, specially about Facebook profile photo malware..

  3. #3
    I'd rather be fishing!
    Overall activity: 0%

    Join Date
    Jan 2011
    Location
    Minnesota, USA
    Posts
    3,155
    Liked
    1543 times
    Points
    4,220
    Thanks for the info Ceyfer! It's always good to be aware of this kind thing.
    Life isn't about waiting for the storm to pass, it's about learning to dance in the rain!

  4. #4
    Moderator
    Overall activity: 100.0%

    Join Date
    May 2010
    Location
    Eire /The Garden of Ireland
    Posts
    5,486
    Liked
    1750 times
    Points
    31,018
    Cheers Ceyfer appreciate the information although it does create a couple of headaches along the way... as Bear mentioned it is alway good to be aware
    Stutz Bearcat

  5. #5
    The Specialist *
    Overall activity: 76.0%

    Join Date
    May 2010
    Location
    KOLKATA
    Posts
    5,162
    Liked
    731 times
    Points
    47,580
    Thanks for the heads up ceyfer .
    I don't need to know everything, I just need to know where to find it, when I need it.

 

 

Similar Threads

  1. Replies: 2
    Last Post: 04-15-2011, 12:50 PM
  2. Switch your Facebook photo viewer back to 'classic'
    By Bluedot in forum General Forum
    Replies: 1
    Last Post: 02-20-2011, 02:27 AM
  3. Facebook : top source for malware infections
    By princeaniket in forum Spyware/Viruses
    Replies: 14
    Last Post: 09-21-2010, 10:20 AM
  4. Comodo Instant Malware Analysis Log
    By LCaveman in forum Spyware/Viruses
    Replies: 1
    Last Post: 04-26-2009, 12:23 PM

Tags for this Thread

All times are GMT +8. The time now is 09:48 AM.