[FSec] Facebook Finally Blocks Malware Attack

Newsfeed

Nachrichtenbote
With more than 24 hours having passed since it began, Facebook has finally blocked a malware attack that linked to Windows and Mac malware.

The attack site pushed MacGuard scareware at Mac users, and host modifying fake "Adobe Flash Players" at Windows users.

Contrary to our earlier post, rather than using the "Like" feature, we now think the malware was spreading by posting directly to Facebook accounts. The posted link used the Like feature's icon rather than icons used by Links or Videos.

Here's what Facebook search revealed a couple of hours ago:

Rihanna_and_Hayden_Panettiere.png


And this is an example from a user's Wall:

newtubes_in.png


The "LOL, just found new tube site" link didn't reference any .php as the others.

Here you can see the same site, newtubes.in, was used on Sunday:

BoobsTooBig.png


The subject was "Boobs Too Big For Seatbelt".

The bad guys attempted, and failed, to launch their attack during the Memorial Day holiday weekend, with big boobs.

As mentioned earlier today, the attack site was Geo-IP and OS aware, and focused only on USA/UK IP addresses. All others were safely redirect to youtube.com. It also employed anti-analysis evasion techniques, such as blocking IP address that visited too frequently. This was a highly professional attack using well developed techniques.

We hope that it cannot be repeated soon.






On 01/06/11 At 10:06 PM

Weiterlesen...
 
Zurück
Oben