Dec28
8:56 pm (UTC-7)   |   by Loucif Kharouni (Threats Analyst)

The holidays will be a time for refreshing connections, both in the real world, and online. Sadly, a ZLOB variant is being used by cyber criminals in this recent predictable spin on the malware social networking scene. Users of Friendster, a social networking site hugely popular in Asia, may have recently received an email via the site’s internal messaging utility that entices them to view a video.

Figure 1. Users receiving email via Friendster may feel safe since the email arrives within the Friendster zone. However, the email links to an external site.

In this particular case, the link is a front for a quick redirection which leads the user to a fake video site. However, the user cannot view the video because he lacks an updated version of the player (in this case, what pretends to be Adobe Flash Player). The name of the site is “YuoTube”–the cybercriminals’ attempt to appear like the legitimate and popular video site, YouTube.

Figure 2. The “YuoTube” site features the purported video, but users cannot view it without installing a certain update for the video player.


Figure 3. Ubiquitously named “setup.exe” is then downloaded onto the system. It is a ZLOB variant.

Since early November we have been observing the increasing occurrence of social networking malware, whose main modus operandi is to trick users into clicking a link which will then download other malicious files. The link scores much on credibility, because it often arrives via messages sent through social networking sites’ internal messaging functionality.

The sender will often appear to be one of the user’s contacts; this increases likelihood that users will click on the link. Malware from WORM_KOOBFACE family (one of the earliest being WORM_KOOBFACE.E, and the latest being WORM_KOOBFACE.AC) specializes in propagating via social networking sites. They propagated mostly in Facebook but have been seen to expand operations to other networking sites like Hi5 and Bebo. These worms have the capacity to hurdle CAPTCHAs.

As always, users are advised to be wary of unsolicited messages. Also, only download software and software updates from the software vendor’s sites or via auto-update features (this can be specified in most programs’ settings).

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




2 Responses to “Malevolent Social Networking: Now on Friendster”

  1. NoVirusThanks Blog » Blog Archive » Malevolent Social Networking: Now on Friendster Says:

    [...] blog.trendmicro.com The holidays will be a time for refreshing connections, both in the real world, and online. Sadly, [...]

  2. 網路資訊雜誌 » 病毒最愛在Facebook做的12件事 Says:

    [...] 1. 自 Cookie 檔案中搜尋與 facebook 相關字串 WORM_KOOBFACE.E 與 WORM_KOOBFACE.D 會在中毒電腦上的 cookie 檔案中搜尋與 Facebook  相關的特定字串。 一旦找到,這些蠕蟲就會利用 cookie 中的登入資訊存取使用者的個人資料檔案,並且在中毒使用者的個人資料檔案中加入一些指向自己的連結,引誘使用者點選。這一系列的惡意程式雖然是在 Facebook 上首見 (也是名稱由來),但其變種與手法也曾經出現在其他社交網站,如 Friendster。 [...]

Leave a Reply

You must be logged in to post a comment.



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice