MalwareCleaning

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label facebook. Show all posts
Showing posts with label facebook. Show all posts

Monday, June 24, 2013

Gina Lisa Facebook scam

Posted on 2:17 PM by Unknown


Yet another Facebook scam, this time luring users with a sextape from Gina Lisa, whom is apparently a German model:


Yet another Facebook scam: "Gina Lisa Sextape"
















Note I only covered up the profile name & profile picture of the user who posted this, the screenshot from the "video" itself is actually not edited. Not sure what it should be covering up there...

When you click on the link you get:
Verify your age first












When you click on the video to "verify your age" you are redirected to what appears to be a site for gambling, pokergames, etc....:

Subscribe and get a free bonus. Looks legit














I suspect you'll probably have to pay up sooner or later to continue playing. Stargames.com is apparently known for spamming blogs & other sites.

hXXp://hot-movie.pw - URLvoid Report
hXXp://stargames.com - URLvoid Report


Interestingly enough, when I decided to also try and visit the page without a proxy, I got the following warning:

Illegal games much?












This scam and/or spam will also post on Facebook on your behalf. Go over your Privacy Settings on Facebook and make sure you delete this "app" if you see it. Remove any posts you have made as well and report posts similar as this made by your friend(s).



Prevention

Pretty straightforward: do not click on any of these links, how tempting they might be ! Ask your friend if he or she knows what it means, and slightly hover over the post until the 'X' becomes visible. You can then mark the post as spam, and it will be removed from your friend's wall.

It might also help to install the WOT extension into your browser. (Compatible with most modern browsers)
WOT is a community-based tool and is therefore very useful for these kinds of scams, whereas other users can warn you about the validity.
More information and to download WOT: http://www.mywot.com/



Conclusion
To keep it short and simple:
don't fall for these types of spam/scam, most of the times it's pretty obvious it's fake.
Read More
Posted in blog update, facebook, facebook scam, Facebook spam, gina lisa, illegal games, poker games, scam, spam | No comments

Wednesday, February 20, 2013

Facebook in a different color? Nah, just a survey scam

Posted on 7:59 AM by Unknown

I got messaged about an obvious scam on Facebook:


New Facebook colors!













Strangely enough, that person's Facebook color was still in blue. Is it possible this is just a scam? ;-)


Going to the application:

The application "Pick a col0r" requests your permissions


 Next screen....:
I choose the blue color. Oh, right...




















You've won!



As with most applications like these, you first have to fill in a survey to get your Facebook in a different color. Obviously, you still won't be able to even if you have filled in all your information for a chance to win product X or Y.


The application will make the same post on your wall as in the first picture. To remove it:

Go to your privacy settings, applications and remove "Pick a C0lor".



Confirm the removal and check the box. 




 Conclusion

You cannot change the color of Facebook at this point, there is no dislike button, ....

All of these 'applications' point to survey scams where you fill in all your information and your inbox will be flooded with spammail. And no, you haven't won anything.




Read More
Posted in blog update, change facebook color, facebook, facebook dislike button, facebook scam, Facebook spam, scam, survey scam | No comments

Wednesday, January 30, 2013

Facebook spam leads to Exploit Kit

Posted on 3:08 AM by Unknown

To no wonders, the Blackhole Exploit Kit is still trying to infect users. One of the techniques commonly used is to send the victim an email from for example Facebook, Linkedin, Twitter, .... Asking to click on a link.

We'll take a small peek at those tactics. We received the following email:

You have received a new comment
















Hi ,
You have disabled your Facebook account. You can restore your account at any moment by logging into Facebook using your old login email address and password. Subsequently you will be able to use the site in usual way.
Thanks,
The Facebook Team


Obviously, Facebook didn't disable your account at all. There are some factors to easily determine this email is fake:

  • The 'From' field says it's from "Facebook", however, the sender is clearly 'nondrinker@iztzg.hr'.
  • Have you disabled your account? If not, then there's no reason to receive this mail.
  • The subject and the content of the email do not match.
  • Hovering over the links in the email reveals the real URL, which are not Facebook URLs.


When clicking on any of the links, you are presented (after several redirects) with the Blackhole Exploit Kit (aka BH EK). It tries to load a Java exploit on the machine by firstly detecting which plugin and Java version you are using:

PluginDetect
 








The payload? Probably ransomware or a Banker Trojan.


You can find the full JavaScript and the infection source on Pastebin :
http://pastebin.com/9PgDTXsb



Prevention

Use the NoScript add-on in Firefox or NotScripts in Chrome to prevent this.
Use the WOT add-on to check on the status of a website.
Use your common sense and ask yourself the proper questions (see below).
Use a URL scanner if you're unsure about a URL. Some examples are VirusTotal, URLvoid and URLquery.




Conclusion

As usual with this kind of emails, be alerted and always ask yourself the proper questions:

Why did this get in my Unwanted Email or Spam folder if I normally get Facebook mails in my normal Inbox?
Why would Facebook send me this when my account isn't disabled at all?
Why are those links not pointing to Facebook websites?
Why is the sender not from Facebook itself? What can I see in the headers?

Use your common sense, update your 3d-party applications as well as Windows, and use a decent antimalware and antivirus product.

Read More
Posted in blackhole exploit kit, blog update, exploit, facebook, Facebook spam, java exploit, malware | No comments

Tuesday, December 6, 2011

New Facebook scam

Posted on 6:26 AM by Unknown
A new Facebook scam is spreading today, 6th of December. The interesting thing is that I have seen it posted in Dutch as well.

The method used is the same as in previous Facebook scams, see for example my earlier post:
New Facebook scam

Here is the post in question (in Dutch):


Classical scam post to lure users into clicking the link.

Here's what it reads:
WOW! Mijn profiel is ALLEEN VANDAAG AL 12 keer bekeken.. en ik kan zien dat er behoorlijk wat stalkers bijzitten LOL! Kijk zelf wie jou allemaal in de gaten houdt op #removed#

In English:

WOW! My profile has been seen 12 time ALREADY ONLY TODAY .. and I can see that quite a few stalkers are included LOL! See for yourself who's keeping an eye on yoy on #removed#



The link has been shortened by the bit.ly URL shortening service. While this service is not malicious on itself, it can also be used by persons with malicious intent, whether it would be hackers, malware authors, ... Or in this case scammers.

Let's review some stats for the bit.ly link first:


98 clicks on this link in the last hour



Top countries, including: France, Germany, The Netherlands



Facebook.com is the most referring site


At the moment of writing, there have been over 1,000 clicks on the link so far. I have already reported it to bit.ly and it should be taken down soon.

UPDATE: bit.ly has already issued a warning for when you click on the link. (12/07/2011)


Now let us analyse where the bit.ly link is taking us. The link can redirect you to different websites, but they will all (so far) redirect you to a page similar to this one (depending on your location):


Who is viewing your Facebook profile ?


You probably don't remember my post from February this year, but the concept is the same: you can supposedly view who's been "stalking", or viewing, your profile. This to attract users on clicking the link. Who doesn't want to see this, right ? Here is my post from early this year:
Facebook rogue applications still lurking around

You can presented with a screen like this (I have several, but I will only post one as example):

Are you the "lucky" winner ?

As stated previously, the concept is the same. Before you can see who's been viewing your profile, you need to fill in a short service to continue.

You may have won a prize, you may have won an iPad, you may have won free ringtones, you may have won a free iPhone application, etc, etc, etc, .... This is of course all a lie.
Remember: if it looks too good to be true, it probably is !

You have to fill in your email address and/or phone number to continue as well. At the end you will end up losing a lot of money, leaving your email address in the open and maybe worse.

Remember: if you click the link while logged in to Facebook, it will also post it on your own wall.



Conclusion

Conclusion is pretty straightforward: do not click on any of the links ! If in doubt, send your friend on Facebook (or if someone sent you the link) via PM if he or she knows what this is about.

To remove this from your or your friend's wall, click on the X on the message, and choose to "Report/Mark as spam" or "Remove Post".

You can also use a linkscanner to verify the integrity of a link on either http://www.urlvoid.com or https://www.virustotal.com/

To get some information on a bit.ly (or other URL shortener serivce) link, you can use any of the following websites:
- http://www.getlinkinfo.com/
- http://longurl.org/
- http://www.longurlplease.com/ (includes Firefox extension)

To report a malicious bit.ly link use:
http://bitly.com/a/report_spam

For any other question, do not hesitate to post a comment !
Read More
Posted in blog update, facebook, phishing, scam, spam, spim | No comments

Sunday, June 19, 2011

New Facebook scam

Posted on 1:11 PM by Unknown
There's a new Facebook scam actively spreading.

Titles as "Monstrously Erotic blonde", "This chick is awesomely crazy" and "Shows her boobs on national TV!" may appeal to the imagination.

Here's some examples:
Example #1

Example #2


Example #3

However, if you click on the link, it will not take you to a Blogger page but instead will redirect you right away to a page where you can see the "video":


You need to click "Jaa" twice to confirm you're over 18



It looks like a legit Facebook page and a Youtube video, but in fact it is all fake. If you click on "Jaa" (which appears to be Finnish for "Share"), you'll see the following page:


Ultimately you need to fill in a survey to see the video


Haven't we seen this type of scam before on Facebook ?
It is similar to the "See who stalks you on Facebook" application that was pretty viral some months ago.
I also made a blog post back then:
http://bartblaze.blogspot.com/2011/02/facebook-rogue-applications-still.html

You need to fill in a survey to see the video. Of course you might be attracted by the chance of winning an iPhone, but it is all fake.

The purpose of these scams are for you to send expensive text messages to 'unlock' the video. Don't be fooled, you'll only lose money by sending text messages !
Additionally, it will also make the same post on your wall (subject & link may vary), so your friends are targeted as well.




Prevention

Pretty straightforward: do not click on any of these links, how tempting they might be ! Ask your friend if he or she knows what it means, and slightly hover over the post until the 'X' becomes visible. You can then mark the post as spam, and it will be removed from your friend's wall.

It might also help to install the WOT extension into your browser. (Compatible with most modern browsers)
WOT is a community-based tool and is therefore very useful for these kinds of scams, whereas other users can warn you about the validity.
More information and to download WOT: http://www.mywot.com/




Conclusion

Although it's been a while since I encountered these types of scams, keep in mind that they may pop-up on your wall one day.

If so, follow the prevention tips mentioned above and all should be fine.


Read More
Posted in blog update, facebook, scam, spam | No comments

Wednesday, April 13, 2011

Facebook Support. Personal data has been changed!

Posted on 2:06 PM by Unknown

There appears to be a new malicious email being sent out with the subject: "Facebook Support. Personal data has been changed! ID75300"

In a previous post I already explained a similar campaign:
Your FaceBook password has been changed


First of all, you would receive an email similar to this one:

Email claiming your personal data has been changed.


The email content is the following:

Dear user of FaceBook.

Your password is not safe! To secure your account the password has been changed automatically.

Attached document contains a new password to your account and detailed information about new security measures.

Thank you for your attention,
Administration of Facebook.


Your password from Facebook appears to be unsafe and you need to verify attached document to view your new login information. There is a file attached called "New_Password_NU44133.zip"

Inside the ZIP file you will find a file called New_Password.exe:


The file New_Password.exe is in fact not a Microsoft Word document, as you may suspect from the icon, but is in fact a malicious executable:

New_Password.exe
Result: 19/42 (45.2%)
MD5: 99a7cc6e674b94fbecef52f520c03dc3
VirusTotal
ThreatExpert Report
Anubis Report

The file also drops the following executable on the system:

aspimgr.exe
Result: 39/42 (92.9%)
MD5: 4531d9d75dab83c957122538b6fc92ba
VirusTotal
ThreatExpert Report


The executable also tries to connect (called "phoning home") to download additional malware. However, at time of writing the URLs were offline.


Conclusion

If you receive emails like this, you should already be alerted:
"Why would Facebook send me an email my password has been changed ?"

The answer is simple: they don't. Whether you have Facebook or not, instantly delete the email and don't look back.


Read More
Posted in blog update, facebook, malware, spam | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • League of Legends RP hack
    I recently blogged about a (still current) scam targeting players of the online game League of Legends: Free Riot codes scam . When re-check...
  • test for the blog
    Just testing ... :-)
  • Facebook Support. Personal data has been changed!
    There appears to be a new malicious email being sent out with the subject: " Facebook Support. Personal data has been changed! ID7530...
  • WinMHR: Free Malware Detector
    Today I checked out WinMHR brought to you by: Team Cymru Now, what exactly is WinMHR ? (This is copied from the website) WinMHR is... Free ...
  • Malware Puzzle
    A malware (crossword) puzzle you say? Yes! Why not? I've made a puzzle about malware (and security) related keywords. It comes in .PNG f...
  • Brazilian banking Trojan tricks
    So I encountered what I suspect to be a banker focused on Brazilian banks. (Win32/Bancos) Part 1 - spam mail : Fiscal note Mail from: mail.u...
  • Increase in Dutch banking phishing
    Recently I made a post on Malware Disasters about an increase of targeted phishing in the last few monts. The focus was mainly on Dutch (an...
  • Gina Lisa Facebook scam
    Yet another Facebook scam, this time luring users with a sextape from Gina Lisa, whom is apparently a German model: Yet another Facebook sca...
  • A word on XDocCrypt/Dorifel/Quervar
    I'm sure everyone has heard by now about the so called XDocCrypt/Dorifel/Quervar malware. It has mostly damaged machines in The Netherla...
  • FedEx spam loads malware
    Received an email from (supposedly) FedEx today, seems my parcel was unable to be delivered: Print your receipt!     Mail details: Subject: ...

Categories

  • ACH transfer
  • adobe
  • adobe exploit
  • ADP
  • adware
  • affiliate
  • all your data are belong to us
  • antimalware
  • asprox
  • bancos
  • banking trojan
  • basic malware cleaning
  • battle.net
  • blackhole exploit kit
  • blog update
  • botnet
  • brazilian banking trojan
  • brucon
  • change facebook color
  • conduit
  • cracked hotmail
  • credit card blocked
  • crimeware kit
  • CVE-2006-0003
  • CVE-2010-0840
  • CVE-2012-4681
  • cybercrime
  • d3
  • diablo
  • diablo III
  • diablo phishing
  • DLL injection
  • Dorifel
  • dorkbot
  • encryption
  • end of july
  • exploit
  • exploit kit
  • exprez
  • facebook
  • facebook dislike button
  • facebook event
  • facebook scam
  • Facebook spam
  • facepalm
  • Fake Symantec security check
  • fakeAV
  • fareit
  • FedEx
  • FedEx spam
  • first post
  • flv media player
  • foistware
  • free riot code scam
  • free riot codes
  • free riot points
  • free riot points scam
  • free RP generator
  • fun
  • gina lisa
  • google earth
  • google image poisoning
  • google images
  • hacked hotmail
  • Hacked Hotmail accounts
  • hakin9
  • Hewlett-Packard ScanJet
  • hotfile
  • hotmail
  • illegal games
  • infostealer
  • ING
  • IP and RP Hack Download
  • java
  • java exploit
  • kuluoz
  • lame old malware
  • League of Legends
  • League of Legends MultiHack Generator
  • League of Legends RP generator
  • League of Legends RP hack
  • linkedIN
  • LoL
  • LoL RP Hack
  • low detection
  • malvertising
  • malware
  • malware analysis
  • malware analysis lab
  • malware cleaning
  • malware lab
  • malware puzzle
  • malware tools
  • medfos
  • messenger
  • MSN
  • neosploit exploit kit
  • paypal
  • paypal spammail
  • PC Speed Maximizer
  • pcspeedplus
  • PDF
  • phishing
  • poker games
  • potentially unwanted program
  • pricegong
  • PUP
  • pushdo
  • Quervar
  • Question and Answer
  • rabobank
  • ransomware
  • rapidshare
  • redkit exploit kit
  • RemovalTool.exe
  • Riot codes scam
  • Riot points scam
  • roguevertising
  • rogueware
  • rootkit
  • sasfis
  • scam
  • scareware
  • security
  • security conference
  • security.nl
  • skype
  • skype worm
  • social engineering
  • spam
  • spear phishing
  • spim
  • survey scam
  • team cymru
  • technoviking
  • tepfer
  • test
  • trojan
  • twitter
  • United Parcel Service
  • UPS
  • UPS spam
  • verizon spam
  • video
  • vmware
  • wellsfargo
  • whitesmoke
  • Windows Antibreaking System
  • windows live
  • WinMHR
  • worm
  • XDocCrypt
  • yontoo
  • youtube
  • youtube comment spam
  • youtube spam
  • youtube top comments
  • zeus

Blog Archive

  • ▼  2013 (18)
    • ▼  September (2)
      • Malware: the blame game
      • PayPal spam leads to malware cocktail
    • ►  August (2)
    • ►  July (1)
    • ►  June (3)
    • ►  May (2)
    • ►  April (1)
    • ►  March (1)
    • ►  February (3)
    • ►  January (3)
  • ►  2012 (14)
    • ►  November (1)
    • ►  October (2)
    • ►  September (2)
    • ►  August (3)
    • ►  July (1)
    • ►  June (2)
    • ►  April (3)
  • ►  2011 (15)
    • ►  December (1)
    • ►  September (1)
    • ►  June (1)
    • ►  April (3)
    • ►  March (1)
    • ►  February (5)
    • ►  January (3)
  • ►  2010 (14)
    • ►  December (3)
    • ►  November (1)
    • ►  October (6)
    • ►  September (2)
    • ►  August (1)
    • ►  March (1)
Powered by Blogger.

About Me

Unknown
View my complete profile