<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; facebook</title>
	<atom:link href="http://blog.mxlab.eu/tag/facebook/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Mon, 13 Feb 2012 23:20:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; facebook</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>&#8220;Spam from your Facebook account&#8221; messages contains trojan</title>
		<link>http://blog.mxlab.eu/2011/04/28/spam-from-your-facebook-account-messages-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2011/04/28/spam-from-your-facebook-account-messages-contains-trojan/#comments</comments>
		<pubDate>Thu, 28 Apr 2011 20:24:47 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Facebook trojan]]></category>
		<category><![CDATA[malwrae]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1378</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with tone of the following subjects: Spam from your account Spam from your Facebook account Your password has been changed The email is from &#8220;Facebook Abuse Department&#8221; containing a spoofed email address in the format ***@facebook.com, where the part before the @-sign [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1378&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with tone of the following subjects:</p>
<p>Spam from your account<br />
Spam from your Facebook account<br />
Your password has been changed</p>
<p>The email is from &#8220;Facebook Abuse Department&#8221; containing a spoofed email address in the format ***@facebook.com, where the part before the @-sign contains different names starting with a capital, and has the following body:</p>
<blockquote><p>Dear client</p>
<p>Spam is sent from your FaceBook account.</p>
<p>Your password has been changed for safety.</p>
<p>Information regarding your account and a new password is attached to the letter.<br />
Read this information thoroughly and change the password to complicated one.</p>
<p>Please do not reply to this email, it&#8217;s automatic mail notification!</p>
<p>Thank you for using our services.<br />
FaceBook Service.</p></blockquote>
<p>The attached ZIP file has the name Attached_SecurityCode08592.zip, where the number is choosen randomly, and contains the 33 kB large file Attached_SecurityCode.exe.</p>
<p>The trojan is known as W32/Trojan2.NNGG (Commtouch) and Troj/DwnLdr-IZR (Sophos). This trojan will install itself on the infected computer and has a build in SMTP engine for spreading its payload further by email.</p>
<p>The following files will be created:</p>
<p>%Temp%\_check32.bat<br />
%Windir%\s32.txt<br />
%System%\aspimgr.exe<br />
%System%\document.doc<br />
%Windir%\ws386.ini</p>
<p>Several Windows registry changes will be exectued and the trojan can establish connection with the following IPs:</p>
<table width="400px" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td>Remote Host</td>
<td>Port Number</td>
</tr>
<tr>
<td>148.223.242.243</td>
<td>25</td>
</tr>
<tr>
<td>148.244.121.6</td>
<td>25</td>
</tr>
<tr>
<td>161.132.8.44</td>
<td>25</td>
</tr>
<tr>
<td>174.120.139.92</td>
<td>25</td>
</tr>
<tr>
<td>200.157.233.13</td>
<td>25</td>
</tr>
<tr>
<td>200.57.129.65</td>
<td>25</td>
</tr>
<tr>
<td>200.57.129.66</td>
<td>25</td>
</tr>
<tr>
<td>204.200.167.219</td>
<td>25</td>
</tr>
<tr>
<td>207.193.205.1</td>
<td>25</td>
</tr>
<tr>
<td>216.200.145.36</td>
<td>25</td>
</tr>
<tr>
<td>194.247.183.170</td>
<td>80</td>
</tr>
<tr>
<td>91.207.178.169</td>
<td>80</td>
</tr>
</tbody>
</table>
<p>Data can be obtained from following URLs:</p>
<ul>
<ul>
<li>hxxp://cl63amgstart.ru:80/board.php</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=document</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=2</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=3</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=4</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=5</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=6</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=7</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=8</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=9</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=uploader</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=0</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=0&amp;luck=1</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=1</li>
<li>hxxp://campaigncommunications.ru/connect/load.php?file=1&amp;luck=1</li>
</ul>
</ul>
<p>At the time of writing, only 2 of the 41 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=4f537c89ac7387c046f6a2598bf9606003a715ea9ebbd0d8bc9528083859e526-1304020434" target="_blank">permalink</a> and MD5: 72a45688ba03a9bfd3b3755c33843dcd.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1378/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1378/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1378/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1378&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/28/spam-from-your-facebook-account-messages-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Facebook Support. Your password has been changed!&#8221; contains trojan</title>
		<link>http://blog.mxlab.eu/2011/04/11/facebook-support-your-password-has-been-changed-contains-trojan/</link>
		<comments>http://blog.mxlab.eu/2011/04/11/facebook-support-your-password-has-been-changed-contains-trojan/#comments</comments>
		<pubDate>Mon, 11 Apr 2011 10:37:15 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Facebook trojan]]></category>
		<category><![CDATA[Facebook virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1369</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject &#8220;Facebook Support. Your password has been changed! ID09687&#8243;. Note that the number may change with each email. The email is send from the spoofed addresses: account@facebook.com manager@facebook.com The message has the following body: Dear user of FaceBook. Your password [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1369&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subject &#8220;Facebook Support. Your password has been changed! ID09687&#8243;. Note that the number may change with each email.</p>
<p>The email is send from the spoofed addresses:</p>
<p>account@facebook.com<br />
manager@facebook.com</p>
<p>The message has the following body:</p>
<blockquote><p>Dear user of FaceBook.</p>
<p>Your password is not safe!<br />
To secure your account the password has been changed automatically.</p>
<p>Attached document contains a new password to your account and detailed information about new security measures.</p>
<p>Thank you for your attention,<br />
Your Facebook</p></blockquote>
<p>The attached ZIP file has the name New_Password_IN04393.zip, note that the number at the end will change, and contains the 33 kB large file New_Password.exe.</p>
<p>The trojan is known as Gen:Heur.VIZ.2 (BitDefender), Mal/FakeAV-JX (Sophos), Trojan.Generic.Bredolab-2 (ClamAV).</p>
<p>The following files will be created:</p>
<p>%System%\document.doc</p>
<p>Several Windows registry changes will be exectued and the trojan can establish connection with the IP 193.106.34.20 on port 80.</p>
<p>Data can be obtained from following URLs:</p>
<ul>
<li>hxxp://profmiale.ru/TGQW4nHJOS/document.doc</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=8</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=9</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=uploader</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=grabbers</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/grabbers.php</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=0</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=1</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=2</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=3</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=4</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=5</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=6</li>
<li>hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=7</li>
</ul>
<p>At the time of writing, only 6 of the 42 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=890276dab331171d5c96375fa7fc9bddb328ed85187313fc09777b04757121dc-1302515158" target="_blank">permalink</a> and MD5: ecc2d442886b7296b5bd7eaeaae0bcea.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1369/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1369&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/11/facebook-support-your-password-has-been-changed-contains-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;New Facebook password!&#8221; emails contains W32/Oficla.BC trojan</title>
		<link>http://blog.mxlab.eu/2010/09/23/new-facebook-password-emails-contains-w32-oficla-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/09/23/new-facebook-password-emails-contains-w32-oficla-trojan/#comments</comments>
		<pubDate>Thu, 23 Sep 2010 10:26:26 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Facebook trojan]]></category>
		<category><![CDATA[Facebook virus]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1100</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject &#8220;New Facebook password!&#8221; The email is send from the spoofed address &#8220;&#8221;Facebook Manager, Loraine Nwabeke&#8221; &#60;juliancb@facebook.com&#62;&#8221; and has the following body: Dear user of facebook. Because of the measures taken to provide safety to our clients, your password has [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1100&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, started to intercept a new trojan distribution campaign by email with the subject &#8220;New Facebook password!&#8221;</p>
<p>The email is send from the spoofed address &#8220;&#8221;Facebook Manager, Loraine Nwabeke&#8221; &lt;juliancb@facebook.com&gt;&#8221; and has the following body:</p>
<blockquote><p>Dear user of facebook.<br />
Because of the measures taken to provide safety to our clients, your password has been changed.<br />
You can find your new password in attached document.<br />
Thanks,<br />
Your Facebook.</p></blockquote>
<p>The attachedZIP file has the name FaceBook_Password_Nr47825.zip and contains the 32 kB large file FaceBookDOC.exe.</p>
<p>The trojan is known as W32/Oficla.BC (Authentium), Heuristic.Trojan.SusPacked.TMS (ClamAV), Suspicious file (Panda).</p>
<p>The following files will be created:</p>
<p>%Temp%\1.tmp<br />
%System%\hyli.igo</p>
<p>The following registry key is created:</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid</p>
<p>The following registry key is modified:</p>
<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]<br />
Shell =</p>
<p>At the time of writing, only 4 of the 43 AV engines did detect the trojan at Virus Total.</p>
<p>Virus Total <a href="http://www.virustotal.com/file-scan/report.html?id=4c82c0986f3fead79b29a0856aae66ba646886628dc87dc69657fdbf62d0f659-1285237217" target="_blank">permlink</a> and MD5: 1a12dc605dbcecb119b53d1d896693ab.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1100&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/09/23/new-facebook-password-emails-contains-w32-oficla-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>New Oficla trojan variant targets Facebook users</title>
		<link>http://blog.mxlab.eu/2010/04/27/new-oficl-trojan-variant-targets-facebook-users-2/</link>
		<comments>http://blog.mxlab.eu/2010/04/27/new-oficl-trojan-variant-targets-facebook-users-2/#comments</comments>
		<pubDate>Tue, 27 Apr 2010 15:54:48 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[oficla]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=819</guid>
		<description><![CDATA[MX Lab detected a new variant of the Oficla trojan that targets Facebook users and provides instructions on how to use the new password for their online Facebook account. The emails is send from the spoofed email address The Facebook Team &#60;profile@facebook.com&#62; with subjects like for example: Facebook Password Reset Confirmation! Customer Message. Facebook Password [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=819&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected a new variant of the Oficla trojan that targets Facebook users and provides instructions on how to use the new password for their online Facebook account.</p>
<p>The emails is send from the spoofed email address The Facebook Team &lt;profile@facebook.com&gt; with  subjects like for example:</p>
<p>Facebook Password Reset Confirmation! Customer Message.<br />
Facebook Password Reset Confirmation! Customer Support.<br />
Facebook Password Reset Confirmation! Important Message.<br />
Facebook Password Reset Confirmation! Support Message.<br />
Facebook Password Reset Confirmation! Your support.</p>
<p>The content of the email:</p>
<blockquote><p>Dear user of facebook,</p>
<p>Because of the measures taken to provide safety to our clients, your password has been changed.<br />
You can find your new password in attached document.</p>
<p>Thanks,<br />
Your Facebook.</p></blockquote>
<p>The email contains the attachment Facebook_document_Nr1637.zip &#8211; where the last 4 digits ay vary &#8211; that contains the executable 48 kB large Facebook_document_Nr1637.exe once extracted.</p>
<p>The trojan is known as Trojan:Win32/Oficla.M (Microsoft), Trojan-Downloader:W32/Oficla.Y (F-Secure) or TR/Crypt.ZPACK.Gen (Antivir).</p>
<p>The trojan will attempt to download a rogue security program identified as TrojanDownloader:Win32/FakeScanti. The Win32/FakeScanti family of trojans will present themselfs as being genuine anti virus programs but instead are malware and display fake warning of possible virus infections on your system. As a user you will be offered to register and pay for the so-called anti virus software.</p>
<p>The following files are being created:</p>
<p>%Temp%\1.tmp<br />
%System%\ngts.vao</p>
<p>The registry key &#8220;HKEY_LOCAL_MACHINE\SOFTWARE\Classes\idid&#8221; is created.<br />
The registry key &#8220;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]&#8221; will be modified.</p>
<p>The trojan can establish a remote connection with the IP 195.78.108.201 on port 80 and retrieve data from hxxp://designfolkov.ru/hules/bb.php?v=200&amp;id=256235564&amp;b=26aprela&amp;tm=2.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/819/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/819/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/819/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=819&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/04/27/new-oficl-trojan-variant-targets-facebook-users-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;updated account agreement&#8221; email contains Bredolab trojan</title>
		<link>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/</link>
		<comments>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 22:26:36 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=751</guid>
		<description><![CDATA[MX Lab started to intercept emails with the subject &#8220;updated account agreement&#8221; that contains the Bredolab trojan. The campaign is designed for Facebook users because of the content. The email comes from the spoofed email address and contains &#8220;Facebook Team&#8221;. The body of the email: Dear Facebook user, Due to Facebook policy changes, all Facebook [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=751&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab started to intercept emails with the subject &#8220;updated account agreement&#8221; that contains the Bredolab trojan. The campaign is designed for Facebook users because of the content. The email comes from the spoofed email address and contains &#8220;Facebook Team&#8221;.</p>
<p>The body of the email:</p>
<blockquote><p>Dear Facebook user,</p>
<p>Due to Facebook policy changes, all Facebook users must submit a new, updated account agreement, regardless of their original account start date.</p>
<p>Accounts that do not submit the updated account agreement by the deadline will have restricted.</p>
<p>Please unzip the attached file and run “agreement.exe” by double-clicking it.</p>
<p>Thanks,<br />
The Facebook Team</p></blockquote>
<p>The email has the ZIP archive agreement.zip attached, once unpacked the file 28 kB big file agreement.exe is available.</p>
<p>Facebook, or any other company, will never distribute agreements,  software updates and patches or anything else in emails. Our recommendation is to delete the email immediatly because a lot of AV engines do not detect this variant very well at the moment.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/3eea167a650a747dad1ec304cf2f46ffaa9be273152d723aeda6d908cf8023d8-1265839538" target="_blank">permlink</a> and MD5: cc632e1dad8775e2bb558a6cd247b94b.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/751/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/751/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/751/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=751&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/02/10/updated-account-agreement-email-contains-bredolab-trojan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Facebook subject to campaign that combines phishing and malware</title>
		<link>http://blog.mxlab.eu/2009/12/08/facebook-subject-to-campaign-that-combines-phishing-and-malware/</link>
		<comments>http://blog.mxlab.eu/2009/12/08/facebook-subject-to-campaign-that-combines-phishing-and-malware/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 19:45:31 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=707</guid>
		<description><![CDATA[MX Lab detected a large new campaign targetting Facebook users. The campaigns combines phishing techniques with the download of malware and a PDF exploit from the web site. The phishing campaign has the same characteristics of the previous campaign that we have posted: Facebook account update (part 1) Facebook account update (part 2) The message is being [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=707&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detected a large new campaign targetting Facebook users. The campaigns combines phishing techniques with the download of malware and a PDF exploit from the web site.</p>
<p>The phishing campaign has the same characteristics of the previous campaign that we have posted:</p>
<p><a href="http://blog.mxlab.eu/2009/10/30/email-regarding-facebook-account-update-is-a-phish/">Facebook account update (part 1)</a><br />
<a href="http://blog.mxlab.eu/2009/11/01/email-regarding-facebook-account-update-is-a-phish-part-2/">Facebook account update (part 2)</a></p>
<p>The message is being sent from the spoofed address &#8220;Facebook &lt;update+umxlabvkqxqrig@facebookmail.com&gt;&#8221; and has various subjects:</p>
<blockquote><p>Facebook account update<br />
Facebook update tool<br />
New login system</p></blockquote>
<p>This is the body of the phishing/malware email:</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091030_facebook_phishing.jpg" alt="" width="450" height="304" /></p>
<p>The included leads to hxxp://www.facebook.com.jjjiok.org.uk/global_directory/MyAccount.php?ref=520***&amp;email=***@***.com.</p>
<p>The phishing web site contains instructions on how to update your account.</p>
<blockquote><p>In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security. Before you are able to use the new login system, you will be required to update your account.<br />
A new Facebook Update Tool has been released for your account. Please download and install the tool using the link below:</p>
<p>updatetool.exe</p>
<p>* Do not use the same password that you use for other online accounts.<br />
* Your new password must be at least 6 characters in length.<br />
* Use a combination of letters, numbers, and punctuation.<br />
* Passwords are case-sensitive. Remember to check your CAPS lock key.</p>
<p>Old Password:<br />
New Password:<br />
(required) 	  ?<br />
Confirm Password:<br />
(required)</p></blockquote>
<p>On this page you can see a web page where you need to confirm your old and new password and the download link to the file updatetool.exe that leads to hxxp://www.facebook.com.jjjiok.org.uk/global_directory/updatetool.exe.</p>
<p>When we have visited the first time the phishing site, an automated download was executed of the file pdf.pdf.</p>
<p>As expected, this PDF contains an exploit. When we submitted the PDF file for examination to Virus Total we got the names EXP/Pidief.FV (Antivir), Exploit.PDF-JS.Gen (BitDefender), Exploit.PDF-JS.Gen (GData), Exploit:Win32/Pdfjsc.CM (Microsoft) and Troj/PDFEx-CD (Sophos).</p>
<p>pdf.pdf:</p>
<p>AV detection rate: 9/40 AV engines did detected the threat<br />
Virus Total <a href="http://www.virustotal.com/analisis/21307e9d7192e464d22d53f0031b48fa4f6ce4fc7cc63399297bce182667213e-1260300974" target="_blank">permlink</a> and MD5: 93cba9349ecc8fb605c7932be0cdc9c6</p>
<p>Updatetool.exe:</p>
<p>AV detection rate: 6/40 AV engines did detected the threat<br />
Virus Total <a href="http://www.virustotal.com/analisis/877f553a2ba6375f24fae50c60b7f13cee3d81074b594a8c5adc634426264f84-1260296072" target="_blank">permlink</a> and MD5: 095fe570f78c322c8e358c656816c200.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/707/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/707/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/707/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=707&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/12/08/facebook-subject-to-campaign-that-combines-phishing-and-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091030_facebook_phishing.jpg" medium="image" />
	</item>
		<item>
		<title>Facebook updated account agreement email contains Sasfis trojan</title>
		<link>http://blog.mxlab.eu/2009/11/07/facebook-updated-account-agreement-email-contains-sasfis-trojan/</link>
		<comments>http://blog.mxlab.eu/2009/11/07/facebook-updated-account-agreement-email-contains-sasfis-trojan/#comments</comments>
		<pubDate>Sat, 07 Nov 2009 00:58:42 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Bredolab]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Facebook trojan]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=649</guid>
		<description><![CDATA[Apparently, the virus campaigns are far from over. MX Lab reported on this blog regarding the latest virus campaign that would be an attempt to grow the Cutwail botnet by infecting new computer systems by launching new trojan variants every few days. MX Lab now intercepts a new Facebook virus campaign from the spoofed address &#60;automailer+gtevzolc@facebook.com&#62; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=649&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Apparently, the virus campaigns are far from over. MX Lab reported on this blog regarding <a href="http://blog.mxlab.eu/2009/11/06/bredolab-surges-to-new-heights-thanks-to-cutwail-botnet/">the latest virus campaign</a> that would be an attempt to grow the Cutwail botnet by infecting new computer systems by launching new trojan variants every few days.</p>
<p>MX Lab now intercepts a new Facebook virus campaign from the spoofed address &lt;automailer+gtevzolc@facebook.com&gt; or similar.</p>
<p>The campaign is send out with one of the following subjects:</p>
<p>Facebook updated account agreement<br />
new Facebook account agreement<br />
new account agreement</p>
<p>The content of the email:</p>
<blockquote><p>Dear Facebook user,</p>
<p>Due to Facebook policy changes, all Facebook users must submit a new, updated account agreement, regardless of their original account start date.<br />
Accounts that do not submit the updated account agreement by the deadline will have restricted.</p>
<p>Please unzip the attached file and run &#8220;agreement.exe&#8221; by double-clicking it.</p>
<p>Thanks,<br />
The Facebook Team</p>
<p>Confirmation Code #: 3233075834</p></blockquote>
<p>The email contains the ZIP archive agreement.zip with the 20 kB big executable agreement.exe inside. This trojan is known as Trojan.Sasfis.A (BitDefender), W32/Sasfis.E (F-Prot) or Trojan:Win32/Oficla.E (Microsoft).</p>
<p>MX Lab submitted the sample to Virus Total at 2009.11.07 00:03:35 UTC and 21 of the 41 AV engines did detect the trojan. The first sample was submitted at 2009.11.06 09:24:44 UTC. So this means that after more than 2 hours 52% of the AV engines can intercept this piece of malware.</p>
<p>Please do remember that Facebook, or any other company, will not communicate in any way like this. Companies like Facebook will not send attachments to update your profile, agreement or anything else.</p>
<p>The trojan will create the files %Temp%\1.tmp and %System%\ifmq.kqo, modify the Windows registry and will try to connect to the remote host 193.104.27.91. The following URLs are requested:</p>
<p>hxxp://193.104.27.91/limpopo/bb.php?id=&amp;v=200&amp;tm=1&amp;b=300<br />
hxxp://193.104.27.91/limpopo/bb.php?id=&amp;v=200&amp;tm=2&amp;b=300<br />
hxxp://193.104.27.91/limpopo/bb.php?id=&amp;v=200&amp;tm=3&amp;b=300</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/0f6a59efee0700489343c37b1cca7c1fba553e2692874ae4be79ad11b209d0b7-1257552215" target="_blank">link</a> and MD5: c175b5afc8bb7a7f716ccf3829412ff1.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/649/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/649/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/649/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/649/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/649/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/649/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/649/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/649/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/649/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/649/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/649/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/649/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/649/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/649/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=649&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/11/07/facebook-updated-account-agreement-email-contains-sasfis-trojan/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Email regarding Facebook account update is a phish &#8211; part 2</title>
		<link>http://blog.mxlab.eu/2009/11/01/email-regarding-facebook-account-update-is-a-phish-part-2/</link>
		<comments>http://blog.mxlab.eu/2009/11/01/email-regarding-facebook-account-update-is-a-phish-part-2/#comments</comments>
		<pubDate>Sun, 01 Nov 2009 10:50:34 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Facebook phishing]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=626</guid>
		<description><![CDATA[MX Lab did intercepted  emails what appeared as Facebook phishing emails. The From address is obviously fake and not related to Facebook in any way. These come in with the subjects: Facebook Account Update Facebook Update Tool new login system But now we did managed to get a working host where the supposed phishing site was hosted. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=626&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab did intercepted  emails what appeared as <a href="http://blog.mxlab.eu/2009/10/30/email-regarding-facebook-account-update-is-a-phish/">Facebook phishing emails</a>.</p>
<p>The From address is obviously fake and not related to Facebook in any way. These come in with the subjects:</p>
<p>Facebook Account Update<br />
Facebook Update Tool<br />
new login system</p>
<p>But now we did managed to get a working host where the supposed phishing site was hosted. We have visited htxxp://www.facebook.com.ujtqwaqo.eu/globaldirectory/LoginFacebook.php?ref=xxx&amp;email=xxx@xxx.com and got the login screen.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091101_facebook_phish_1.jpg" alt="" width="450" height="273" /></p>
<p>When filling in dummy login and password we got redirected to the following screen and to our suprise we didn&#8217;t found a webform to submit personal details but instead <strong>a link to a malware file updatetool.exe</strong>.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091101_facebook_phish_2.jpg" alt="" width="450" height="192" /></p>
<p>This malware is known as Gen:Trojan.Heur.Zbot.gq0@cS0Ulyb (BitDefender), PWS:Win32/Zbot.gen!R (Microsoft) or Mal/EncPk-LE (Sophos). As you may know by know, ZBot is a banking trojan that disables firewall, steals sensitive financial data (credit card numbers, online banking login details), makes screen snapshots, downloads additional components, and provides a hacker with the remote access to the compromised system.</p>
<p>The file %System%\sdra64.exe is created on an infected system. Hidden files are being created: %System%\lowsec\local.ds, %System%\lowsec\user.ds and %System%\lowsec\user.ds.lll all together with a hidden directory %System%\lowsec.</p>
<p>New memory pages created in the address space of the system process(es): %System%\services.exe, %System%\lsass.exe, %System%\svchost.exe, %System%\alg.exe adn %ProgramFiles%\internet explorer\iexplore.exe.</p>
<p>Windows registry modification are also part of the infection and a connection to a remote host will be established: hxxp://193.104.27.42/lcc/ip2.gif and hxxp://193.104.27.42/ip.php.</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/0945d1f1495af9c54a484af5f03ffb11d435361482f464d2fe3fc771438b3ba5-1257024444" target="_blank">permlink</a> and MD5: 1ccbe2c88bbaeb8a72ca0ef7e5e51738. It is detected by only 17 of the 41 AV engines at Virus Total.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/626/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/626/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/626/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/626/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/626/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/626/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/626/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/626/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/626/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/626/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/626/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/626/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/626/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/626/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=626&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/11/01/email-regarding-facebook-account-update-is-a-phish-part-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091101_facebook_phish_1.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20091101_facebook_phish_2.jpg" medium="image" />
	</item>
		<item>
		<title>Email regarding Facebook account update is a phish</title>
		<link>http://blog.mxlab.eu/2009/10/30/email-regarding-facebook-account-update-is-a-phish/</link>
		<comments>http://blog.mxlab.eu/2009/10/30/email-regarding-facebook-account-update-is-a-phish/#comments</comments>
		<pubDate>Fri, 30 Oct 2009 23:25:21 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Facebook phishing]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=617</guid>
		<description><![CDATA[After a virus campaign, MX Lab now also intercepts a phishing campaign targetting Facebook users. The From address is obviously fake and not related to Facebook in any way. This email in particular was directing users to the phishing site hxxp://www.facebook.com.saxzask.me.uk/globaldirectory/LoginFacebook.php?ref=******&#38;email=info@****.com. Unfourtunalty, this host was already down when visiting so we didn&#8217;t had the chance [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=617&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After a virus campaign, MX Lab now also intercepts a phishing campaign targetting Facebook users.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20091030_facebook_phishing.jpg" alt="" width="450" height="304" /></p>
<p>The From address is obviously fake and not related to Facebook in any way. This email in particular was directing users to the phishing site hxxp://www.facebook.com.saxzask.me.uk/globaldirectory/LoginFacebook.php?ref=******&amp;email=info@****.com. Unfourtunalty, this host was already down when visiting so we didn&#8217;t had the chance to investigate it further but we&#8217;ll keep an eye on new ones.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/617/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/617/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/617/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/617/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/617/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/617/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/617/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/617/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/617/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/617/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/617/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/617/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/617/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/617/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=617&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/10/30/email-regarding-facebook-account-update-is-a-phish/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20091030_facebook_phishing.jpg" medium="image" />
	</item>
		<item>
		<title>Facebook message with link to striptease video leads to malware</title>
		<link>http://blog.mxlab.eu/2009/03/19/facebook-message-with-link-to-striptease-video-leads-to-malware/</link>
		<comments>http://blog.mxlab.eu/2009/03/19/facebook-message-with-link-to-striptease-video-leads-to-malware/#comments</comments>
		<pubDate>Thu, 19 Mar 2009 23:27:09 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[striptease]]></category>

		<guid isPermaLink="false">http://blog.mxlab.be/?p=404</guid>
		<description><![CDATA[A message from Facebook Mail with in the subject line &#8220;FaceBook message: Magnificent Striptease Dance (Last rated by Lorena Keyes)&#8221; contains an URL that leads to a host with malware. Some alternative subjects are: FaceBook message: Magnificent girl dancing video clip (Last rated by Sal Velasquez) FaceBook message: Dancing Girl Drunk In The Pub- facebook Video [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=404&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A message from Facebook Mail with in the subject line &#8220;FaceBook message: Magnificent Striptease Dance (Last rated by Lorena Keyes)&#8221; contains an URL that leads to a host with malware.</p>
<p>Some alternative subjects are:</p>
<p>FaceBook message: Magnificent girl dancing video clip (Last rated by Sal Velasquez)<br />
FaceBook message: Dancing Girl Drunk In The Pub- facebook Video (Last rated by Abe Bain)<br />
FaceBook message: Hot Girl Dancing At Striptease Dance Party (Last rated by Lowell Clay)<br />
FaceBook message: Dancing Girl Drunk In The Pub- facebook Video (Last rated by Shane Lucas)</p>
<p>The body of the email:</p>
<blockquote><p>Messages from Your Friends on Facebook, March 19, 2009</p>
<p>You have 1 Personal Message:<br />
Video title: &#8220;Amanda is dancing on Striptease Dance Party, March 14, 2009! We&#8217;re absolutely shocked!&#8221;.</p>
<p>Proceed to view full video message:</p>
<p>hxxp://facebook.shared.default.personalid-f58xc9cp8.launchpad.videosshared.com/home.htm?/efsonline/application=3l6mwjxsb1kpema</p>
<p>Message ID: FB-wtq2w9w5ig7z5gf<br />
2009 Facebook community, Message Center.</p></blockquote>
<p>The URL will lead to the Facebook look-a-like web site where the video is proposed.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090319_facebook_malware_1.jpg" alt="" width="450" height="271" /></p>
<p>From this page on you are required to download the newest Adobe Flash player. The file itself is presented as Flash_Adobe11.exe and is the same malware as in the <a href="http://blog.mxlab.be/2009/03/19/comcast-high-speed-self-installation-kit-is-malware/" target="_self">Comcast High Speed Self Installation Kit malware</a> posted earlier today.</p>
<p>The malware contains the Rootkit.Agent.EX that hides its presence in infected machine in order to perform malicious actions without user’s knowledge. A file %Windir%\9129837.ex,  %System%\abcdefg.bat and %Windir%\new_drv.sys (a hidden file) is being created on an infected machine.</p>
<p>A new hidden process 9129837.exe is started and the following system services are stopped on the computer: ALG (Application Layer Gateway Service), SharedAccess (Windows Firewall/Internet Connection Sharing), wscsvc (Security Center). The malware makes connection on the IP 58.65.232.17, server port 80, with one of the following GET requests:</p>
<p>cgi-bin/cmd.cgi?user_id=412227526&amp;version_id=12&amp;passphrase=fkjvhsdvlksdhvlsd<br />
&amp;socks=14477&amp;version=125&amp;crc=00000000</p>
<p>cgi-bin/options.cgi?user_id=412227526&amp;version_id=12&amp;passphrase=fkjvhsdvlksdhvlsd<br />
&amp;socks=14477&amp;version=125&amp;crc=00000000</p>
<p>Virus Total <a href="http://www.virustotal.com/analisis/7e0c1b09d91d038720b56c4e2aca939f" target="_blank">permalink</a> and MD5: 8bf819ad4704aab758f86684a108c2a1.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/404/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/404/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/404/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=404&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/03/19/facebook-message-with-link-to-striptease-video-leads-to-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090319_facebook_malware_1.jpg" medium="image" />
	</item>
	</channel>
</rss>
