ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

New tricks for Koobface

highMalwareimportance 42
Full article362 words · extracted from securelist.com · click to collapse

Malware descriptions

Malware descriptions

06 Aug 2009

minute read

Once again, there’s a new wave of Koobface.

But this time, the tactics have changed. There’s a new twist to the social engineering, with links from infected messages leading to a very well designed Facebook lookalike page (far more convincing than the previous YouTube page)

And Koobface is now sending unique tweets. Messages sent in previous attacks were all the same:

“My home video 🙂 [URL]”

Now there’s a random component being added, with strings like “HA-HA-HA!!”, “W.O.W.”, “WOW”, “L.O.L.”, “LOL”, “;)” or “OMFG!!!” at the end of each tweet, so the malicious tweets look like this:

They are also adding a random component to the Koobface landing page so now, the URL gets shortened to a different bit.ly URL each time (see my post about the dangers of short URLs) making it harder for Twitter to filter and delete infected messages.

i.e. http://u*******.se/pub1icm0vies/?[RANDOM] -> http://bit.ly/[RANDOM]

This week everyone’s been talking about how Twitter started to use the Google Safebrowsing API to block tweets containing malicious URLs. It is definitely going to stop some attacks, but as we’re seeing with the current attack, it won’t eradicate the problem completely. It’s clearly a step forward, but a single swallow doesn’t make a summer.

We detect the malicious binary as Net-Worm.Win32.Koobface.d and the script that is doing the redirect on the landing page as Trojan-Clicker.HTML.IFrame.ob.

Currently we’ve identified almost 100 unique IP addresses hosting Koobface. We’ll keep you posted!

UPDATE: We’re working on getting the main Koobface page taken down.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/new-tricks-for-koobface/30545/