Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Digg this story   Add to del.icio.us  
Fake Facebook, Fake Video, Fake CAPTCHA
F-Secure, 2009-10-20
Watching videos in Facebook is a popular activity, so it's not surprising to find dozens of fake copycat sites being used to infect unsuspecting viewers with malware.

Here's one fake Facebook site with a malicious Javascript that uses the old "Flash Player upgrade installation" trick - but with a slight twist.

As usual, the viewer thinks they're going to see a video, if they just upgrade their Player:

facebook_vid_malware_1
But first they have to download and install the "upgrade":

facebook_vid_malware_2

The unusual thing is, this "upgrade" comes with a CAPTCHA pop-up:

facebook_vid_malware_3

The request is displayed at random times and doesn't actually do anything. Anything entered into the field by the user results in this being displayed:

facebook_vid_malware_4

The screen will close after a few tries, but will still continue to appear off and on.

While the user is having dubious fun with the CAPTCHA test, the malware copies a couple files to C:\Windows, deletes itself and creates a few Registry keys.

facebook_vid_malware_5

We detect the malware as Trojan:W32/Agent.MDN.

Our Browsing Protection blocks the whole fake Facebook website entirely. As usual though, be careful when you're surfing.

---
WebSecurity post by - Choon Hong

On 20/10/09 At 06:52 AM




The information, views, and opinions contained on this page are those of the author and do not necessarily reflect the views and opinions of SecurityFocus.






 

Privacy Statement
Copyright 2009, SecurityFocus