ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

56th variant of the Koobface worm detected

By | May 15, 2009, 10:46am PDT

Summary: Researchers from PandaLabs are reporting on the detection of the 56th variant of the Koobface worm (Boface.BJ.worm), spreading across Facebook, Tagged, Friendster, MySpace, MyYearBook, Fubar.com, Hi5 and Bebo since May, 2008. According to the company, the growth of Koobface related infections is as high as 1,200% since the first time it was detected over an year [...]

Researchers from PandaLabs are reporting on the detection of the 56th variant of the Koobface worm (Boface.BJ.worm), spreading across Facebook, Tagged, Friendster, MySpace, MyYearBook, Fubar.com, Hi5 and Bebo since May, 2008.

According to the company, the growth of Koobface related infections is as high as 1,200% since the first time it was detected over an year ago, where almost 40% of the infections based in the U.S, with the growth trend also confirmed by Microsoft’s Malware Protection Center.

What the cybercriminals have changed this time is the template, the use of an Ukrainian web site hosting service, and the “missing” fake codec, which upon execution is not only converting the infected PC into a hosting provider part of the campaign, but is also pushing scareware, liveantimalwareproscanner .com and live-antimalware-scanner .com in particular.

Despite the ongoing industry collaboration, and with MySpace already declaring victory over Koobface, the persistence of the malware gang using social engineering tactics, typosquatting of social networking domains, and their outsourcing of the CAPTCHA breaking process aimed to slow down automated abuse of the sites, makes Koobface a success story (see sample statistics) that you should keep an eye on.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
5
Comments

Join the conversation!

Just In

RE: 56th variant of the Koobface worm detected
birumut Updated - 2nd May 2011
Well done! Thank you very much for professional templates and community edition
seslisohbet seslichat
0 Votes
+ -
One more...
kozmcrae 15th May 2009
And there will be 57 varieties. Pass the relish please.
0 Votes
+ -
Is there an OS X version?
zkiwi 15th May 2009
I don't want to be left out. Or for that matter a Linux version.
0 Votes
+ -
The crackers have too much time on their so they have make all of these variants of malware and I'm sure that this will not stop for a long time.
0 Votes
+ -
RE: 56th variant of the Koobface worm detected
gertruded Updated - 16th May 2009
A WINDOWS problem. The articles never say that.

Does this one take us over 300,000 WINDOWS VIRUSES and Worms yet?
0 Votes
+ -
RE: 56th variant of the Koobface worm detected
birumut Updated - 2nd May 2011
Well done! Thank you very much for professional templates and community edition
seslisohbet seslichat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix