ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Malware Watch: 'Spam is sent from your FaceBook account'; Spamvertised malicious photos

By | April 19, 2011, 8:06am PDT

Summary: Malicious attackers are currently spamvertising two separate malware campaigns, enticing end users into downloading and executing malicious file attachments.

Malicious attackers are currently spamvertising two separate malware campaigns, enticing end users into downloading and executing malicious file attachments.

- Spam is sent from your FaceBook account

The first campaign is a variation of last week’s Spamvertised ‘Facebook. Your password has been changed!’ emails lead to malware campaign, and is once again impersonating Facebook on its way to social engineer end users.

Sample subject: Spam is sent from your FaceBook account

Sample message: Dear client, Spam is sent from your FaceBook account. Your password has been changed for safety. Information regarding your account and a new password is attached to the letter. Read this information thoroughly and change the password to complicated one. Please do not reply to this email, it’s automatic mail notification! Thank you. FaceBook Service.

The malware is detected as Mal/BredoZp-B.

- I’m going to send you the Photos in

The second campaign is relying on out of the blue photos notification, using password-protected .zips (DSC0173519.zip) containing the DSC0173519.exe executable.

Not surprisingly, these campaigns and their related variantions (Spamvertised Post Office Express Mail (USPS) emails lead to malware; Spamvertised DHL notifications lead to malware) are resulting in an increased growth in ZIP file attachments, which vendors contribute to the intensifying campaigning of the Bredolab gang.

Users are advised to avoid interacting with malicious file attachments or links found in spam emails in general.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter
8
Comments

Join the conversation!

Just In

RE: Malware Watch: 'Spam is sent from your FaceBook account'; Spamvertised malicious photos
weblaranja 1st Nov
Nice to know that...
acompanhantes sao paulo
garotas de programa sp
"which vendors contribute to the intensifying "

Attribute to?
@dieseltaylor Pulauweb Web Hosting Murah Indonesia
Blogger Nusantara Blogpreneur Indonesia
0 Votes
+ -
got it
hankhallmeyer 19th Apr 2011
thx
I've seen things like this as well. The good thing is that I NEVER open them, and the funny thing is, that when you read this type of thing, all you have to do is look at the second rate English that is being used. That's gotta be the first RED FLAG for anyone. Spammers are quite well known for not being able to spell correctly and for using broken English. You'd think that the Facebook crowd would figure this out if they are savvy enough to be able to spell correctly and use proper English.
Pity we can't have a screening device that blocks all grammatically incorrect messages. Add on the ability to screen out bad spellers and Voila! no more idiot communications. Just think of how much internet traffic would be totally eliminated and how many of these annoying people would be effectively gagged by such a filter. Perhaps we could induce the public to write in full sentences once again and rescue the english language from being reduced to inane "acronym-speak".
I live for the day when OMG and LOL and all their 3 letter relatives become passe'.
Well done! Thank you very much for professional templates and community edition
sesli chat sesli sohbet
Just think of how much internet traffic would be totally eliminated and how many of these annoying people would be effectively gagged by such a filter. Perhaps we could induce the public to write in full sentences once again and rescue the english language from being reduced to inane....congratulations for the work
Ar Condicionado
Massagista
Acompanhantes
Nice to know that...
acompanhantes sao paulo
garotas de programa sp

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix