Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Dissecting the Latest Koobface Facebook Campaign
November 13, 2008 16:08



    
The latest Koobface malware campaign at Facebook, is once again exposing a diverse ecosystem worth assessing in times of active migration to alternative ISPs tolerating or conveniently ignoring the malicious activities courtesy of their customers. The -- now removed -- binaries that the dropper was requesting were hosted at the American International Baseball Club in Vienna, indicating a compromise.

us.geocities .com/adanbates84/index.htm
lostart .info/js/js.js (79.132.211.51)
off34 .com/go/fb.php (79.132.211.51)
youtube-spyvideo .com/youtube_file.html (58.241.255.37)
ahdirz .com/movie1.php?id=638&n=teen (208.85.181.69)
top100clipz .com/m6/movie1.php?id=638&n=teen (208.85.181.67)
hq-vidz .com/movie1.php?id=638&n=teen (208.85.181.68)

The dropper then phones back home to : f071108 .com/fb/first.php (79.132.211.50) with the binaries hosted at a legitimate site that's been compromised :

aibcvienna.org/youtube/ bnsetup24.exe
aibcvienna.org/youtube/ tinyproxy.exe

Related fake Youtube domains participating :
catshof .com (79.132.211.51)
youtube-spy .info (94.102.60.119)
youtubehof .net (218.93.205.30)
youtube-spyvideo .com (58.241.255.37)
yyyaaaahhhhoooo.ocom .pl (67.15.104.83)
youtube-x-files .com (94.102.60.119)

The development of cybercrime platforms utilizing legitimate infrastructure only, has always been in the works. With spamming systems relying exclusively on the automatically registered email accounts at free web based providers, to the automatic bulk registration of hundreds of thousands of domains enjoying a particular domain registrar's weak anti-abuse policies, it would be interesting to monitor whether marginal thinking or improved OPSEC relying on compromised hosts will be favored in 2009.

Related posts:
Fake YouTube Site Serving Flash Exploits
Facebook Malware Campaigns Rotating Tactics
Phishing Campaign Spreading Across Facebook
Large Scale MySpace Phishing Attack
Update on the MySpace Phishing Campaign
MySpace Phishers Now Targeting Facebook
MySpace Hosting MySpace Phishing Profiles

All news for January 5, 2009
  22:56  Schneier on Security: FBI's New Cryptanalysis Contest
  22:03  Steve Riley on Security: Poll: do you use scheduled scans for malware?
  18:22  Martin McKeay: Four information points on Twitter phishing
  14:34  Schneier on Security: Trends in Counterfeit Currency

All news for January 3, 2009
  00:49  Schneier on Security: Friday Squid Blogging: Climate Change Affects Squids
  00:08  Schneier on Security: Friday Squid Blogging: Squid Attacks ROV

All news for January 2, 2009
  20:17  Schneier on Security: Another Recently Released NSA Document
  18:13  Martin McKeay: Welcome to 2009
  14:42  Schneier on Security: Software Security
Keywords: dissecting, the, latest, koobface, facebook, campaign

All news for January, 2009


All news for 2008


All news for 2009