Emsisoft warns: Zbot Trojan spreads through fake Facebook requests

Always
the users of social networks are more often in the crosshairs of
Malware spreaders. Currently, Emsisoft is increasingly observing fake
Friend requests for the Facebook network. Anyone who does not consider such a request
Confirmed, lured to a fake Facebook page and malware
Like the Zbot Trojan. Emsisoft warns: Beware
Fake friends like Kaamil Mahmoud!

Salzburg,
August 2011 – Every Facebook user knows this and is also happy about it:
If a friend or acquaintance wants to network with you on Facebook,
So he sends a friend request. This does not only reach the recipient
the Facebook page itself, but also via an e-mail that
is sent automatically. A mouse click is already enough at this point,
to win a new boyfriend or girlfriend. A lot of friends means
A good image in the online world. Emsisoft’s Malware Analysis Team Warns
But now before too hasty with the invitation mails. They shall:
Currently used increasingly by criminals, users with more dangerous
Infecting malware.

One of these currently circulating phishing emails has now been sent by Emsisoft.
analysed. The English mail is titled “Kaamil Mahmoud wants to be”
Friends on Facebook. The name is interchangeable, but use similar mails
Names such as Uqbah Qasim, Jasoor Shaheen, Talaal Issa, Rayyaan Sulayman or
Inaaya Qasim. If the user clicks on “Confirm Friend Request”, the link leads
but not directly to the Facebook.com page, but to a completely different one that
It is not part of the Facebook group.

The fake page looks like a Facebook page, but it is
None. On the page is the usual text the surprising message: Your
Macromedia Flash Player is too old to continue. Download and install
the latest version of Adobe Flash Player. As soon as the users arrive at
click on the offered link “Download and Install”, the browser loads a malware
with the filename updateflash.exe. It contains the well-known trojan Zeus, which
Also known as ZBot.

Anyone who does NOT start this file is unfortunately not yet on the safe side.
The fake Facebook page automatically loads another
Website in the background. The exploit script that is now in a hidden iFrame
It is part of the BlackHole exploit kit. The script now tries to
Infiltrate the victim’s computer by infiltrating existing security vulnerabilities, such as
Java is exploited. The script allows criminals to use malware.
automatically start without the infected user noticing and
without further interaction with the user.

Emsisoft Managing Director Christian Mairoll: “The safest thing to do is to
users only log in directly to facebook.com and new
Accept friendships only here. How to Secure All Phishing Attacks
out of the way. Anyone who still uses the links in the e-mails should
Keep an eye on target URLs. Often a mouseover over the link is enough,
to find out the true web destination address. Of course it is worth it
Also, to ignore all requests from people you do not know.

Press release Emisoft