Friday, October 1, 2010

Facebook Worm: Your friends hidden camera video

A new worm is spreading in FaceBook. An infected friend account will send you a message telling you, "it was a ggood id3a to hidde acamera in the bathr4oom" and it has a part of the message that orignially comes from the user to help you believe it is real. It invites you to view the link http colon slash slash arieyarieyakturk dot blogspot dotcom if you click on it it will redirect you to http colonslash slash foodsafe dot grslash0z2a8uz/.


foodsafe dot gr slash 0z2a8uz will display a page similar to that of an old youtube video page. It has a description box etc. and it has a video thumbnail of a bugged bathroom. Curious, you may want to give the video a shot but it has an error and it requires you to download what they claim to be a "flash player update". A download dialogue box will appear automatically.

This is the download box that automatically appears when you visit the page. noticeably its filename and source location doesnt have anything to do with flash player. If you run this file. You are owned.


I haven't got a chance to test this file in a computer with a live facebook account but i'll give it a shot to see its payload. I can just imagine that once this is run in a computer with fb account information stored, such account will at least start sending this same malware to everyone.

4 comments:

  1. I think i just got fucked up... I downloaded the files and run it.

    ReplyDelete
  2. Guess you really are. :)

    ReplyDelete
  3. Any update on this?

    ReplyDelete
  4. Great) liked everything very much) keep it up and dont stop)BCFBL

    ReplyDelete

Did this help you?
How can we help you further?