TUCoPS :: HP Unsorted F :: bx3998.htm

facebook messages worm
facebook messages worm
facebook messages worm

Hi all.

There's a facebook (possibly worm) something malicious sending fake 
messages from real users (friends).

The sample also has a remote drop site (verified by someone who shall 
remain nameless).

This is possibly zlob, not verified. Thanks Nick Bilogorskiy for his help.

Infection sites seen so far are on .pl domains.

The AV industry will soon add detection.
Facebook's security folks are very capable, so I am not worried on that 

It's not that we didn't expect this for a long time now, but...
Be careful. Some users know to be careful in email.. but not on facebook.

Note: unlike 2003 when we called everything a worm and the 90s when 
everything was a virus--this is a bot which also spreads/infects on facebook.


"You don't need your firewalls! Gadi is Israel's firewall."
     -- Itzik (Isaac) Cohen, "Computers czar", Senior Deputy to the Accountant General,
        Israel's Ministry of Finance, at the government's CIO conference, 2005.

     (after two very funny self-deprication quotes, time to even things up!)

My profile and resume:

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH