main

Kaspersky Detects New Worms Attacking MySpace and Facebook

Daniel Fleshbourne   on 01 August 2008 - 13:39 · 24 comments & 11189 views

Advertisement (Why?)
Kaspersky Labs, has detected two variants of a new worm, Networm.Win32.Koobface.a. and Networm.Win32.Koobface.b, which attack MySpace and Facebook users.

The worms transform victims machines into zombie computers to form botnets which are used to create DDOS attacks and send spam email.

Net-Worm.Win32.Koobface.a infects the user when they access accesses their MySpace account. The worm creates a range of commentaries to friends' accounts.

Net-Worm.Win32.Koobface.b, targets Facebook users, creates spam messages and sends them to the infected users' friends via the Facebook site.

The messages and comments include texts such as "Paris Hilton Tosses Dwarf On The Street"; "Examiners Caught Downloading Grades From The Internet"; "Hello; You must see it!!! LOL. My friend catched you on hidden cam"; "Is it really celebrity? Funny Moments and many others".

Messages and comments on MySpace and Facebook include links to youtube.[skip].pl. If the user clicks on this link, s/he is redirected to http//youtube.[skip].ru, a site which purportedly contains a video clip. If the user tries to watch it, a message appears saying that s/he needs the latest version of Flash Player in order to watch the clip.
However, instead of the Flash Player, a file called codesetup.exe is downloaded to the victim machine; this file is also a network worm. The result is that users who have come to the site via Facebook will have the MySpace worm downloaded to their machines, and vice versa.

Post a comment · Send to friend Comments · There are 24 additional comments
(5 replies) #1 +DrunkenMaster on 01 Aug 2008 - 14:55
Great. Another social setting where you can get a "virus". The girl at the bar seems a lot better than Facebook right now .....
#1.1 Majesticmerc on 01 Aug 2008 - 16:59
Yeah who says you can't get an STI through poking someone on Facebook

Last edited by Majesticmerc on 01 Aug 2008 - 17:58
#1.2 andy2004 on 01 Aug 2008 - 17:21
(DrunkenMaster said @ #1)
Great. Another social setting where you can get a "virus". The girl at the bar seems a lot better than Facebook right now .....


having just come out of an abusive relationship facebook seems more fun right about now
#1.3 hotdog963al on 01 Aug 2008 - 18:33
Going outside? heh, **** that!
#1.4 +rm20010 on 01 Aug 2008 - 19:12
(Majesticmerc said @ #1.1)
Yeah who says you can't get an STI through poking someone on Facebook


#1.5 Tha Bloo Monkee on 01 Aug 2008 - 22:41
There are plenty of people who have lives and have Facebook, you know...
#2 godzila on 01 Aug 2008 - 14:58
how desinfected this??
(4 replies) #3 XeonBuilder on 01 Aug 2008 - 16:11
Best way to avoid is not to join

Those sites are for 15yr old girls and 40yr old guys looking for 15 yr old girls
#3.1 Danielx714 on 01 Aug 2008 - 16:25
hey, im not 40
#3.2 Brandon on 01 Aug 2008 - 16:26
(XeonBuilder said @ #3)
Best way to avoid is not to join

Those sites are for 15yr old girls and 40yr old guys looking for 15 yr old girls


Or for keeping in contact with friends when you are in college / graduate
#3.3 Majesticmerc on 01 Aug 2008 - 17:06
(Danielx714 said @ #3.1)
hey, im not 40


Dude chill, he's saying you look younger than you actually are!

-------------

Seriously, I have facebook at 21, and the average age of most of my friends is about the same. It's a good, and free way of keeping in touch with more friends than you can any other way. Social networking is good, Profiles filled with crap is bad.
#3.4 ThaCrip on 01 Aug 2008 - 23:58
LOL @ XeonBuilder... you said, "Those sites are for 15yr old girls and 40yr old guys looking for 15 yr old girls"

that's the way i see it... it's just crappy made as the site is bloated and unprofessional looking... i aint seen facebook so maybe thats better than myspace.

bottom line i never use either of em and probably never will.
#4 XeonBuilder on 01 Aug 2008 - 16:12
#5 Esvandiary on 01 Aug 2008 - 16:43
The messages and comments include texts such as "Paris Hilton Tosses Dwarf On The Street"

... and the rest of us are just amused by gems such as that.
#6 Faisal Islam on 01 Aug 2008 - 16:56
lolz..We just need a powerful link scanner.
#7 GSDragoon on 01 Aug 2008 - 19:14
Messages and comments on MySpace and Facebook include links to youtube.[skip].pl. If the user clicks on this link, s/he is redirected to http//youtube.[skip].ru, a site which purportedly contains a video clip. If the user tries to watch it, a message appears saying that s/he needs the latest version of Flash Player in order to watch the clip.
However, instead of the Flash Player, a file called codesetup.exe is downloaded to the victim machine; this file is also a network worm. The result is that users who have come to the site via Facebook will have the MySpace worm downloaded to their machines, and vice versa.


If people fall for this then they deserve to get infected. It's not like you can't see this stuff comming and hit no to stop it. People need to pay more attention to what they are doing. Don't just hit ok when a message box pops up. Read it and then choose an answer wisely.
(2 replies) #8 KingRocky on 01 Aug 2008 - 19:15
Not trying to flame-bait here, but that and the other 70,000 viruses are why my primary computer is now a Mac. I still use Windows, but only when I have to.
#8.1 MPH on 01 Aug 2008 - 19:29
You have to download and execute the supposed codec to get infected. It's not like you get infected by simply visiting the site. Smart users have really not to worry about this one.
#8.2 sharp65 on 01 Aug 2008 - 20:28
Most of it is common sense...I've never gotten a virus and I've been using windows for years.
#9 +Berserk87 on 01 Aug 2008 - 21:15
how many people checked facebook after reading this?
#10 Budious on 01 Aug 2008 - 21:36
I admit, I would have probably clicked on "Paris Hilton Tosses Dwarf On The Street" out of curiosity.
#11 Airlink on 01 Aug 2008 - 23:14
#12 jOshay on 02 Aug 2008 - 00:33
I have been using windows for over 5 years now, never had a virus.
#13 br_ on 02 Aug 2008 - 03:25
Anyone else dislike the blatant Kaspersky ad?

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)