::Trend Micro Threat Resource Center::

11 November 2009

Koobface worm creates Facebook accounts to spread

Be careful the next person you approve as your friend on Facebook.

According to TrendLabs, there is a new Koobface component that makes Internet Explorer create Facebook accounts. It automates the whole process - the browser registers the account, confirms and activates the registration via Gmail, joins random Facebook groups, adds friends, posts messages to their walls...

It actually does a good job at imitating a person starting its Facebook account - the details it provides are complete, credible and vary from account to account: photo, birth date, favorite movies, religious views, etc. These details are picked up from one of the botnet’s available proxy domain.

Another "smart" Koobface feature is that after it has created the account, it makes sure not to surpass the maximum number of friend requests allowed by Facebook, so it doesn't raise the suspicions of its administrators.

The messages that the account posts on friends' walls usually has a link that, if clicked, takes the unsuspecting user to a site that hosts the Koobface loader.

09 November 2009

iPhone worm spreads via default password

In my earlier post about Hacked iPhones held hostage, here's another piece:

An iPhone worm has started jumping between jailbroken devices, taking advantage of users who have replaced the phone's software but failed to create a new root password, security firm F-Secure stated on Monday.

Affected users will find that their iPhone wallpaper has been altered to a picture of Rick Astley (of Rickroll fame) and the message "ikee is never going to give you up".

The worm targets users who have jailbroken their phone but have not changed their default root login password. It will search for vulnerable iPhones by scanning a handful of IP ranges - most of which are in Australia. At the moment, we have no confirmed reports of Ikee outside of Australia.

After Ikee infects a phone, it disables the SSH service, preventing reinfection. To protect your jailbroken iPhone, change your root password. Here's how.

The creator of the worm has released full source code of the four existing variants of this worm. This means that there will quickly be more variants, and they might have nastier payload than just changing your wallpaper or might try password cracking to gain access to devices where the default password has been changed.

Source.

05 November 2009

Facebook best practice

I can't stress enough how important it is to take responsibility of what you post up on the Internet, especially on social networking websites. What you reveal about yourself may eventually be used against you - Refer to the earlier post I made about public search engines mining your private Facebook profile details.

I've observed that of late, many of my friends around me are plagued with this Wall posting weird activity. Facebook has provided users with powerful controls to protect themselves online, and it is up to individuals to check and ensure that appropriate settings are in place.

Sophos has published recommendations for how to configure the settings for each of these privacy areas of Facebook.

Take a look here.

Windows 7 vulnerable to most viruses

Windows 7 was touted as a big improvement on Vista, security aspect included.

The Sophos team wanted to test that assertion, so they installed a full release copy of the new OS on a previously cleaned computer, kept the default values for User Account Control (UAC) and didn't install any anti-virus software.

They then proceed to infect the machine with 10 unique samples of malware that SophosLabs received last. The result wasn't good for the users (although it technically is a good result for manufacturers of anti-malware software around the world): only 2 out of 10 failed to operate!

The UAC managed to block by itself only on sample, and that is definitely not good enough.

The conclusion? If you installed Windows 7, don't forget to use anti-virus software.

04 November 2009

Hacked iPhones held hostage

Dutch T-mobile customers that use jailbroken iPhones got a nasty surprise yesterday. A "message" popped up on their screen claiming that their iPhone's been hacked and instructs them to visit doiop.com/iHacked and secure their iPhones. To add more incentive, the hacker also wrote: "Right now, I can access all your files."

When the scared users would visit the website, they were asked to send €5 to the hacker's PayPal account so he can send them instructions on how to secure their device.

How did this happen? It seems that the hacker identified the jailbroken iPhones using port scanning, because those particular devices have SSH running. SSH has to be enabled for the user to log in via Terminal and run UNIX commands, and the default root password often gets forgotten and remains unchanged. The hacker used this fact to hack into the phones.

Although it appears that the hacker didn't misuse any of the data he had access to - afterwards he posted the instructions on the website, apologized and returned the money - it doesn't mean that someone else will not, since the technique is pretty simple to execute and requires only a basic knowledge of networking.

To all iPhone users that have jailbroken their device, it is advised to shut down SSH when it's not needed and to change the default root password.

02 November 2009

Trojan.Whitewell: What’s your (bot) Facebook Status Today?

I'm very sure by now, most of you Facebookers would have received some weird posts on your Walls from either your friends or your friends would have notified you that you posted something on their wall.

Here are some sample messages:
  • Thought you might want to check this out http://_fb-newss.org
  • has made $159 today working at home! go to TheBizMeet.com to see how you can start! ktq
  • For You http://_newwss2.org
  • I found a job you might be interested in news44.org
Here is a breakdown of what's happening.

If you discover that your account has been used to post weird links on your friend's Walls, you should immediately do the following:
  • Change the password of your FB account.
  • Change the password of the email account linked to your FB.
  • Get your antivirus updated with the latest virus definitions with perform a full scan.
  • If you do not have antivirus software installed on your computer, pls proceed here to download a free copy.