[ insider_reports_insider ] Another Day Another Social Network Phishing Spoof
SecurityProNews Staff Writer
2009-03-13
Insider Reports RSS Feed
A phishing email is making the rounds. Can you guess which Internet giant the hackers are spoofing this time? If it's not Google or Twitter then it must be Facebook, right? Right.
 | | Another Day Another Social Network Phishing Spoof |  |
At least it appears their English is getting better. Not perfect, just better.
The emails purport to be from Facebook and try to dupe recipients into following a link supposedly leading to a striptease video.
The subject lines vary, but three of them are as follows:
FaceBook message: Girls Dancing on facebook Video (Last rated by Fannie Cano)
FaceBook message: Dancing girl oriental dance (Last rated by Abdul Kay)
FaceBook message: Hot Girl Dancing At Striptease Dance Party
If you're a Facebook user this should seem odd right away if you've paid any attention to the types of messages Facebook sends out. Book is capitalized, it doesn't say who at Facebook sent it, the "rated by" thing is off, and well, Facebook doesn't generally send out or allow porn.
One imagines the tactic isn't going to work for people who have good filters, who are familiar with how Facebook operates, looks, and feels, or with a modicum of self-click-control. Still it does illustrate the continuance of the recent trend to target social network users, especially Facebook and Twitter users these days. Facebook has around 175 million users and growing, making it nearly as attractive as Google itself as a target.
A screen shot of the email can be found at Trend Micro's blog, where Bernadette Irinco describes what kind of trouble following that link can get one into:
"Clicking the link, lands users to a bogus Facebook site that asks the user to install the malicious file, Adobe_Player11.exe to watch the video. Trend Micro detects this file as TSPY_PAPRAS.AX. PAPRAS variants are info-stealers that launch a carnivore sniffer to retrieve passwords from network packets. It then sends gathered information to a remote site."
View All Articles by SecurityProNews
About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.
More insider_reports_insider Articles
Insider Reports RSS Feed
|
|