{"id":2033,"date":"2010-01-20T12:40:26","date_gmt":"2010-01-20T19:40:26","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=2033"},"modified":"2018-01-30T11:09:35","modified_gmt":"2018-01-30T18:09:35","slug":"spongeface-koobface-variant-uses-spongebob-as-a-tease","status":"publish","type":"post","link":"https://www.webroot.com/blog/2010\/01\/20\/spongeface-koobface-variant-uses-spongebob-as-a-tease\/","title":{"rendered":"&#8216;Spongeface&#8217; Koobface Variant Uses Spongebob as a Tease"},"content":{"rendered":"<p class=\"getsocial\" style=\"text-align:left;\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2005.png\" alt=\"\" \/><a title=\"Add to Facebook\" href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/blog.webroot.com\/2010\/01\/20\/spongeface-koobface-variant-uses-spongebob-as-a-tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2015.png\" alt=\"Add to Facebook\" \/><\/a><a title=\"Add to Digg\" href=\"http:\/\/digg.com\/submit?phase=2&amp;url=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease&amp;title=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20as%20a%20Tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2025.png\" alt=\"Add to Digg\" \/><\/a><a title=\"Add to Del.icio.us\" href=\"http:\/\/del.icio.us\/post?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease&amp;title=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20as%20a%20Tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2035.png\" alt=\"Add to Del.icio.us\" \/><\/a><a title=\"Add to Stumbleupon\" href=\"http:\/\/www.stumbleupon.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease&amp;title=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20as%20a%20Tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2045.png\" alt=\"Add to Stumbleupon\" \/><\/a><a title=\"Add to Reddit\" href=\"http:\/\/reddit.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease&amp;title=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20as%20a%20Tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2055.png\" alt=\"Add to Reddit\" \/><\/a><a title=\"Add to Blinklist\" href=\"http:\/\/www.blinklist.com\/index.php?Action=Blink\/addblink.php&amp;Description=&amp;Url=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease&amp;Title=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20as%20a%20Tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2065.png\" alt=\"Add to Blinklist\" \/><\/a><a title=\"Add to Twitter\" href=\"http:\/\/twitter.com\/home\/?status=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20a...+%40+http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2075.png\" alt=\"Add to Twitter\" \/><\/a><a title=\"Add to Technorati\" href=\"http:\/\/www.technorati.com\/faves?add=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2085.png\" alt=\"Add to Technorati\" \/><\/a><a title=\"Add to Furl\" href=\"http:\/\/www.furl.net\/storeIt.jsp?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease&amp;t=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20as%20a%20Tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2095.png\" alt=\"Add to Furl\" \/><\/a><a title=\"Add to Newsvine\" href=\"http:\/\/www.newsvine.com\/_wine\/save?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F01%2F20%2Fspongeface-koobface-variant-uses-spongebob-as-a-tease&amp;h=%27Spongeface%27%20Koobface%20Variant%20Uses%20Spongebob%20as%20a%20Tease\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2105.png\" alt=\"Add to Newsvine\" \/><\/a><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2115.png\" alt=\"\" \/><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/01\/20100120_spongeface_video.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-2038\" title=\"20100120_spongeface_intro\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/01\/20100120_spongeface_intro.jpg\" alt=\"\" width=\"294\" height=\"119\" \/><\/a>A new variant of the Koobface social networking worm is sending social networkers links that lead to fake videos supposedly posted by the beloved cartoon antihero Spongebob Squarepants. The fake videos only display a popup message labeled &#8220;Adobe Flash Player Update&#8221; that says &#8220;<strong>This content requires Adobe Flash Player 10.37. Would you like to install it now?<\/strong>&#8221; Clicking anywhere on the page downloads the Koobface installer to the victim&#8217;s PC.<\/p>\n<p>The technique isn&#8217;t new, but this is the first sign that the crew behind Koobface is switching from &#8216;holiday mode&#8217; (when they sent around links to videos that were supposedly posted by Santa Claus) to &#8216;post-holiday mode.&#8217;<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/01\/20100120_spongeface_video_flash.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignright size-full wp-image-2039\" title=\"20100120_spongeface_video_flash\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/01\/20100120_spongeface_video_flash.jpg\" alt=\"\" width=\"226\" height=\"147\" \/><\/a>In other ways, the worm features a few small tweaks: Its Captcha tool, which attempts to convince infected users to enter the text of a captcha into a dialog box, has been modified to read and properly display the new ReCaptcha format used by some social network sites. The new format randomly places black circles &#8216;behind&#8217; the text, and inverts the text of the captcha phrase where the text and black circles intersect.<\/p>\n<p><!--more--><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/01\/20100120_spongeface_captcha.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-2040\" title=\"20100120_spongeface_captcha\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/01\/20100120_spongeface_captcha.jpg\" alt=\"\" width=\"428\" height=\"332\" \/><\/a><\/p>\n<p>The dialog box warns users that their PC will shut down if they don&#8217;t enter the correct information before a three-minute timer runs down, but users don&#8217;t have to worry: If you enter bogus information or simply let the timer run down, nothing happens. If you do enter the correct captcha, however, the component will send the captcha text to its distributed network of servers, which can use that information to bypass captcha controls and post links to the bogus videos.<\/p>\n<p>Another recent innovation is that each infected PC will run a service called Webserver, which appears in the Task Manager as webserver.exe; In the process of installing this service component, the worm opens TCP ports 53 (used for DNS) and 80 (for www pages) so they&#8217;re no longer blocked by the Windows Firewall. Presumably this permits the Koobface operators to more easily control (and send commands to) infected machines.<\/p>\n<p>The new variant is also using a new command-and-control server, at the domain <strong>u07012010u.com<\/strong>, so if you have the ability to block that domain at your gateway, you should.<br \/>\n<a title=\"wordpress blog stats\" href=\"http:\/\/www.statcounter.com\/wordpress.com\/\" target=\"_blank\"><img decoding=\"async\" src=\"http:\/\/c.statcounter.com\/4868061\/0\/92d716bc\/1\/\" alt=\"wordpress blog stats\" \/><\/a><\/p>\n<p><em>Tip of the hat to Threat Research Analyst Scott Manley for spotting this one.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>spongebob koobface <\/p>\n","protected":false},"author":65,"featured_media":17051,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[4985,7179,7189,4875,4357,7193,7181,7183,7187,6619,4459,4279,4247,3699,7185,4269,3471,5439,7191,4183],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2033"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=2033"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2033\/revisions"}],"predecessor-version":[{"id":17105,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2033\/revisions\/17105"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17051"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=2033"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=2033"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=2033"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=2033"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}