{"id":2809,"date":"2010-06-14T14:43:16","date_gmt":"2010-06-14T21:43:16","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=2809"},"modified":"2018-01-30T12:21:19","modified_gmt":"2018-01-30T19:21:19","slug":"facebook-photo-album-spam-drops-trojans","status":"publish","type":"post","link":"https://www.webroot.com/blog/2010\/06\/14\/facebook-photo-album-spam-drops-trojans\/","title":{"rendered":"Facebook &#8220;Photo Album&#8221; Spam Drops Trojans"},"content":{"rendered":"<p class=\"getsocial\" style=\"text-align: left;\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2003.png\" \/><a title=\"Add to Facebook\" href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/blog.webroot.com\/2010\/06\/14\/facebook-photo-album-spam-drops-trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Facebook\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2013.png\" \/><\/a><a title=\"Add to Digg\" href=\"http:\/\/digg.com\/submit?phase=2&amp;url=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans&amp;title=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Digg\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2023.png\" \/><\/a><a title=\"Add to Del.icio.us\" href=\"http:\/\/del.icio.us\/post?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans&amp;title=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Del.icio.us\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2033.png\" \/><\/a><a title=\"Add to Stumbleupon\" href=\"http:\/\/www.stumbleupon.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans&amp;title=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Stumbleupon\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2043.png\" \/><\/a><a title=\"Add to Reddit\" href=\"http:\/\/reddit.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans&amp;title=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Reddit\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2053.png\" \/><\/a><a title=\"Add to Blinklist\" href=\"http:\/\/www.blinklist.com\/index.php?Action=Blink\/addblink.php&amp;Description=&amp;Url=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans&amp;Title=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Blinklist\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2063.png\" \/><\/a><a title=\"Add to Twitter\" href=\"http:\/\/twitter.com\/home\/?status=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans+%40+http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Twitter\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2073.png\" \/><\/a><a title=\"Add to Technorati\" href=\"http:\/\/www.technorati.com\/faves?add=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Technorati\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2083.png\" \/><\/a><a title=\"Add to Furl\" href=\"http:\/\/www.furl.net\/storeIt.jsp?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans&amp;t=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Furl\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2093.png\" \/><\/a><a title=\"Add to Newsvine\" href=\"http:\/\/www.newsvine.com\/_wine\/save?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F06%2F14%2Ffacebook-photo-album-spam-drops-trojans&amp;h=Facebook%20%22Photo%20Album%22%20Spam%20Drops%20Trojans\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Newsvine\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2103.png\" \/><\/a><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2113.png\" \/><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/06\/20100614-bamital_facebook-spam-message.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-2813\" title=\"20100614-bamital_facebook spam message_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/06\/20100614-bamital_facebook-spam-message_crop.jpg\" width=\"508\" height=\"124\" \/><\/a>A spammed link campaign that spread through Facebook rapidly over the weekend delivered a malicious payload designed to take control of the Facebook account of any infected user, steal passwords, and hijack clicks in the victim&#8217;s browser. The messages appear as links sent by a friend, accompanied by the brain-damaged text &#8220;<strong>You? I find it on Google.<\/strong>&#8221;<\/p>\n<p>Clicking the link directs recipients to a page on <strong>online-photo-albums.org<\/strong> which, at the time, pointed to malware hosted on a server (now offline) based in Bosnia and Herzegovina.<\/p>\n<p>This installer drops no fewer than six payloads, including the &#8220;clickjacker&#8221; <strong>Trojan-Bamital<\/strong>, which redirects the browser to a different site when a user on an infected machine clicks a linked result in a very specific subset of search engine Web sites (such as, for example, results on the South Korean version of Google, Google.kr, but not the main Google.com site itself).<\/p>\n<p>In addition, album.exe file also drops <strong>Trojan-Downloader-Suurch<\/strong>, which can download and install additional payloads, and leads hapless Web surfers into the abyss by hijacking searches on a broader set of search engines, and injecting its own code into the search results page. The album.exe installer also drops a DLL which captures passwords and other data entered into Web forms in Internet Explorer, and forwards that data on to a different Web domain (which happens to be hosted at the same IP address in Bosnia that was used for the album.exe download &#8212; and remains online as I publish this).<\/p>\n<p><!--more--><\/p>\n<p>The link points to a URL in the form of <strong>online-photo-albums.org\/<em>Firstname_Lastname<\/em><\/strong> (with the first and last name of the recipient plugged into the link). That page features a number of photos of what appear to be the variety of bored models with stupefied, drug-addled expressions on their faces that are always packaged in new picture frames.\u00a0 A link in the center of the page, customized with the victim&#8217;s name, leads to a malware installer named <strong>Album.exe<\/strong>.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/06\/20100614-fb_onlinephoto_dropper2.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-2819\" title=\"20100614-fb_onlinephoto_dropper_crop2\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/06\/20100614-fb_onlinephoto_dropper_crop2.jpg\" width=\"350\" height=\"275\" \/><\/a><\/p>\n<p>In addition, the component which captures data in Internet Explorer also hijacks any Facebook account previously accessed on the infected system to spread itself, very much in the style of <strong>Koobface<\/strong>, but without any of the other characteristics of a Koobface infection. I suppose it makes sense that the domain used in this attack is named <strong>spmfb3309.com<\/strong> (as in <em>spam facebook<\/em>, get it?), and the IP address was also used to host the previously-seen <strong>spmfb2299.com<\/strong>, which shares a similar reputation for shenanigans the newer domain appears to exhibit.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/06\/20100614-bamital_fbstrings2.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-2817\" title=\"20100614-bamital_fbstrings2_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/06\/20100614-bamital_fbstrings2_crop.jpg\" width=\"381\" height=\"154\" \/><\/a><\/p>\n<p>Once again, this highlights the need for anyone who uses a social network to be extremely careful about clicking random links, especially when those links appear to come from someone you know. Just because a URL gets posted on Facebook doesn&#8217;t confer to it some sort of magical protective ability.<\/p>\n<p>Most of the payloads remain undetected by competitor AV engines at the time we did the research. The album.exe installer and all of its dropped payloads will be detected in the next release of our definitions.<br \/>\n<a title=\"wordpress blog stats\" href=\"http:\/\/www.statcounter.com\/wordpress.com\/\" target=\"_blank\"><img decoding=\"async\" alt=\"wordpress blog stats\" src=\"http:\/\/c.statcounter.com\/4868061\/0\/92d716bc\/1\/\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A spammed link campaign that spread through Facebook rapidly over the weekend delivered a malicious payload designed to take control of the Facebook account of any infected user, steal passwords, and hijack clicks in the victim&#8217;s browser. The messages appear as links sent by a friend, accompanied by the brain-damaged text &#8220;You? I find it [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17051,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[3673,7647,7645,3769,4499,7649,4497,7643,3487,4293,5641,4531,4797,4459,3919,6625,3743,7651,3471,4313],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2809"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=2809"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2809\/revisions"}],"predecessor-version":[{"id":19121,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/2809\/revisions\/19121"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17051"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=2809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=2809"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=2809"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=2809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}