Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Facebook Password Reset Confirmation. Customer Support. (Malware) - Internet Security | DShield SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Facebook Password Reset Confirmation. Customer Support. (Malware)

I received an email today purporting to be from Facebook, which of course had an attachment. The file was Facebook_Password_833fd.zip, which unzipped to be Facebook_Password_833fd.exe. The zip file is in fact a zip file, and the exe is in fact MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit (according to the file command). The subject line is "Facebook Password Reset Confirmation. Customer Support. " The body of the email is pretty straight forward:

"Hey email,

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Thanks,
Your Facebook."

Which is an attempt to get you to first open the attachment, unzip the file, and then run the executable content. The executable has the following attributes:

File size: 27648 bytes
MD5   : 11dee2f7ecc31a9a6f5fcab4e9654073
SHA1  : 30cfe72393ca5c58e7bba452c401932c6dcc9a9f

First set of Virustotal results were 20/41 today at 01:30:12 (UTC) https://www.virustotal.com/analisis/af6abaa7d0a29cdd4cf2680771d6d87e22d190a6a293572910ab89bd0653b322-1260408612 when I ran it again at 17:49:06 (UTC) they were up to 26/41 detection. It is a dropper which subsequently downloads and executes other badness.

Facebook does not send out passwords in attached files. If you have forgotten your password on Facebook reset it here: http://www.facebook.com/reset.php if you cannot login to your account (someone else has taken it over) go to this page: http://www.facebook.com/help.php?topic=login, which also has this advisory on it:

"Fake password reset emails

Some users have received fake password reset emails with attachments that contain viruses. Do not click on these emails or download the attachment. Also, please note that Facebook will never send you a new password as an attachment. To learn more visit our Security page: facebook.com/security
"

Cheers,
Adrien de Beaupré
Intru-shun.ca Inc.

Adrien de Beaupre

353 Posts
ISC Handler
Yep, I got the same, but Gmail nabbed it as Spam.

I'm betting this has everything to do with the Privacy Updates just pushed out by Facebook.

So...if 1 in 200 phishing attempts is successful. Which is why phishing attempts continue to exist.

I wonder what the success rate is for Password Reset mails with virus attachments?

--
Jeff
HackDefendr

65 Posts
famous website = more malicous eyes on that website.
good note, thanks, and if you could upload it, it would be fine .
Arash

1 Posts

Sign Up for Free or Log In to start participating in the conversation!