{"id":243,"date":"2008-08-07T10:03:46","date_gmt":"2008-08-07T10:03:46","guid":{"rendered":"http:\/\/kera.name\/articles\/2008\/08\/facebook-attacked-by-phishermen\/"},"modified":"2008-09-03T18:41:40","modified_gmt":"2008-09-03T18:41:40","slug":"facebook-attacked-by-phishermen","status":"publish","type":"post","link":"https:\/\/kera.name\/articles\/2008\/08\/facebook-attacked-by-phishermen\/","title":{"rendered":"Facebook Attacked By Phishermen"},"content":{"rendered":"<p>It looks like there&#039;s a new malicious Facebook virus in the wild, and it just popped up today. Users are logging in this morning to find wallposts left by their friends along with a link:<\/p>\n<p><img decoding=\"async\" id=\"image244\" src=\"https:\/\/kera.name\/articles\/wp-content\/uploads\/2008\/08\/facebookvirus1.jpg\" alt=\"Facebook virus\" \/><\/p>\n<blockquote><p>hi Tomalak, hehe.. you could be tht naughty i didnt knw..really hard to see tht from my eyes lol<\/p>\n<p>have a luk urself&#8230;<br \/>\nhttp:\/\/www.google.com.id.ezwjc3q9.k4sw5d.2b99df1a.cn\/galle<strong>[&#8230;]<\/strong>za8lnik<br \/>\n(click open or run when prompted)\n<\/p><\/blockquote>\n<p>It&#039;s yet to be seen whether &#034;virus&#034; is really the right term for this, but regardless there is some malware out there somewhere taking advantage of the fact that a lot of Facebook users will blindly click on the suspicious-looking link hoping to find out where they&#039;ve been &#034;naughty&#034;. All they really find, though, is a download box for <strong>Picture_dl.exe<\/strong>. I didn&#039;t go as far as to actually download it, but presumably someone will hack it to pieces soon enough to discover its purpose.<\/p>\n<p>In the meantime, I don&#039;t really want to report my friend to Facebook because she&#039;s clearly not sent this intentionally. It&#039;s called &#034;koobface&#034; and it&#039;s already <a title=\"facebook worm\" href=\"http:\/\/www.merit.edu\/mail.archives\/nanog\/msg10247.html\">known to the authorities<\/a>. Apparently TPTB are working on it.<\/p>\n<p>Meanwhile, <em>do not click on every random link you see on the internet!<\/em> The link above may look like a Google link to the untrained eye, but the reams of meaningless-looking text after &#034;www.google.com&#034; give away that this is, in fact, a phishing site. Actually, I&#039;m kind of surprised that my FF3 installation didn&#039;t catch that&#8230;<\/p>\n<p><strong>Update:<\/strong> Arik&#039;s <a title=\"Beware Of A Virus Spread Via Facebook &raquo; Obvious Ideas\" href=\"http:\/\/www.arikfr.com\/blog\/facebook-virus.html\">written<\/a> about this too.<\/p>\n<p><strong>Update 2:<\/strong> It looks like this might be the first Facebook-based virus\/worm since the <a title=\"Warning: Facebook 'Virus' | Dao By Design Blog\" href=\"http:\/\/www.daobydesign.com\/blog\/2008\/06\/warning-facebook-virus\/\">facebook.com phish<\/a> back in June.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It looks like there&#039;s a new malicious Facebook virus in the wild, and it just popped up today. Users are logging in this morning to find wallposts left by their friends along with a link.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[26,9],"_links":{"self":[{"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/posts\/243"}],"collection":[{"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/comments?post=243"}],"version-history":[{"count":1,"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/posts\/243\/revisions"}],"predecessor-version":[{"id":308,"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/posts\/243\/revisions\/308"}],"wp:attachment":[{"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/media?parent=243"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/categories?post=243"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kera.name\/articles\/wp-json\/wp\/v2\/tags?post=243"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}