"Facebook Password Reset Confirmation" VIRUS ALAERT!

This forum is for all other types of chatter, including non-SCUBA stuff.
Post Reply
User avatar
BASSMAN
I've Got Gills
Posts: 5808
Joined: Thu Jan 05, 2006 2:55 am

"Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by BASSMAN »

Bredolab Trojan Lets Cyber Criminals Control Personal Computers



A new computer virus is making the rounds online, using the Facebook brand to trick unsuspecting users into downloading potentially vicious malware.

The virus arrives as an attachment to an e-mail claiming to be from Facebook. The subject line reads "Facebook Password Reset Confirmation" and purports to be from "The Facebook Team," according to Belgium-based security research firm MX Lab.

The message itself reads: "Because of the measures taken to provide safety to our clients, your password has been changed. You can find your new password in attached document."

But the attachment actually contains a nasty virus called the Bredolab Trojan, which security analysts have been tracking for a while.

Once downloaded, the virus gives the sender complete control of the target computer, allowing cyber criminals to potentially spy on users of the computer or use it to steal personal information or distribute more spam.
Hi, my name is Keith, and I'm a Dive Addict! :supz:
Geek
Pelagic
Posts: 945
Joined: Tue Jun 30, 2009 5:27 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Geek »

Thanks for the tip.... I will be expecting more business shortly :)
If I'm killed by the questions like a cancer,
Then I'll be buried in the silence of the answer.


http://www.tacomacomputersolutions.com


Life isn't like a box of chocolate's, life is like a box of chocolate and horse bisket's and no matter which one you get you have to keep on chewing...
User avatar
scottsax
I've Got Gills
Posts: 2102
Joined: Thu Aug 10, 2006 12:14 am

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by scottsax »

Children, talk to your parents about phishing scams and trojan viruses. Prevention starts at home!
I'm going to look like a moose on rollerskates. -airsix
... my Mom caught me fenestrating once. -lavachickie
And I get so tired of fainting and peeing all over myself when the hammer falls on an empty chamber! -Nailer

Want to know where I'm performing? Check out my Facebook fan page!
User avatar
Tubesnout23
Submariner
Posts: 585
Joined: Tue Nov 25, 2008 11:24 am

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Tubesnout23 »

Thanks for the info!
User avatar
ArcticDiver
I've Got Gills
Posts: 1476
Joined: Thu May 03, 2007 7:15 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by ArcticDiver »

Wonder if this is related to this I get on FB? I replied a couple times and then just ignored it. Nothing seems to happen.

"Please update your email addressOur systems have detected that xxxxxxxxxx is no longer a valid email. Facebook requires all users to maintain an active contact email. Please enter and confirm a new contact email below:

New Email:
If you believe you have received this message in error, please reconfirm your current email."
The only box you have to think outside of is the one you build around yourself.
User avatar
Norris
NWDC Moderator
NWDC Moderator
Posts: 4710
Joined: Wed Sep 03, 2008 2:31 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Norris »

yes that is the usual delivery of a phishing site. it will then take you to a page that looks just like facebook but isnt. Usually checking the URL when you are wondering will help. If it doesnt start with http://www.facebook.com then it is most likely just trying to get your login info.
**Pinch it, don't stick your finger through. You're just pinching a bigger hole.
CAPTNJACK - 2012**
User avatar
ArcticDiver
I've Got Gills
Posts: 1476
Joined: Thu May 03, 2007 7:15 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by ArcticDiver »

Norris wrote:yes that is the usual delivery of a phishing site. it will then take you to a page that looks just like facebook but isnt. Usually checking the URL when you are wondering will help. If it doesnt start with http://www.facebook.com then it is most likely just trying to get your login info.

Gotta confess that paranoid as I am I was had by this. Fortunately I went through the password reset rigamarole after that and have ignored the message since then. So the phishing site has my email but not my password. So they don't really have anything than my email address. Since then none of my scanners have turned up any malware on this machine.
The only box you have to think outside of is the one you build around yourself.
User avatar
Norris
NWDC Moderator
NWDC Moderator
Posts: 4710
Joined: Wed Sep 03, 2008 2:31 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Norris »

Not a worry for a local virus, usually phishing sites grab login info so they can send stuff out as you such as posting ads for various things as your status and such. Good call on not giving a password.
**Pinch it, don't stick your finger through. You're just pinching a bigger hole.
CAPTNJACK - 2012**
User avatar
ArcticDiver
I've Got Gills
Posts: 1476
Joined: Thu May 03, 2007 7:15 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by ArcticDiver »

Norris wrote:Not a worry for a local virus, usually phishing sites grab login info so they can send stuff out as you such as posting ads for various things as your status and such. Good call on not giving a password.

Doesn't everyone use different passwords for different sites? Or, at least different category of sites? If the phisher had my Facebook password all they could do was use it for that site.

Posing as me, eh? As long as they don't put child porn on my machine like happened to that poor schmuck who was in the news not sure they'd benefit much.

But, I have to confess I did my Facebook thing and now seldom go there. Well, seldom by my standards which are far from cosmic in time frame.
The only box you have to think outside of is the one you build around yourself.
User avatar
Norris
NWDC Moderator
NWDC Moderator
Posts: 4710
Joined: Wed Sep 03, 2008 2:31 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Norris »

I use the same password for social sites and a much more encrypted one for Charles Schwab, Bank, email and that sort of thing. I would suggest to anyone that they do the same. I mean if someone got your facebook login, and they were the shady people they are, why not go and try it at some bank sites, and paypal??
**Pinch it, don't stick your finger through. You're just pinching a bigger hole.
CAPTNJACK - 2012**
User avatar
BASSMAN
I've Got Gills
Posts: 5808
Joined: Thu Jan 05, 2006 2:55 am

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by BASSMAN »

from what I read about it it is not just trying to get your password but it is a way for you to invite this "Trjan Virus" into your computer. If you don't click the link you will not get it.
I have already been asked to go to links like this on different terms.
Hi, my name is Keith, and I'm a Dive Addict! :supz:
User avatar
Norris
NWDC Moderator
NWDC Moderator
Posts: 4710
Joined: Wed Sep 03, 2008 2:31 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Norris »

Ahh yeah I just read that too. So there was an email with an attachment sent to users? I do not EVER open attachements from anywhere unless they are from friends. If you ever get a wierd "out of ordinary" email like this, I would suggest pasting the subject line into Google/Bing, and hit go. You are generally not the first to get it, and someone has already, most likely, cracked the case.
**Pinch it, don't stick your finger through. You're just pinching a bigger hole.
CAPTNJACK - 2012**
User avatar
ArcticDiver
I've Got Gills
Posts: 1476
Joined: Thu May 03, 2007 7:15 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by ArcticDiver »

I don't know about otherISPs; but both of our major ones here in AK have some pretty obnoxious filters. They can be set up by the user. But, even then, unless the user puts a domain or address on the White List just about every known malware is filtered out before it gets to the user. In fact sometimes they filter even desired stuff.

Back to phishing for a minute. I understand wanting a user's passphrase and then trying it on other sites. But, even on this site what can someone do with a UserID and Passphrase other than post posing as the user?
The only box you have to think outside of is the one you build around yourself.
User avatar
Norris
NWDC Moderator
NWDC Moderator
Posts: 4710
Joined: Wed Sep 03, 2008 2:31 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Norris »

Well I know generally on like FB and such spammers like to get them so they can spam ads and sites to all your homies. I think most of it is automated too so that once you put the info into the site the spamming begins. The cool thing is that generally your password doesnt get changed so once your friends get them and you see it happening, you can go change your password and it stops.

It makes you wonder though, what percentage of logins collected can get you into a paypal or bank site too?
**Pinch it, don't stick your finger through. You're just pinching a bigger hole.
CAPTNJACK - 2012**
User avatar
ArcticDiver
I've Got Gills
Posts: 1476
Joined: Thu May 03, 2007 7:15 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by ArcticDiver »

Thanks. It seems that the only people who can get more than just annoyed are those who don't use different passphrases for at least different categories of sites.
The only box you have to think outside of is the one you build around yourself.
spatz84
Aquaphile
Posts: 109
Joined: Mon Jan 04, 2010 1:09 pm

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by spatz84 »

we just got this thing today only it use the phrase that our Facebook account was going to be deactivated do to suspicious behavior and that if we wanted more information on the problem open the attachment to look into it further. I did but nothing happend I notice that the URL line read HotHotgirls or something to that effect and I quickly shut it down. A moment later the Norton pop up displayed and said that an attempt against our system had been blocked. I hope that it actualy worked and who ever the LOW LIFE,SCUM BALL,DIRT BAG, BOTTEM FEEDER, ASS NUGGETS :boxer: on the other end of these types of things were foiled for the day!
Last edited by spatz84 on Fri Jun 18, 2010 10:52 am, edited 1 time in total.
User avatar
Old Nubbins
Aquaphile
Posts: 115
Joined: Sun Jan 31, 2010 4:38 am

Re: "Facebook Password Reset Confirmation" VIRUS ALAERT!

Post by Old Nubbins »

Better unplug that thing
Post Reply