CornDog Computers

Tag: PandaLabs blog

Koobface: The Saga Continues

posted by Travis Eichelberger on Aug.13, 2009, under Tech News

koobface_wormThe gang behind the Koobface worm has been hard at work in releasing their next iteration of their worm. We’ve already identified over 60 active domains spreading the content through the usual method of posting a message linking to a “CooooL Video” on Facebook.

After clicking the link, the victims are automatically redirected to a Koobface controlled server, which then routes the them off to a fake codec site specifically designed for the social network they came from.

Fake codec site:

The Koobface gang uses the same old “Flash Player upgrade required” tactic to trick users into opening the executable, which then ultimately transforms their machine into a distribution point for the infection to further propagate.

On infection, the Koobface worm immediately attempts to download three additional exectuable files.

After turning the victims computer into its next distribution point, it also attempts to monetize by installing “Total Security” Rogueware.

 

via PandaLabs blog

View Comments :, , , , , , more...

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!