Latest Comments
"i want to have direct deposit"
by maria | Jul 5, 2009 7:54 AM
 
"lol"
by Tina | Jul 5, 2009 12:04 AM
 
"Good! Its very good blog the for the people who are having debit collection and credit report ..."
by identity theft lawyers | Jul 4, 2009 6:55 PM
 
"Thank you "
by Dr. Holub | Jul 4, 2009 11:17 AM
 
"Agree that wireless hotspots are an easy way for hackers to gather information from connected ..."
by Patrick Hooper | Jul 3, 2009 4:06 AM

Bogus Facebook emails pass trojans

  • Email a Friend
  • Print Page
Bogus Facebook emails pass trojans
By Angela Moscaritolo
Sep 24, 2008 9:56 AM
Tags: Bogus | Facebook | emails | pass | trojans
A new round of malicious emails tries to trick recipients into believing someone wants to be their Facebook friend.
A new round of malicious emails tries to trick recipients into believing someone wants to be their Facebook friend.

A trojan-laden phish disguised as a message from the popular social networking website Facebook is making the rounds.

In an alert Monday, web security company Websense said that the email appeared to be sent by the domain facebookmail.com with a subject line that reads "An old friend added you as a friend of facebook." The email contains an attachment called "picture.zip" that is actually a trojan.

The body of the email contained a view of Facebook's login page with a notification that says an old classmate has requested to be your friend and, "To see her picture please check your attachment."

Facebookmail.com is an official domain that Facebook commonly uses to notify its users of friend requests and events, the Websense alert said. It is unclear how the attackers spoofed the address.

Users might not think twice about clicking the attachment, said Ken Dunham, director of global response for iSight Partners, a global risk mitigation company.

"Big brand names like Facebook, MySpace, YouTube - those are trusted names that people are less likely to be concerned about," he told SCMagazineUS.com on Tuesday.

The email body contains Facebook's login screen and will take users there, lending to the legitimacy of the message. This technique is commonly used by phishers as a way to gain trust so victims do not think they are being duped, Dunham said.

A Facebook spokesperson did not respond to a request for comment.

Dunham suggested corporate IT departments inform and train employees to be suspicious of unsolicited email.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Exclusive Data Centre - Sponsored Content by Microsoft
 
Vulnerabilities & Exploits Whitepapers