Warning: "Faceebook" Email is Viral

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
b0b
Posts: 29079
Joined: 4 Aug 1998 11:00 pm
Location: Cloverdale, CA, USA

Warning: "Faceebook" Email is Viral

Post by b0b »

I received several of these emails this morning with the subject "Your Faceebook profile has been published". (Notice the misspelling.) They are obviously a virus - the link they invite you to click is an executable program. If you get this email, don't click the link!

Code: Select all

From: security@federalreserve.gov
Subject: Your Faceebook profile has been published 
Date: 06/24/2011 07:41 AM 
To: quasar@b0b.com

Your personal Facebook and Banking information has been publeshed.

Please click here to view further information
This service is provided to you by the Federal Reserve Board. Visit us on the web at http://www.federalreserve.gov.  
I wouldn't normally post about a virus here, but this appears to be a new blitz attack to multiple email lists. This is malicious junk email. Delete it immediately if you receive it.
-𝕓𝕆𝕓- (admin) - Robert P. Lee - Recordings - Breathe - D6th - Video
User avatar
b0b
Posts: 29079
Joined: 4 Aug 1998 11:00 pm
Location: Cloverdale, CA, USA

Post by b0b »

Received 2 more copies of this. The subject line, text and misspellings are being randomized slightly to get past spam filters. I don't know what the .exe file would do if clicked, but it certainly isn't anything good. :x

Sometimes the return address is alert[at]facebook.com, and the link appears to be facebook.com (it's not).
-𝕓𝕆𝕓- (admin) - Robert P. Lee - Recordings - Breathe - D6th - Video
User avatar
Jim Smith
Posts: 7949
Joined: 4 Aug 1998 11:00 pm
Location: Midlothian, TX, USA

Post by Jim Smith »

I'm on Facebook and have never received any emails like that, not even in my Gmail Spam folder. Just what do you been doing on there anyway? ;)
User avatar
b0b
Posts: 29079
Joined: 4 Aug 1998 11:00 pm
Location: Cloverdale, CA, USA

Post by b0b »

This has nothing to do with Facebook. It's email spam. Seems to have stopped. I received about ten of them yesterday.
-𝕓𝕆𝕓- (admin) - Robert P. Lee - Recordings - Breathe - D6th - Video
User avatar
Brendan Mitchell
Posts: 1558
Joined: 26 Nov 2000 1:01 am
Location: Melbourne Australia

Post by Brendan Mitchell »

While you are there B0b ,
how do I delete an email before opening it ?
I see many suss looking emails coming in but if I don't open them they just sit there cluttering up . If I want to delete them I must click on them to open and then delete .
User avatar
b0b
Posts: 29079
Joined: 4 Aug 1998 11:00 pm
Location: Cloverdale, CA, USA

Post by b0b »

I don't know what email program you use, Brendan, but with most of them you can right-click on an email in your inbox and select Delete. Also, in some programs you can drag unopened emails to the Trash with your mouse pointer.

Opening the email is not harmful. Clicking on a link in the email is where the danger lies.
-𝕓𝕆𝕓- (admin) - Robert P. Lee - Recordings - Breathe - D6th - Video
User avatar
Fred Thompson
Posts: 799
Joined: 30 May 2006 12:01 am
Location: Zephyrhills, FL

Post by Fred Thompson »

Thanks B0b. I picked up a virus from a facebook 'friend' :aside: about a month ago. I closed my account, had my pc 'sterilized', up-graded my anti-virus, and re-opened my account :roll: :\ . Now, I'm very careful of what I open or answer.
The difference between a musician and a savings bond is eventually the bond will mature and earn money.
User avatar
Mark van Allen
Posts: 6425
Joined: 26 Sep 1999 12:01 am
Location: Watkinsville, Ga. USA

Post by Mark van Allen »

Thanks for warning everybody, b0b. I haven't seen that particular one, but lately there have been a whole lot that purport to be from actual friends in your profile leaving a personal message that use their account photo and often say they've left you a personal message that shows as ". This may be the type Fred got. These appear to originate from inside facebook itself as hacks of individual accounts, and also carry executable files.

Tough times. Be careful everybody.
User avatar
b0b
Posts: 29079
Joined: 4 Aug 1998 11:00 pm
Location: Cloverdale, CA, USA

Post by b0b »

Yeah, like I said, I don't think this is connected to Facebook at all. They just put "Faceebook" in the title to get your attention. I think it's probably a trojan virus that's building a botnet for some future scam.
-𝕓𝕆𝕓- (admin) - Robert P. Lee - Recordings - Breathe - D6th - Video
User avatar
Jim Smith
Posts: 7949
Joined: 4 Aug 1998 11:00 pm
Location: Midlothian, TX, USA

Post by Jim Smith »

This might be a good time to remind everyone to PLEASE use "Bcc:" instead of "To:" when sending jokes or whatever to your friends.

Just this week I received emails from a couple friends with close to 100 email addresses exposed between the two of them. Those spam bots love to harvest that stuff, so they have legitimate email addresses to send this crap to.
User avatar
Wiz Feinberg
Posts: 6113
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA

Post by Wiz Feinberg »

This Federal Reserve themed spam campaign is part of one running since at least the middle of the month of June, 2011. It is being used to distribute the Zeus banking Trojan.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Brendan Mitchell
Posts: 1558
Joined: 26 Nov 2000 1:01 am
Location: Melbourne Australia

Post by Brendan Mitchell »

Thanks B0b
You would think I would have known about the right click by now !!