trojan blue

Updated - Now: Trojan Releases through Facebook Messages

A message from a friend told us about a new threat (Trojan) is on Facebook. Using the social messaging service, scammers try to make trjjans to unsuspecting users.

Our friend from safer-internet.gr, sent us two different ones from Facebook messages. The messages say something like "see this and don't tell anyone" and contain two .rar files with different names:

foto2We asked for the files to analyze them and of course did not contain anything to look at. Although both rar had a different name executable they contained was exactly the same (same CRC Checksum.)

trojan

and his name: Watch This !!! vbs

Executable files were a form .vbs. vbscript is one scripting (script as they translate it) and comes with Windows. With it you can do various useful things, as you have seen from it category Tweaks iGuRu.gr, but you can also write trøjans.

The script that contained 2 rar had the TrojanDownloader.Agent.NJV trjan that has indexed from ESET on 11 February of 2012.

What Makes a Trojan Downloader?

A Trojan downloader with the running on the victim's computer seeks access to a remote computer to download files that he then installs on the infected computer.

This particular Trojan, TrojanDownloader.Agent.NJV trojan, is old and so it's immediately recognizable by antivirus, of course, if you've updated it.

Needless to tell you that you do not open zip files, rar you do not expect them and come to you, even if you know who sent it to you.

If you have already run the file and the antivirus has not "hit" it change or update your security application.

Update:

While malicious messages are still coming to Facebook. we decided to open the script for further analysis.

All malicious links seem to be leading to the same server that has apparently been tampered with.

See 3 from the domains

hack

2 hack

1 hack

Η of iGuRu.gr informed the owner of the server to take the necessary measures.

All malicious addresses are included in the photo below as they appear in the script

hack scriptWe believe that the malicious user is Greek as there are malicious files with Greek names, such as. /vasika/kalisperasas.zip. Also the folder that it does to download the malicious files is named by the malicious user "\ MyFolderakis."

After installation, make the above folder on the victim's computer, download the content.zip that contains one. jar file.

download (csPATH)
Unzip csPATH & ”\content.zip“, CsPATH
Loop While ReportFileStatus (csPATH & ”\sapsalo.jar

Once it downloads the content.zip and runs the jar (while the vbs script only runs on Windows, the jar runs on Windows. Mac and Linux) it starts downloading all the other malicious files, from the links we provided above.

Beware, as we did not download the above files and we do not know what they are.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

19 Comments

Leave a Reply

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).