Pick Your Poison: KOOBFACE or FAKEAV?

September 18, 2009 by admin  
Filed under Security News


86 views   Leave a Comment

The Koobface botnet is widely known to install FAKEAV or rogue antivirus malware onto a victim’s PC. It has a dedicated component which actually installs the FAKEAV onto the user’s system. However, the Koobface gang has added a new twist to its fake Facebook page.

 

When the user closes the window/tab with the fake Facebook page, a popup window appears. Whatever button the user clicks, this new Koobface variant is downloaded onto the affected system. Here’s a video that illustrates this behavior:

 

This is the script used by cybercriminals to perform this new routine; it only works for users who used Internet Explorer to visit the fake page:

 

koobface script2 Pick Your Poison: KOOBFACE or FAKEAV?
Figure 1. Koobface Script

 

The scripts above leaves the user with very little choice – closing the browser window downloads a FakeAV variant (detected as TROJ_FAKEAV.FGR), while clicking anywhere on the web page will download a Koobface loader (detected as WORM_KOOBFACE.AZ).



Related posts:

  1. Koobface Tweets
  2. The Real Face of KOOBFACE
  3. 8 Things You Probably Didn’t Know About KOOBFACE
  4. Removal tool for Suspect-1B!E4800A5BF6F6, Mal/FakeAV-BW (ave.exe) Malware
  5. Removal of W32/Koobface.GJ Worm (Manual)

Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!