Backdoor Distributed as Facebook Messenger Application

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
New rogue emails posing as official Facebook communications lead users to a website distributing a backdoor as an application called Facebook Messenger.

The emails bear a subject of "[user] listed you as his uncle" and make use of the real template corresponding to real Facebook notifications.

The body message informs recipients of several pending actions, including a friendship request and includes a www.facebook.com link that actually points to a third-party website.

The rogue page advertises a program called Facebook Messenger, which according to its description, is supposed to be an "app for quick access to messages from your Facebook account."

The screenshots presented on the page are taken from an Android phone, but the file served for download is an executable called FacebookMessengerSetup.exe, not an .apk Android package.

facebookmessenger2.jpg


According to researchers from Trend Micro, the file is an installer for BKDR_QUEJOB.EVL, a backdoor that opens a connection on TCP Port 1098 and listens for commands.

The backdoor allows attackers to update the malicious file, download and run other malware applications, and launch certain processes. Information about the infected system, such as installed antivirus products and OS version, is gathered and sent to an SMTP server.

More details - link
 

MrXidus

Super Moderator (Leave of absence)
Apr 17, 2011
2,503
I imagine many feel victim to this hopefully if they got an AV working and up to date it prevented it.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
It will look convince that your are in a legit site of Facebook with a Messenger to be download.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top