|
|
LinkedIn is a popular social networking site where you can manage business contacts online. Since you can set up a profile with links to your own website, it seems to attract criminals’ attention as well. A Google search reveals that several hundred fake LinkedIn profiles from nude “Kirsten Dunst” to nude “Hulk Hogan” exist already. The rogue profiles look all alike, with a picture of the celebrity and three links to the parts of the “nude video” like shown in the following picture.

This is exactly the lure – don’t follow these links! The linked websites contain obfuscated script code which decodes to a simple browser redirection. This obfuscated script code is proactively detected by McAfee as “Exploit-IFrame.gen.c” already.

If you’d follow the link (don’t do that!) to see how deep the rabbit hole goes, you will end up with a Traffic Management System like described in this Avert Labs blog entry. On every reload the server-side application will point to a different domain.

So when an unsuspecting user gets tricked to follow the lure, he will end up on different malicious websites trying the classical social-engineering tricks of either the “missing video codec” or of showing a fake AV scan and telling that the user his computer was infected with malware and offering a “free” AV scanner software, which in fact is the real threat. So beware when following links, even on trusted Web 2.0 platforms like LinkedIn. Especially when they promise some nude celebrity videos.
|
|
The LinkedIn scams have another twist, I now have an invitation from a anna kouakou (a well known 419 psuedo) which I can not remove from my invitation list. It also does some strange things when you click on the name and will not allow you to either delete or mark as spam.
As a thumb rule, whenever there is an iframe injected with a url embedded should alarm that there’s something fishy.
The problem with this particular trojan is because by default most of the scanners do not detect it.
hello sir,i am from india and i am very big fan of your blog.i read it regularly.i am in 3rd year of computer sci. engineering and i also want to be a security researcher like you people.can you please tell me what cources i have to do and from where ?
http://www.webwasher.de/download/fileinsight/
The FileInsight tool can be found here:
http://www.webwasher.de/download/fileinsight/
And they’re using animated GIF’s for the animated images.
Hey, I love the way you guys are incorporating animation into your blogs. As a blogger myself, can I ask what software you use to do this?
Where can I get McAfeee FileInsight?
Submit your own comments / message for this post