Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

facebook trojan

An Independent researcher named Mohammad Reza Faghani has disclosed a new Malware in the wild affecting Facebookers. A new trojan is being spread all through the Facebook which has approximately infected more than 110k Facebook users just within two days.

Medium of Facebook Trojan

The behavior of the trojan is said to be as follows:

  • tags infected user's friends in an enticing post
  • when the tagged person open the post, then an adult video preview is shown and abruptly stops
  • then, it asks for downloading a flash player (fake) to continue viewing the video
  • the fake player is the actual malware which is downloaded on the user's system

Technique used in Facebook Trojan

Mohammad Rez Faghani said he has been monitoring this malware from last two days, and since then, he calculated that, an approximate of 110,000 users had been affected and still counting. Faghani added,

This malware keeps its profile low by only tagging less than 20 user in reach round of post.

How is this new Trojan Different ?

Previous Trojans used to send messages to the victim's friends, affecting only a number of users which was limited, and then repeating the same process. But this new trojan uses a technique named as "Magnet" by Fagahni, in which the users are tagged in a post and since the post is visible to all the friends of that tagged user thus a broader range of potential users can be lured and infected. This is how this new trojan is different from the previous trojans being already spread on Facebook.

Technical Details

The MD5 of the executable file (fake flash player):cdcc132fad2e819e7ab94e5e564e8968 The SHA1 of the executable file (fake flash player): b836facdde6c866db5ad3f582c86a7f99db09784 The fake flash file drops the following executables as it runs:chromium.exe, wget.exe, arsiv.exe, verclsid.exe.

The malware is able to hijack keyboard and mouse movement (at initial investigation)

Existence of the chromium.exe in the Windows processes, is an Indication of Compromise (IoC). The malware tries to connect to the following network upon execution:

www.filmver.com and www.pornokan.com

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.