A currently circulating across Facebook, multi-layered monetization tactics utilizing, Turkish users targeting, malicious campaign, is attempting to trick users into thinking that they need to install a fake Adobe Flash Player, displayed on a fake YouTube Video page, ultimately serving P2P-Worm.Win32.Palevo on the hosts of the socially engineered (international) users.
Let's dissect the campaign, expose its infrastructure in terms of shortened URLs, redirectors, affiliate network IDs, landing pages, pseudo-random Facebook content generation phone back URLs, legitimate infrastructure hosted content, and provide MD5s for the served malicious content.
Sample redirection chain: hxxp://m3mi.com/10469 ->
Dancho Danchev's Blog - Mind Streams of Information Security Knowledge: Facebook Spreading, Amazon AWS/Cloudflare/Google Docs Hosted Campaign, Serves P2P-Worm.Win32.Palevo
Threat actors don't rest. Neither do we. Edison NewWorld is a cybersecurity research blog covering threat hunting, malware analysis, incident response, and cyber threat intelligence — built for defenders who think like attackers. Real samples. Raw analysis. No vendor spin.
Subscribe to:
Post Comments (Atom)
ShieldBreak: When Microsoft Patches a Zero-Day and the Researcher Patches the Patch
ShieldBreak: When Microsoft Patches a Zero-Day and the Researcher Patches the Patch Category: Vulnerability Research | Windows Security |...
-
api.ipify.org - The Simplest Way to Get Your Public IP Address api.ipify.org – The Simplest Public IP Address API Whether you...
-
About Nitol: Nitol is a family of Trojan that performs DDoS (distributed denial of service) attacks, allow backdoor access and control, ...
No comments:
Post a Comment