Thursday, April 30, 2009

Facebook Phishing (again)

Today, if you're a user of Facebook, you may have received a message in your inbox from an apparent user with the subject "Look at this!". The message simply contains the domain name fbstarter[dot]com. If you have automatic notifications set up in your facebook account which most people do due to default settings, you also received this email in the form of a notification in your email inbox, and that's exactly how we are seeing them here at AppRiver. We're not seeing a ton of them, but enough to be a nuissance, around 2 per minute currently, though this is likely a bit more exaggerated in users' Facebook inboxes than in email boxes because of these notification settings. The domain fbstarter[dot]com was just registered today to a man called Boris Soroka. The registrar, ALANTRON BLTD., is located in Latvia, but the contact information for the domain is pointing to Moscow. Currently the domain doesn't have any content, though I concur with other experts that sometime soon, likely by the end of the day, this domain will begin to host Facebook phishing sites. Make sure you're paying close attention, and never click on links in emails from people you don't recognize. You should avoid opening them at all if possible.
Facebook has been a very popular taget as of late for all sorts of malware, and spam campaigns due to its fairly recent rise to the top of the social networks. It's use of Web 2.0 3rd party applications and advertisements along with its growing popularity make it a fertile target for malfeasance. Be careful, and be aware.

0 comments: