Categories

Facebook-photo dot org

Another breed of msn viruses is out in the wild.
This time it links to facebook-photo.org / image.php?=PIC…..JPG?

which is a Windows type .exe file when you download the link.
I sent the file to Virustotal for analysis, seems like a lot of virus scanners don’t recognize it just yet: Result: 7/42 (16.67%)

McAfee says “Artemis!AC20BF7EE912″,  F-Secure identifies it as “Trojan:W32/Agent.NRY”.

Whatever this nasty bugger does, DO NOT CLICK ON THE LINKS you get from your friends on MSN. And don’t be so stupid to actually install the .exe…

Since this file most certainly has no good intentions, the scan result SHOULD show lots more warnings… but it’s frightening that there aren’t more of them. But maybe some info will emerge in the next few days.

I know for sure Microsoft already blocks certain types of links or messages on their MSN network. I wonder if they have an infrastructure to block virus links like this? I assume it’s easy for them to blacklist a few keywords or text patterns and disable sending them via the MSN protocol. Yet, I’ve received numerous messages from my contacts during the course of the day containing this virus/trojan link.

It’s not even a holiday, what’s taking them (MSN and the virus scanner vendors) so long to fix this? Yes, I expect problems like this to be corrected in a few hours or even minutes, not 20 hours and counting! They are failing their duties.

Whois is Facebook-photo.org?
http://www.aawhois.com/facebook-photo.org

Name: Bernadette Evans
Handle: 31fcccecd0c354fe
Address: unit A/9 forrest Avenue
Bunbury
6230
AU
Phone: +61.897212040
Email: cuti@ilirida.net
Last Update: 2009-11-09
Created Date: 2009-09-09
Expiry Date: 2010-09-09
Host name: facebook-photo.org
IP address: 98.124.198.1
Location: Bellevue, WA, UNITED STATES

1 comment to Facebook-photo dot org

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>