Author Topic: Messages from facebook redirected to a possible infected site  (Read 6144 times)

0 Members and 1 Guest are viewing this topic.

24ores

  • Guest
Messages from facebook redirected to a possible infected site
« on: February 18, 2013, 12:34:09 PM »
The last hours i see a few messages on facebook profile saying that im tagged to a friend photo with a link under h....://195.244.61.38
a turkish site with a download link in it.I assume it is another virus,please inform me about it.
« Last Edit: February 18, 2013, 12:36:04 PM by 24ores »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Messages from facebook redirected to a possible infected site
« Reply #1 on: February 18, 2013, 02:41:56 PM »
The redirecting domain was just recently registered: http://2013.netorginfo.com/20130131/bon.htm
Going to the site it has in Turkish
Quote
Firefox Extension Update
Please Refresh button, Firefox Add-Update your

Due to system errors and security vulnerabilities that are required by pressing the Reload button

Install Firefox Plug-in Update.

As long as you have not updated the site faydalanamayacaksınız features. 
Do you recognize having Google Enhancer firefox extension? Is it checked by firefox as a reliable extension?
The update site domain is 20 days old: http://www.statscrop.com/www/bond2-reawer.com
Nothing here: http://urlquery.net/report.php?id=1033633
But detected as a possible spammer: http://www.urlvoid.com/scan/bond2-reawer.com/ also -> (http://sitecheck.sucuri.net/results/www.bond2-reawer.com)
Probably your Google Enhancer became incompatible with firefox. The unnecessary part of the request is created by an outdated add-on for Firefox, meaning: requested URL /&sa=U&ei=KykiUebZCc7bqQG6mYHoCQ&ved=0CB8QFjAC&usg=AFQjCNFC5cnxNv7BOheL_jsiiSQ6X9UXbg.
It was going to the updater of that extension.
So nothing to worry about,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

24ores

  • Guest
Re: Messages from facebook redirected to a possible infected site
« Reply #2 on: February 18, 2013, 08:08:01 PM »
Τhx for your reply could you check another link  that i seen to those messages,h...://www.facebook.com/131224037048839

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Messages from facebook redirected to a possible infected site
« Reply #3 on: February 18, 2013, 08:17:05 PM »
seems it will only work when logged in.... and i don have facebook   ;)

http://urlquery.net/report.php?id=1036022   click picture in top right corner

24ores

  • Guest
Re: Messages from facebook redirected to a possible infected site
« Reply #4 on: February 18, 2013, 08:26:15 PM »
That url,  from facebook, redirects to another link h...://www.profonix--cod.tk/
« Last Edit: February 18, 2013, 08:27:57 PM by 24ores »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
« Last Edit: February 18, 2013, 08:40:55 PM by Pondus »

24ores

  • Guest
Re: Messages from facebook redirected to a possible infected site
« Reply #6 on: February 18, 2013, 08:30:17 PM »
Nope this one h...://www.facebook.com/131224037048839 goes to a picture and redirects to h...://www.profonix--cod.tk/
Thx for you help by the way :)
« Last Edit: February 18, 2013, 08:32:16 PM by 24ores »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Messages from facebook redirected to a possible infected site
« Reply #7 on: February 18, 2013, 08:32:04 PM »
edit above

24ores

  • Guest
Re: Messages from facebook redirected to a possible infected site
« Reply #8 on: February 18, 2013, 08:34:34 PM »
Thank you for your help :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Messages from facebook redirected to a possible infected site
« Reply #9 on: February 18, 2013, 08:43:06 PM »
so seems new....
the bad guys always fish in the pond with most fish, and the biggest is facebook

24ores

  • Guest
Re: Messages from facebook redirected to a possible infected site
« Reply #10 on: February 18, 2013, 08:43:41 PM »
One more address that redirects that message from facebook-h...://www.pvphosting.net/
We have a big problem in Greece as i see  from other profiles with that virus or whatever it is.
« Last Edit: February 18, 2013, 08:47:02 PM by 24ores »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Messages from facebook redirected to a possible infected site
« Reply #11 on: February 18, 2013, 09:00:27 PM »
tested with 5 scanners, got nothing.....yet

http://urlquery.net/report.php?id=1036211

24ores

  • Guest
Re: Messages from facebook redirected to a possible infected site
« Reply #12 on: February 18, 2013, 09:11:05 PM »
Facebook moderators, as i see try for the best cleaning all those messages  from users profiles, i hope to get rid of with that virus soon.
In case i notice anything suspicious i will inform you again.
Greetings from Greece :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Messages from facebook redirected to a possible infected site
« Reply #13 on: February 18, 2013, 09:12:33 PM »
 ;)

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: Messages from facebook redirected to a possible infected site
« Reply #14 on: February 18, 2013, 10:07:31 PM »
Hi Pondus,

Could it be this one: http://pastebin.com/3Yzsv0PW
See the like hostile code flagged here: http://urlquery.net/report.php?id=1036089
I reported on this earlier in our webforum section here: http://forum.avast.com/index.php?topic=102797.0 (218 views, no reactions)
Already high in the IDS alert charts during 2011:
The .tk domain is leased out and highly hostile. if you find some legitimate content in there we'd love to see it.
Other than a couple personal blogs we've been unable to do so. (And we really tried!)

 2012810 - ET CURRENT_EVENTS HTTP Request to a .tk Domain - Likely Hostile (current_events.rules)
 2012811 - ET CURRENT_EVENTS DNS Query to a .tk domain - Likely Hostile (current_events.rules)  (reported by/credits to matt jonkman-
Emerging Sigs on EmergingThreats  5/15/2011)
Also PHISHING going on from that IP - and long overdue issues -migrated from   178.211.44.113   178.211.44.113 to 46.45.177.101   


polonus
« Last Edit: February 18, 2013, 10:18:28 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!