
SonicWALL UTM Research team observed reports of a new Facebook malware being spammed via private messages through Facebook. The message pretends to contain link to a photo album but eventually leads to download of the malware.
Thousands of users were reportedly affected by this malware. Messages sent by the malware from the infected machine looks like:
If the recipient user clicks the link, it leads them to a malicious site that looks like:
Malware gets downloaded when user clicks on the photo album:
If the user attempts to open the downloaded executable it will perform following activities:
Process 1.exe
This process scans for any open Internet Explorer or Firefox instances and terminates them to ensure that code injected by process 3.exe gets executed during next browsing session.
Process 2.exe
This process performs following file and registry modifications:
Process 3.exe
Following HTTP requests were initiated by the malware once the user logs onto Facebook on an infected machine:
SonicWALL Gateway AntiVirus provides protection against this malware via GAV: Kbot.ANJ (Trojan) signature.
Share This Article

An Article By
An Article By
Security News
Security News