Koobface behind the scenes

By Cara Garretson  Add a new comment

Security researchers are looking into not just how Koobface infects users’ PCs, but how its creators manage to spread the worm across popular social networking sites to maximize its effectiveness.

Not unlike enterprising Web sites that try to maximize page views, Koobface’s creators leverage SEO (search-engine optimization) techniques to achieve high levels of exposure.

According to a blog post on security vendor Finjan’s Web site, the malware automatically creates BlogSpot accounts and aims to attract maximum visitors by filling blog posts with the latest news from Google news feeds, which often include the most popular search terms.

Of course, the readers of these blogs gets much more than the latest news; scripts are embedded in the posts that redirect readers to a bogus Web site, such as a fake Facebook page, that attempts to download Koobface. If the site is successful in convincing visitors to download Koobface, the worm then creates new accounts on various Web sites.

It works its way around the CAPTCHA box by telling users of the infected PCs they must enter the correct text or their machine will shut down. Once the user responds, the new accounts are created and bogus blog posts are produced.

Proof that this technique works is readily available – Finjan says its researchers tracked the creation of one of these malware Web pages and found it attracted more than 150,000 users in two days.

Researchers at Symantec are also tracking the practices of the “Koobface gang.” They’ve found that the central server that is responsible for redirecting victims to infected PCs – where they then become infected – has been very successful in eluding take-down attempts.

The malware’s creators have been able to quickly replace domain names that fall under suspicious with new ones: over a three-week period Symantec saw 17,170 distinct IP addresses used. The researchers also noticed that members of the Koobface botnet are highly concentrated in the U.S., but also present in Europe and other parts of the world.

Do you tweet? Follow me on Twitter here.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question