Facebook Password Reset Confirmation! Your Support.
E-mail Attachment Delivers Virus – Old Tricks Die Hard
I got another e-mail from “Facebook support”. This one tells me that my password has been reset, and my new password is contained in the attached Zip file.
[update: I just got two more. This time from “Facebook Networks”, and “Facebook Messages”.]
“Dear user of facebook,
Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.Thanks,
Your Facebook.”
According to Sophos, the malware inside the .zip is: Malware: Mal/TibsPk-A
“About this threat:
Mal/TibsPk-A is a malicious program that contains highly obfuscated code that has been encrypted and compressed. This program typically arrives in the form of a hoax email with an accompanying file attachment.
This program tends to:
- Harvest information
- Download code from the internet
- Open a backdoor allowing a remote intruder to gain access
- Sell fake anti-virus/security related products” (see, Your Computer Is Lying To You… The Epidemic Of Rogues)
Short version: open it and you’re thoroughly hosed.
Sophos continues..
“Fake package delivery or password reset messages trick users
This week, Mal/TibsPk-A arrived as an email attachment in a variety of ways. A typical email containing this malware can be one of the following formats:
Subject: Facebook Password Reset Confirmation! Customer Support.
Attached file: Facebook_password_<random characters>.zip
Subject: DHL Office. Please get your parcel
Attached file: DHL_Label_<random characters>.zip
Subject: Amazon Shop! Your order has been paid! Parcel NR.5014.
Attached file: Postal_label_<random characters>.zip”
I cannot stress enough to you, Dear Reader, that cybercrime is a bigger industry than the illegal drug trade, and they are stealing billions every year. Why not? All it takes is one wrong click!
Don’t be a victim. Exercise “paranoid common sense” when online. This is just one “for instance”.. sent to tens, maybe hundreds, of thousands of e-mail addresses (I never have signed up for Facebook).
Oh, .. and visiting here regularly can help.
Unrelated: Do you like free software? Own a laptop? See my current software license giveaway: Software License Giveaway Drawing. Entering is easy.
Copyright 2007-2010 © Tech Paul. All Rights Reserved. post to jaanix.
>> Folks, don’t miss an article! To get Tech – for Everyone articles delivered to your e-mail Inbox, click here, or to subscribe in your RSS reader, click here. <<
Share this post : | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
March 24, 2010 Posted by techpaul | cyber crime, hackers, Internet, Internet scam, News, security, spam and junk mail | attachment, cybercrime, e-mail, email, Facebook, Facebook Messages, Facebook Networks, Facebook support, facebook.zip, Internet dangers, Internet safety, internet scams, Internet security, password reset, rogue, virus | Leave a comment
• About Tech Paul
I am a Retired computer & network technician. I used to think the machines were pretty cool. Now I don’t.
They’re anything but.
I regularly posted how-to’s and tricks & tips and general computing advice here starting in 2007. (Use the Search tool to find answers. But be aware, many are rather dated.) Sometimes I answered (your) specific questions in an article if I believed the answer was generally helpful to “everyone”. All the writing you see was my own, typos and all. There always is/was an implied “IMHO” in what you see here.
Note: You are responsible for using this blog and its content. I am in no way liable for any losses caused by user error, viruses and/or other malware, hardware or software failure, or any other conceivable reason.
-
Recent Posts
- Merry Christmas
- Just one reason I walked away..
- Use a cellphone? Read this
- A great How To guide for Online Privacy
- “Medicaid Database Department” phone scam
- Yet another major theft..
- How to erase yourself from the Internet
- Accept these two realities
- Remove yourself from people search sites and erase your online presence
- 12 Simple Steps..
Blogroll
- * 100 Incredibly Useful and Interesting Web Sites
- * 15 Mobile Security Tools (smart phones/tablets)
- * AnandTech
- * Best Antivirus 2018 (comparison)
- * Best Free Antivirus 2018 (comparison)
- * Best Free Software
- * Best Internet Security Suites 2016
- * CNet's Security & Antivirus Center
- * Cult of Mac
- * CyberSafe (Kids) – How To Talk To Your Kids (Video Learning)
- * How to erase yourself from the Internet
- * How to remove yourself from Internet search results and hide your identity
- * How To Stay Anonymous Online
- * iLounge
- * Laptop Magazine (part of Tom's Guide)
- * Online Safety and Privacy Education
- * Paul Thurrott's SuperSite for Windows
- * Practical advice for greater online safety
- * Practical Advice for Parents: Computer Use
- * Pulp Tech
- * startpage (the world's most private search engine)
- * The Verge
- * TNW (The Next Web.com)
- * TWiT.TV
- * What's On My PC?
- * Z – MORE READING RECO'S
- How to stop Google from tracking you
Visitors to date
- 4,161,482
-
-
Pages
Recent Comments
Previous Tips & Answers (aka Search This Site)
-
Or use keyword(s)
March 2023 M T W T F S S 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 A Winner’s Blueprint for Achievement
BELIEVE while others are doubting.
PLAN while others are playing.
STUDY while others are sleeping.
DECIDE while others are delaying.
PREPARE while others are daydreaming.
BEGIN while others are procrastinating.
WORK while others are wishing.
SAVE while others are wasting.
LISTEN while others are talking.
SMILE while others are frowning.
COMMEND while others are criticizing.
PERSIST while others are quitting.~ William Arthur Ward