Malware City/Blog/

Nov
17
Filed Under:
WEEKLY REVIEW

BitDefender Weekly Review – Trojan.Sasfis.A Aims at Facebook Users

17 November 2009
Email attachments containing viruses or Trojans are pretty rare these days, but they haven’t gone totally extinct. The most recent campaign trying to lure users into downloading and installing a Trojan on their systems targets Facebook subscribers and features Trojan.Sasfis.A.

The Trojan comes attached to an email message allegedly coming from Facebook. The spam message announces the user that the popular platform has updated their Terms of Service (included in the attachment) and every active subscriber must revise and accept it or else their access would be restricted. This is a typical scenario that relies on victims' fear of being restricted or prosecuted unless they comply with the request.

However, the attached zip archive only contains a binary file, called agreement.exe and infected with Trojan.Sasfis.A. The 20-kilobyte file is a dropper, which means that it only downloads a dll file from the web and copies it either in %USERPROFILE%\Local Settings\Temp\[random digits].tmp or in %SYSTEM%\ifmq.kqo. If the infected system has Microsoft Office installed, the malware would attempt to run a Visual Basic script with OLE automation in the context of MS Word's process.

Trojan.Sasfis.A also features an update component, which makes it extremely dangerous, given the fact that an attacker may remotely install additional malware such as keyloggers.

Please remember that legitimate companies do not send messages containing attachments, but rather inform users on policy changes as they log into their account. You are also advised to install and regularly update a security solution with antimalware, anti-phishing and anti-spam modules.

Information in this article is available courtesy of BitDefender virus researcher Horea Coroiu.




Bogdan never trusts anything until it is disassembled into small pieces and carefully inspected. The passion for writing and the almost obsessive attention to details are some of his greatest qualities and, at the same time, some of his greatest flaws.

Comment on this

Name:

Email:

Website:

Your email adress will not be published.