8 ms·
I was tricked on Facebook into downloading an obfuscated script
- Aelinsaar 10y agoI treat any attempt to download like an attempt to call my phone, or ring my doorbell when I'm not expecting someone. Instant suspicion which is, 99% of the time, unfounded. Still, I've never had to deal with the Jehovah's Witnesses.
- ht85 10y agoI'm always curious about how people react to unwanted solicitation. When it happens to me, as soon as I realize I say "sorry" and close the door. When my door rings unexpectedly, I'm more worried it might be someone I know, as I'm usually in the middle of my work day, as in hacking stuff in my underwear.
- mathattack 10y agoFor whatever reason, in my most current job, unwanted phone calls and email solicitations have gone up 20X. With phone calls I give a polite "not interested" and if there is anything other than "I'm sorry" I hang up mid-sentence. It took me a while to be this direct, but they have no right to waste my time. With email I used to politely say, "I'm not interested" to the spammer's email. (I've been on the other side, and it's tough work) Then I realized that it's just feeding the beast, so I usually ignore and mark as spam.
- djKianoosh 10y agoI take it a step further. insta-block phone numbers (never answer either) and insta-spam/unsubscribe emails.
- tokenizerrr 10y agoAnd how do you know a phone number is spam without answering it?
- uxp 10y agoGenerally, if it's not in my contacts list, then it's unsolicited and flagged spam. I won't answer unknown phone numbers (as I get a large number of spam calls in Spanish for immigration and high interest loans coming from or spoofed to the same area code and CO as my number, so even "local" numbers are suspect to me). If I don't answer, they leave a message, and it is someone or someplace I know about, then I'll add it to my contacts. If I answer an unknown number, just the act of asking "Hello?" seems to be about the equivalent as clicking an unsubscribe link in a true spam message; it notifies the spammer that they've got a warm contact that they can resell or contact again.
- tokenizerrr 10y agoIt's insane to me that you refuse to pick up the phone for people whose phone number you don't know. Aren't you anyone's emergency contact?
- uxp 10y agoYes I am. I know iOS allows someone to dial their emergency contact from a locked phone, so in that case I will receive a call from the person's phone that I know about. Otherwise, they leave a message and I get to it immediately and call them back. The reality of an emergency situation where someone I know has me listed as an ICE contact and someone else calls on their behalf from an unknown number is that I cannot do much to help them in a situation that a minute or two of phone-tag would introduce. That's what 911 and other emergency services are for. If you are ever in a situation where you come across someone that has just sustained major injury, who are you going to call first? Their children or spouse to let them know of the situation, or medical help via 911? I'd hope you would chose the latter to get them the critical medical help they need before you inform someone else of the situation.
- kalleboo 10y agoI simply don't answer. We have a video intercom though so I can see on a screen if it's a courier or something.
- pavel_lishin 10y agoThis has only happened to me in apartment buildings; it's either some proselytizers, or people pretending to work for Con-Ed trying to scam me out of money. Either way they're trespassing, and in the latter case actively trying to harm me. The last time this happened, I technically wasn't on the lease, so my wife discouraged me from following them around the building, introducing myself to the neighbors and breaking their spiel.
- Aelinsaar 10y agoI find the phrase, "I'm as a armed as I am dangerously and violently psychotic" to be a fabulous ice-breaker. Since I'm neither armed, nor psychotic, it's a true statement and not my fault that they probably didn't get that part.
- a3n 10y agoI engage Jehovah's Witnesses, but not in the dick way that capital A Atheists might (I'm a small a atheist). I try to learn what they're about. They're generally nice people.
- cbd1984 10y agoAtheists are atheists. If you're going to make a distinction, make it between individuals, not groups.
- Zancarius 10y agoPerhaps I'm being unnecessarily charitable in my interpretation of what a3n said, but I gathered from the differentiation between "capital A" atheists and lowercase a atheists as a subtle distinction between individuals who evangelize their beliefs and those who don't.
- jacquesm 10y agoI think it is the party coming to your door that does the evangelizing and I've yet to have an atheist ring my doorbell.
- nostrebored 10y agoRight, but to pretend that it doesn't happen in common conversation is absurd. Atheists frequently evangelize. It is a religious belief.
- type0 10y ago> Atheists frequently evangelize. It is a religious belief. They evangelize, but its more of ideology that concerns religion rather than just a belief. The main problem with atheism is the definition: absence of religion, this is such a derogatory word as if believing in deities should be the norm. Agnostic is even worse seat: declaring that you have no clue but probably are somewhat spiritual. If you don't like religion say proudly that you are antitheist!
- my_first_acct 10y agoMaybe the wrong place for a newbie question, but here goes. IF I am running up-to-date versions of Windows and Chrome, and I click on this link, is it game over? Or do I get another chance to refuse installation of whatever malware is in the payload?
- thefreeman 10y agoYou have to double click the downloaded file to execute it under Windows Script Host
- my_first_acct 10y agoThanks. That is somewhat reassuring. The likelihood of my doing something stupid/oblivious is higher than it should be, but the likelihood of being stupid twice in a row is quite a bit lower.
- jaredsohn 10y agoI imagine the likelihood of making incorrect decisions twice in a row is higher in some contexts, though. For example, if you click a button that says it will download a Flash update from some random website, I'm guessing there is a good chance you will then run it afterward.
- alexchantavy 10y agoAnd then if you have UAC (or whatever it's called) turned on, you'll get a warning that the .exe you're about to run is unsigned, right?
- yuhong 10y agoIt is not an exe. But even without UAC, there is another layer of warnings that has been there since XP SP2 for unsafe file types downloaded from the Internet.
- 10y ago
- vanderZwan 10y ago> Facebook tricked me into downloading an obfuscated script This title suggests Facebook is doing this, even though it's clearly a malware exploit
- dang 10y agoThat was a badly rewritten title, and we've restored the original. (Edit: never mind–the rewrite was at the host end.) Submitters: please use the original title unless it is misleading or linkbait. That's in the site guidelines (https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html). Making a title more misleading and linkbait is the wrong direction! (Submitted title was 'Facebook tricked me into downloading an obfuscated script'.)
- m-app 10y agoTo be honest, the original title used to be just that: http://security.stackexchange.com/posts/128254/revisions http://security.stackexchange.com/posts/128254/revisions
- dang 10y agoOh, good catch. Sorry for doubting you, yammesicka :) Actually the dynamic rewrite thing has only ever come up significantly with NYT, who do that all the time.
- Kiro 10y ago> I got a notification on Facebook: "(a friend of mine) mentioned you in a comment". However, when I clicked it, Firefox tried to download the following file: I interpret that as it started downloading when clicking the notification but the picked answer suggests otherwise.
- paulpauper 10y agoThey must have gotten a TON of downloads..look at the sats: http://whos.amung.us/stats/pingjse3462 http://whos.amung.us/stats/pingjse3462 http://whos.amung.us/stats/pingjse346 http://whos.amung.us/stats/pingjse346
- x0ner 10y ago* Disclosure: I used to work for Facebook's security team and focused on threats that impacted users on the platform. * The post outlines in some detail a common attack done by some actors known as BePush/Killim. I made a request for help in fighting these clowns months ago on a private security working group. Here's the post below which outlines a good amount of detail about the hacks and motives. If you are interested in tracking these actors yourself, it's pretty easy once you find one of their command and control servers. Example: https://www.passivetotal.org/passive/userexperiencestatics.net https://www.passivetotal.org/passive/userexperiencestatics.n... From there, we can see the actors are using Cloudflare to obfuscate their infrastructure, but we can make a pivot based on the WhosAmongUs IDs (dsafagegg2 [1] and dsafagegg [2]) in order to find more websites owned by these guys. It's a rats nest that extends to hundreds of domains registered weekly. Servers are typically hosted in places where legal action is difficult meaning the attacks seldom stop or go down completely. [1] https://www.passivetotal.org/trackers/WhosAmungUsId/dsafagegg2 [2] https://www.passivetotal.org/trackers/WhosAmungUsId/dsafagegg ----------------------------------------------- As promised, below is a quick high-level summary of the malware outlined in the subject. We've been dealing with the malware for months and while some would call is spam, we consider it malware simply because any of the executables or Chrome extensions could be changed to steal passwords, credit cards or every document off a system. We welcome any help in dealing with these actors and would also be interested in new ways to combat malicious extensions, both Chrome and Firefox as those are only increasing in usage. If you would like more information on the technical details of the binaries, extensions or other loaders, feel free to shoot me a message. If there's enough interest, I will just spam the list, but would prefer to keep this to the higher level points, so others gain a better understanding of the threat. -= Summary =- BePush is a set of Turkish-based actors who use innovative techniques to spread malicious code and spam through social networking sites and ad-based networks. Those involved in the development of BePush malware are constantly adjusting their TTPs to account for changes in detection or disruption. Actors favor multiple levels of obfuscation through the use of short-url redirectors, third-party hosting providers and multi-stage payloads. Despite high infection rates, local law enforcement has yet to take an interest in pursuing those actors involved. -= Infection Process =- Based on our logs, primary infection processes tend to occur through direct traffic, followed by Facebook and various ad providers. Shortened URL links are shared among users which typically traverse through a series of redirects to a landing page mimicking Facebook infrastructure and using porn as a lure to install a plug-in. Depending on the attacker behavior, payloads may be delivered in the form of a Google Chrome extension (hosted within the store) or through an executable (likely AutoHotkey, but could be Pyinstaller based) that later replaces Chrome with a version of Chromium with their malicious extension. Once installed, malicious code will make use of the Facebook Graph API in order to make requests/posts on behalf of the infected user using a stolen access token. In order to establish a high infection count, the malicious code will often create pages with malicious links, post statuses/comments to the user's friends and spam within certain application pages. Once the spreading routine completes, the process generally begins again with the infected user's friends. -= Motives and Capabilities =- It appears the primary motivation for the BePush actors is the money gained through the sale of Facebook likes, followers or various ad-network and affiliate partners. In some cases, Facebook observed BePush actors including a bundled bitcoin miner, but it never appeared to gain much popularity. From a capabilities perspective, actors involved with BePush appear to pay attention to how their code is detected. When numbers begin to dwindle, changes to the code or 3rd-party providers are made. Actors demonstrate a level of understanding in .Net programming, Python, JavaScript and techniques used to detect spam. We have also observed the actors repurposing browser exploits, but we never saw these used against users. -= Third-Party Provider Usage =- BePush favors the use of free and open infrastructure in order to keep their campaigns alive long enough to get a strong infection foothold. The following providers have been observed in some capacity: - Amazon AWS - Used for hosting content - Dropbox - Used to host binaries - Box.com (http://box.com/) - Used to host binaries - Bitly - Used for redirection - Tinyurl - Used for redirection - Godaddy - Used for redirection - WhosAmungUs - Used for campaign tracking - Stellar - Used for bitcoin wallet hosting - Imgur - Used for redirection - Dot.tk - Used for redirection - Google - Used for redirection, Chrome extensions and binary hosting - CloudFlare - Used to obfuscate real infrastructure - Microsoft Azure - Used to host binaries -= Detection and Research =- BePush has a limited set of providers they prefer to use and through industry relationships, we have been able to put pressure on the attackers. Here are a couple items we noticed when doing disruption work that helped in making a larger impact against the group. Using passive DNS data to identify other domains sitting on the same IP address (these guys don't use a lot of unique servers) Use ESET (Facebook) or Microsoft (Kilim) AV signatures to identify new binaries being used Polling whos.amung.us (http://whos.amung.us/ http://whos.amung.us/) tracking pixels in order to identify/gauge recent campaigns Reaching out to 3rd-parties with domain and hash combination for takedown -= Reference Hashes and Domains =- www[.]filmgetir[.]com https://www.virustotal.com/en/file/9e4484240df6e891b2a07c1ff2345e0864dd8b54e005c58388c6556cdc7cc120/analysis/ www[.]kingtr[.]click https://www.virustotal.com/en/file/9e4484240df6e891b2a07c1ff2345e0864dd8b54e005c58388c6556cdc7cc120/analysis/ www[.]pornokan[.]com https://www.virustotal.com/en/file/c5eeef4da2c64e8633b1f00745fecb0b692be27d4b615df086201754b07ebe60/analysis/ https://www.virustotal.com/en/file/3566452da48ba0fa31b11deae561b4d5f2a1385e83fd5537a021e75b649664b6/analysis/ https://www.virustotal.com/en/file/1a0163780f07aeaafd9e94fbe628b3f354b25afbec1f7c6e6e401cc7c06d909a/analysis/ https://www.virustotal.com/en/file/b216915643628834acd60e7ae9647e51baca636d8b05ea66857d40c9d04172a8/analysis/ https://www.virustotal.com/en/file/80d9d1df0d859fe6759bba7077be1a15eea477774c91e789e9d5988f19f0a023/analysis/ https://www.virustotal.com/en/file/940bc772a2e301e15a326e667a318942dd840149afa4031245dd125c645330ab/analysis/