A message from a friend of ours informed us about a new threat (Trojan) circulating on Facebook. Using the social network's private messaging service, scammers are trying to market trojans to unsuspecting users.
Our friend from safer-internet.grsent us two different images from Facebook messages. The messages say something like “watch this and don’t tell anyone” and contain two .rar files with different names:
We requested the files to analyze them and of course there was nothing to see. Although the two rar files had different names, the executable file they contained was exactly the same (same CRC Checksum.)
and its name: Watch This!!!.vbs
The executable files were in .vbs format. vbscript is a scripting language that comes with Windows. With it you can do various useful things, as you have seen from the Tweaks category of iGuRu.gr, but you can also write trojans.
The script contained in the 2 rar files contained the TrojanDownloader.Agent.NJV trojan, which was indexed by ESET on February 11, 2012.
What does a Trojan Downloader do?
A Trojan downloader, as soon as it runs on the victim's computer, searches for access to a remote computer to download files which it then installs on the infected computer.
This particular Trojan, TrοjanDownloader.Agent.NJV trojan, is old and therefore is immediately recognizable by antivirus software, provided you have updated them.
It goes without saying that you should not open zip or rar files you aren't expecting and that arrive in messages, even if you know the sender.
If you already have the file running and it hasn't “hit” to antivirus you are using, change or update your security application.
Update:
While the malicious messages continue to arrive on Facebook, we decided to open the script for further analysis.
All the malicious links appear to lead to the same server, which has apparently been compromised.
See 3 of the domains
The iGuRu.gr team informed the server owner to take the necessary measures.
All malicious addresses are included in the photo below as listed in the script
We believe that the malicious user is Greek as there are malicious files with Greek names, such as e.g. . /vasika/kalisperasas.zip. Also the folder that is used to download the malicious files is named by the malicious user “\MyFolderakis.”
After installation it creates the above folder on the victim's computer, downloads the content.zip which contains a . jar file.
download(csPATH)
Unzip csPATH &”\content.zip“, csPATH
Loop While ReportFileStatus(csPATH &”\sapsalo.jar
Once it downloads the content.zip and runs the jar (while the vbs script runs only on Windows, the jar runs on Windows, Mac and Linux) it starts downloading all the other malicious files, from the links we provided above.
Caution, as we have not downloaded the above files and do not know what they contain.




