Threat Level: green Handler on Duty: Rob VandenBrink

SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center InfoSec Handlers Diary Blog

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Facebook Password Reset Confirmation. Customer Support. (Malware)

Published: 2009-12-10
Last Updated: 2011-02-08 23:52:53 UTC
by Adrien de Beaupre (Version: 1)
2 comment(s)

I received an email today purporting to be from Facebook, which of course had an attachment. The file was, which unzipped to be Facebook_Password_833fd.exe. The zip file is in fact a zip file, and the exe is in fact MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit (according to the file command). The subject line is "Facebook Password Reset Confirmation. Customer Support. " The body of the email is pretty straight forward:

"Hey email,

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Your Facebook."

Which is an attempt to get you to first open the attachment, unzip the file, and then run the executable content. The executable has the following attributes:

File size: 27648 bytes
MD5   : 11dee2f7ecc31a9a6f5fcab4e9654073
SHA1  : 30cfe72393ca5c58e7bba452c401932c6dcc9a9f

First set of Virustotal results were 20/41 today at 01:30:12 (UTC) when I ran it again at 17:49:06 (UTC) they were up to 26/41 detection. It is a dropper which subsequently downloads and executes other badness.

Facebook does not send out passwords in attached files. If you have forgotten your password on Facebook reset it here: if you cannot login to your account (someone else has taken it over) go to this page:, which also has this advisory on it:

"Fake password reset emails

Some users have received fake password reset emails with attachments that contain viruses. Do not click on these emails or download the attachment. Also, please note that Facebook will never send you a new password as an attachment. To learn more visit our Security page:

Adrien de Beaupré Inc.

2 comment(s)
Diary Archives