{"id":74604,"date":"2012-07-24T15:06:51","date_gmt":"2012-07-24T09:36:51","guid":{"rendered":"https:\/\/blogs.quickheal.com\/?p=74604"},"modified":"2023-10-12T12:54:22","modified_gmt":"2023-10-12T07:24:22","slug":"malware-attack-through-facebook-photo-tag-notification","status":"publish","type":"post","link":"https:\/\/www.quickheal.com\/blogs\/malware-attack-through-facebook-photo-tag-notification\/","title":{"rendered":"Malware attack through Facebook photo tag notification"},"content":{"rendered":"<p>This is a warning for Facebook users. A fraudulent email is circulating on the Internet claiming to be from Facebook and saying you&#8217;ve been tagged in a photo.\u00a0The email probably looks like this:<\/p>\n<p><a href=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2012\/07\/scamscamFacebook.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-74606\" src=\"https:\/\/blogs.quickheal.com\/wp-content\/uploads\/2012\/07\/scamscamFacebook.jpg\" alt=\"\" width=\"485\" height=\"370\" \/><\/a><\/p>\n<p>On a closer look the email is from \u201c<em>notification @faceboook.com<\/em>\u201d and not from a \u201c<em>Facebook.com<\/em>\u201d domain. This is a specially crafted email that is targeting innocent <a href=\"https:\/\/blogs.quickheal.com\/can-facebook-account-misused-hacked\/\">Facebook<\/a> users. Those who click on the link in the email get redirected to a bogus link that hosts malicious iframe scripts. These scripts take advantage of the\u00a0<em>Blackhole<\/em> exploit kit and start infecting the system.<\/p>\n<p>This happens within a few seconds and then the browser gets redirected to the original Facebook website. So the user does not get a hint about any kind of suspicious or malicious activity. In our case, two malicious files got downloaded. These files belong to the <strong>Trojan. Redirector<\/strong> family. Malware that\u00a0belongs to this category has the following characteristics:<\/p>\n<ul>\n<li>Stays resident in the background<\/li>\n<li>Changes browser settings<\/li>\n<li>Shows commercial adverts<\/li>\n<li>Connects itself to the Internet<\/li>\n<\/ul>\n<p>Kindly do pay attention while clicking on any link in the email. If you come across such emails do not click on any link present inside. Instead, delete the email and keep your <a href=\"https:\/\/www.quickheal.com\/\">Quick Heal<\/a> antivirus updated.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a warning for Facebook users. A fraudulent email is circulating on the Internet claiming to be from Facebook and saying you&#8217;ve been tagged in a photo.\u00a0The email probably looks like this: On a closer look the email is from \u201cnotification @faceboook.com\u201d and not from a \u201cFacebook.com\u201d domain. This is a specially crafted email [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,41,24],"tags":[182,22,42,23,43,29,66,40],"class_list":["post-74604","post","type-post","status-publish","format-standard","hentry","category-email","category-facebook","category-malware","tag-blackhole","tag-email-malware","tag-facebook-scam","tag-fraudulent-email","tag-facebook-malware","tag-social-engineering","tag-social-network-privacy","tag-trojan"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/74604"}],"collection":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/comments?post=74604"}],"version-history":[{"count":3,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/74604\/revisions"}],"predecessor-version":[{"id":92115,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/posts\/74604\/revisions\/92115"}],"wp:attachment":[{"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/media?parent=74604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/categories?post=74604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.quickheal.com\/blogs\/wp-json\/wp\/v2\/tags?post=74604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}