Fake 'Rihanna & Chris Brown S3X Video' Spam Campaign Spreading Across Facebook, Monetized Through Adf Dot Ly PPC Links

A currently ongoing, click-jacking driven spam campaign is circulating across Facebook, with the affected users further spreading the links on the Walls of their friends, in between tagging them, with the cybercriminal/cybercriminals behind the campaign, earning revenue through the pay-per-click (PPC) monetization scheme.

Redirection chain:
hxxp:// -> hxxp:// -> hxxp:// -> hxxp://

MD5s for the Facebook spamming/click-jacking scripts:
Domain name reconnaissance: - -

Name servers used:

Responding to the same IP ( are also the following domains:

Known to have responded to the same IP ( in the past are also the following domains:

Responding to ( is also the following domain:

Known to have responded to the same IP ( is also the following domain:

Bogus "Shocking Video" Content at Scribd Exposes Malware Monetization Scheme Through Parked Domains

Bogus content populating Scribd, centralized malicious/typosquatted/parked domains/fraudulent infrastructure, combined with dozens of malware samples phoning back to this very same infrastructure to monetize the fraudulently generated traffic, it doesn't get any better than this, does it?

URL redirection chain:
hxxp:// -> hxxp://
0mZKYzSpf6qGlAAgYN_vvwAA4H8BAABAgFsLAADgPokxWVMmWUExNmhaQqAAAADw -> monetization through Google/MSN


Domain names reconnaissance: - - Email: - Belcanto Investment Group - - Email: - Oversee Domain Management, LLC

The following related domains are also registered with the same email (

Out of the hundreds of domains known to have phoned back to the same IP in the past, the following are particularly interesting:

Malicious MD5s known to have made HTTP (monetization) requests to the same IP (
Malicious MD5s known to have made HTTP (monetization) requests to the same IP (
This case is a great example of one of the core practices when profiling cybercrime incidents and campaigns -> sample everything, as what you're originally seeing is just the tip of the iceberg.

Malware-Serving "Who's Viewed Your Facebook Profile" Campaign Spreading Across Facebook

A currently ongoing Facebook spreading malware-serving campaign, entices users into downloading and executing a malicious executable, pretending to be a "Who's Viewed Your Facebook Profile" extension. In reality though, the executable, part of a campaign that's been ongoing for several months, will steal private information from local browsers, will auto-start on Windows starup, and will attempt to infect all of the victim's friends across Facebook.

The executable, including several other related executables part of the campaign, are currently hosted on Google Code, and according to Google Code's statistics, one of the malicious files has already been downloaded 1,870,788 times. Surprisingly, the Coode Project is called "Project Don't Download". Very interesting self-contradicting social engineering attempt.

Let's dissect the campaign, list the domain's portfolio used in it, provide detection rates for the malicious executables, and connect the campaign to multiple other campaigns observed in the wild over the last couple of weeks.


Sample redirection chain:
hxxp:// -> hxxp:// -> hxxp:// -> hxxps://

Subdomain reconnaissance: - - - Email:

Detection rate for the malicious executable: MD5: c5b2247a37a8d26063af55c6c975782d - detected by 23 out of 47 antivirus scanners as JS:Clicker-P [Trj]; RDN/Generic.dx!chs

Once executed, the sample drops the following MD5s on the affected hosts:
Download statistics for the malicious executables hosted on Google Code:
Profile Viewer - 5.exe - 1,870,788 downloads
Profile Stalker - V.exe - 45983 downloads
Profile View - 5v2.exe - 9496 downloads
Profile Stalker - D.exe - 2 downloads

Detection rates for the malicious executables hosted on Google Code:
Profile Stalker - D.exe - MD5: c9220176786fe074de210529570959c5 - detected by 3 out of 47 antivirus scanners as Trojan.AVKill.30538; JS/TrojanClicker.Agent.NDL
Profile Stalker - V.exe - MD5: a6073378d764e3af4cb289cac91b3f97 - detected by 24 out of 47 antivirus scanners as JS/TrojanClicker.Agent.NDL; Trojan.Win32.Clicker!BT
Profile Viewer - 5.exe - MD5: 814837294bc34f288e31637bab955e6c - detected by 24 out of 47 antivirus scanners as Troj/Agent-ABOE

Samples phone back to the followind URLs/domains:
hxxp:// - - -

Facebook and Google have been notified.

This post has been reproduced from Dancho Danchev's blog. Follow him on Twitter.