Posted by: David Harley | April 12, 2010

I thought I’d bought London Bridge, but instead I bought the farm

Back at the end of March, I reported on a hoax alert from Graham Cluley  about an alleged Farmville virus threatening users of the Facebook farming simulation game.

 Here’s the hoax text again:

RED ALERT!!! Norton has just informed me that the post for Send the 3 spring Eggs at a time is a virus, Rawand Bradosty is a HACKER from Pakistan, do not click on this post it is not legitimate, please copy and repost immediately.

Just in case there’s any confusion, the association of the Farm Town app with malvertizements redirecting to malicious URLs pushing fake AV is a different kettle of fish. Err, cows? OK, maybe it’s a fish farm? Whatever.

As I just got back from a few peaceful days avoiding anything to do with malware and have lots to catch up on, here are a few links with info on the Farm Town problem, if you need more info.

Jeremy Kirk of PC World on “Malicious Facebook Ad Redirects to Fake Antivirus Software”: http://www.pcworld.com/businesscenter/article/194008/malicious_facebook_ad_redirects_to_fake_antivirus_software.html

Graham Cluley of Sophos on “Farm Town virus warning: Malvertising at work?” and giving you a good idea of what Slashkey are doing wrong, at http://www.sophos.com/blogs/gc/g/2010/04/12/farm-town-virus-warning-malvertising-work/

Elinor Mills at CNET: http://news.cnet.com/8301-27080_3-20002267-245.html?part=rss&tag=feed&subj=InSecurityComplex&utm_source=twitterfeed&utm_medium=ping.fm

David Harley FBCS CITP CISSP
Mac Virus
Small Blue-Green World
AVIEN Chief Operations Officer
ESET Research Fellow & Director of Malware Intelligence

Also blogging at:
http://www.eset.com/blog
http://avien.net/blog/
http://smallbluegreenblog.wordpress.com/
http://blogs.securiteam.com
http://blog.isc2.org/
http://dharley.wordpress.com
https://chainmailcheck.wordpress.com
http://amtso.wordpress.com

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Categories

%d bloggers like this: