Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spam Reports

July 12th, 2010, 08:31 GMT · By

YouTube Spam Emails Carry Malicious JavaScript

SHARE:

Adjust text size:


Fake YouTube friend request emails carry malicious HTML documents
Enlarge picture
Security researchers from German antivirus vendor Avira warn of a new spam campaign producing emails that masquerade as YouTube friend requests. The rogue emails have attached an HTML file containing obfuscated malicious JavaScript code.

“During the last few days we received a lot of mails with subjects like 'User <username> suggests you to become friends on YouTube,'” the Avira researchers announce. The “From” field has been forged to appear as if the emails originate from “YouTube Service.”

English speakers should be able to realize that this is a spam quite easily, as the message is very poorly spelled. The body of the rogue emails reads “User <username> suggests you to become friends on YouTube. Offerts and acceptance of offers on friendship simplify tracing of that your friends place in the selected works, add or estimate, and also simplifies video departure by all or to the selected users. To accept or reject this invitation, pass in attach file.”

Fake YouTube friend request spam email
Enlarge picture
The attachement is an HTML document called “YouTube Message.html” and according to Avira, it contains obfuscated JavaScript code. If the file is opened in a browser this code will redirect the user to an external domain, from where they will be redirected once again onto a page loading malicious content via a hidden IFrame.

These content consists of exploits targeting outdated versions of popular applications that might be installed on the visitor's computer. Successful exploitation leads to a malware installer being dropped and executed onto the system. These attacks are known as drive-by-downloads and Avira detects the malicious IFrame as HTML/IFrame.cef.

In order to keep themselves protected against such threats, users are advised to keep their applications up to date, especially those installing browser plug-ins, like Adobe Flash Player, Adobe Reader or the Java Runtime Environment. Using an antivirus program capable of scanning and identifying threats over HTTP, when surfing the Web is also a must.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,987 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Twitter Invitation Email Scam Spreads Malware Downloader

Fake Changelog Emails Contain Malware

Fake DHL Emails Distribute New Trojan

New Bredolab Campaign Spoofs Amazon

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM