Forum     

Go Back   Digit Technology Discussion Forum > News > Random News
Register FAQ Calendar Mark Forums Read

Random News Non-technology news that you feel members should know about. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 25-03-2007, 01:07 PM   #1 (permalink)
Human Spambot
 
Kiran.dks's Avatar
 
Join Date: Apr 2006
Location: Pune, India
Posts: 2,501
Exclamation WARNING: Orkut ID Hacked and Testimonial written in some language...!!


Today I received email notification that my friend "Raj" has written a testimonial for me. I logged in Orkut and found something bizzare. A testimonial from my friend in some language and a link. I found it strange. My friend Raj revealed that he never wrote a testimonial for me!! He is astonished and so am I too!

The testimonial leads to a website. I clicked on the link. Instead of opening the page, it download a exe file of 145KB. I downloaded it and scanned for spywares. I found nothing. But I am not sure of running the exe.

The whole point in posting this thread is to spread awareness.

Below is the snap shot of the testimonial I recieved. It says it is from Raj(My friend). He never sent it!

__________________
Kiran Kumar R

Last edited by Kiran.dks; 25-03-2007 at 01:12 PM.
Kiran.dks is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 25-03-2007, 01:10 PM   #2 (permalink)
Right Off the Assembly Line
 
SoFtEcH's Avatar
 
Join Date: Sep 2006
Location: Karaikal, India.
Posts: 48
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

OMG@ this is weird....
SoFtEcH is offline  
Old 25-03-2007, 01:14 PM   #3 (permalink)
The Thread Killer >:)
 
phreak0ut's Avatar
 
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Thanks a lot for sharing Kiran. Need to spread this news asap!!
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)
phreak0ut is offline  
Old 25-03-2007, 01:29 PM   #4 (permalink)
Human Spambot
 
Kiran.dks's Avatar
 
Join Date: Apr 2006
Location: Pune, India
Posts: 2,501
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Ok guys...I did some R&D of the language used. It turned out to be Portugese!!

Here is the translation:
Quote:
Its presence is a gift for the world You is unico(a) and alone you have an equal person Its life you can be what to want that is Alive the days, only one of each time Counts to its bençãos, its problems You will not surpass them, you happen what to happen Inside of you she has many answers Understands, you have courage, either strong you do not impose limits exactly itself... Many of your dreams are for being carried through. E this image below complements everything what you mean:
h**p://urlcut.com/img12
Happinesses 1000!
What the heck is this??? Bloody hacker.
__________________
Kiran Kumar R
Kiran.dks is offline  
Old 25-03-2007, 05:20 PM   #5 (permalink)
The Thread Killer >:)
 
phreak0ut's Avatar
 
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
Exclamation Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Guys, I had downloaded the malware and submitted the file to virustotal.com, which does a scan for suspicious behaviour with various antivirus. Here is the report which I got in my mail

Quote:
Complete scanning result of "x.exe", processed in VirusTotal at 03/25/2007
13:41:39 (CET).

[ file data ]
* name: x.exe
* size: 147622
* md5.: 3442355b265a863016eeb69e88de7de2
* sha1: d4f1e73f4cbded11701d3bcc92f5feef0506a746

[ scan result ]
AhnLab-V3 2007.3.24.1/20070324 found nothing
AntiVir 7.3.1.44/20070325 found [TR/Delphi.Downloader.Gen]
Authentium 4.93.8/20070324 found [Possibly a new variant of
W32/new-malware!Maximus]
Avast 4.7.936.0/20070323 found nothing
AVG 7.5.0.447/20070324 found nothing
BitDefender 7.2/20070325 found [Trojan.Downloader.Banload.AOO]
CAT-QuickHeal 9.00/20070323 found [(Suspicious) - DNAScan]
ClamAV devel-20070312/20070325 found nothing
DrWeb 4.33/20070325 found nothing
eSafe 7.0.14.0/20070322 found [Win32.Polipos.sus]
eTrust-Vet 30.6.3506/20070323 found nothing
Ewido 4.0/20070324 found nothing
F-Prot 4.3.1.45/20070323 found [W32/new-malware!Maximus]
F-Secure 6.70.13030.0/20070324 found [Trojan-Downloader.Win32.Banload.aoo]
FileAdvisor 1/20070325 found nothing
Fortinet 2.85.0.0/20070325 found [suspicious]
Ikarus T3.1.1.3/20070325 found [Backdoor.Win32.Hupigon.BV]
Kaspersky 4.0.2.24/20070325 found [Trojan-Downloader.Win32.Banload.aoo]
McAfee 4991/20070323 found [New Malware.u]
Microsoft 1.2306/20070325 found nothing
NOD32v2 2143/20070325 found [a variant of Win32/TrojanDownloader.Banload.AOO]
Norman 5.80.02/20070323 found nothing
Panda 9.0.0.4/20070324 found nothing
Prevx1 V2/20070325 found nothing
Sophos 4.15.0/20070323 found [Mal/Packer]
Sunbelt 2.2.907.0/20070324 found [VIPRE.Suspicious]
Symantec 10/20070325 found [Infostealer.Banpaes]
TheHacker 6.1.6.080/20070323 found nothing
UNA 1.83/20070316 found nothing
VBA32 3.11.2/20070324 found [suspected of Downloader.Banload.15 (paranoid
heuristics)]
VirusBuster 4.3.7:9/20070325 found [Packed/NSPack]
Webwasher-Gateway 6.0.1/20070325 found [Trojan.Delphi.Downloader.Gen]

[ notes ]
packers: NSPACK
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that
are deemed suspicious through heuristics.
So, be careful of this malware and start deleting the testimonials/messages etc.
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)

Last edited by phreak0ut; 25-03-2007 at 08:35 PM.
phreak0ut is offline  
Old 25-03-2007, 07:13 PM   #6 (permalink)
Human Spambot
 
Cool G5's Avatar
 
Join Date: Aug 2006
Location: Aamchi Mumbai !!!
Posts: 4,227
Post Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

I also got a testimonial from my friend in some unknown language.It was also similar to the above posted one.He also is sure that he did not send it.
__________________
ShutterTux - Photography, Linux & Life! : http://shuttertux.wordpress.com
Cool G5 is offline  
Old 25-03-2007, 07:19 PM   #7 (permalink)
Google Bot
 
Pathik's Avatar
 
Join Date: Aug 2005
Posts: 9,772
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

all this has been happening since long back... did no1 of u know this???... just ignore/delete such msgs/testi/scraps...
Pathik is offline  
Old 25-03-2007, 07:27 PM   #8 (permalink)
Wise Old Owl
 
Tech Geek's Avatar
 
Join Date: Sep 2006
Location: Cyber Hell
Posts: 1,602
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

even i recieve it once a weeek
just ignore it and delete it
__________________
Behind every good computer... is a jumble of wires 'n stuff
Tech Geek is offline  
Old 25-03-2007, 08:12 PM   #9 (permalink)
Human Spambot
 
Kiran.dks's Avatar
 
Join Date: Apr 2006
Location: Pune, India
Posts: 2,501
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

I have received many such scraps. But this is the first time it came as a testimonial using my friend ID. Many others might come across this in future. Please see that you don't click on such links.

Thanks to phreak0utt for posting the report here. I too sent it to VirusTotal earlier this evening. Still waiting for the report.

This does throw some light on the capabilities of AntiVirus Products.....
Avast! and AVG has found nothing....now that's strange considering the popularity of these too antivirus products.
AntiVir, the less popular one has detected it.
__________________
Kiran Kumar R
Kiran.dks is offline  
Old 25-03-2007, 08:18 PM   #10 (permalink)
ToTheBeatOfUrHeart
 
Harvik780's Avatar
 
Join Date: Feb 2006
Location: Boston,Newyork
Posts: 1,882
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Ya,thanks for the update.I have been using avast for quiet a while but this has made me think again on searching for better protection.
Harvik780 is offline  
Old 26-03-2007, 12:17 PM   #11 (permalink)
ax3
Cool as a CUCUMBAR ! ! !
 
ax3's Avatar
 
Join Date: Dec 2003
Posts: 5,052
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

just DELETE it ! ! !
ax3 is offline  
Old 26-03-2007, 07:07 PM   #12 (permalink)
Right Off the Assembly Line
 
Join Date: Oct 2006
Posts: 5
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

you idot lol thats a porn bot who wants to kill you ya i mean it its porn bot which is a infilitration in design. go it ? or am i too technical . its a virus or a trojan written by some idiot (Custom made)

**** the intelligent me download this shidd from some orkut freind who was given a testimonial by some fake Orkut ID one pc in RWW is infected by virus because of me and the dont know. the virus was some file - like pic.jpg.exe

Last edited by neilsequeira; 26-03-2007 at 07:07 PM. Reason: Automerged Doublepost
neilsequeira is offline  
Old 26-03-2007, 08:19 PM   #13 (permalink)
Human Spambot
 
Kiran.dks's Avatar
 
Join Date: Apr 2006
Location: Pune, India
Posts: 2,501
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Quote:
Originally Posted by neilsequeira
you idot lol thats a porn bot who wants to kill you ya i mean it its porn bot which is a infilitration in design. go it ? or am i too technical . its a virus or a trojan written by some idiot (Custom made)

**** the intelligent me download this shidd from some orkut freind who was given a testimonial by some fake Orkut ID one pc in RWW is infected by virus because of me and the dont know. the virus was some file - like pic.jpg.exe
Do u have any kind of forum ethics? I have seen u always barking and messing up here. Your act against some of our reputed members has been very rude and senseless. Learn some ethics and enter the technical forum.
__________________
Kiran Kumar R
Kiran.dks is offline  
Old 26-03-2007, 08:24 PM   #14 (permalink)
Human Spambot
 
shantanu's Avatar
 
Join Date: Dec 2006
Posts: 2,798
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

r u sure its in portugese..
shantanu is offline  
Old 26-03-2007, 08:33 PM   #15 (permalink)
Human Spambot
 
Kiran.dks's Avatar
 
Join Date: Apr 2006
Location: Pune, India
Posts: 2,501
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Yes. I am sure it is portugese. Hence the translation...
__________________
Kiran Kumar R
Kiran.dks is offline  
Old 26-03-2007, 09:06 PM   #16 (permalink)
Still in war with allies
 
ssdivisiongermany1933's Avatar
 
Join Date: Jan 2006
Location: Nuremberg trial court
Posts: 539
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

I have stopped using orkut , waste of time
ssdivisiongermany1933 is online now  
Old 26-03-2007, 09:44 PM   #17 (permalink)
Wise Old Owl
 
Tech.Masti's Avatar
 
Join Date: Dec 2005
Location: ( 22.2° N, 88.2° E )
Posts: 1,507
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Thanks for the information friends.....
Tech.Masti is offline  
Old 26-03-2007, 10:00 PM   #18 (permalink)
The Thread Killer >:)
 
phreak0ut's Avatar
 
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

@Kiran-Thanks a lot for the translation. I posted the report in such excitement that I overlooked whatever was posted before. Thanks for letting us all know. Dunno what these guys get by sending such malwares. Well, I'm safe on linux
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)
phreak0ut is offline  
Old 26-03-2007, 10:10 PM   #19 (permalink)
TooR
 
alok4best's Avatar
 
Join Date: Dec 2006
Location: 192.168.1.100
Posts: 519
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Quote:
Originally Posted by neilsequeira
you idot lol thats a porn bot who wants to kill you ya i mean it its porn bot which is a infilitration in design. go it ? or am i too technical . its a virus or a trojan written by some idiot (Custom made)

**** the intelligent me download this shidd from some orkut freind who was given a testimonial by some fake Orkut ID one pc in RWW is infected by virus because of me and the dont know. the virus was some file - like pic.jpg.exe
Is this Guy trying to act smart..Dude get a life...this is not yahoo chat where u can use chat lingos..whatever u want to say,write in human readable form. ,if u can write simple English at all...and dont think u r ultimate geek ever born on Earth..
__________________
I wish !!
alok4best is offline  
Old 26-03-2007, 11:11 PM   #20 (permalink)
Human Spambot
 
Kiran.dks's Avatar
 
Join Date: Apr 2006
Location: Pune, India
Posts: 2,501
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

BTW, here are details of the trojan.
It is a new one discovered on 04/01/2007. Avast! and AVG are not fast in providing rapid updates I guess...they missed the trojan.

So friends, be careful. It is a new one. Most paid versions are detecting it. But not all of free antivirus versions.

Name: TR/Drop.Delf.YX detected as TR/Delphi.Downloader.Gen by AntiVir
Date discovered: 04/01/2007
Type: Trojan
Subtype: Dropper
In the wild: No
Reported Infections: Low
Distribution Potential: Low
Damage Potential: Low to medium
Static file: Yes
File size: 109.056 Bytes
MD5 checksum: 7084ec1ce75b6a3521df3e224d5421c7
VDF version: 6.35.01.100 - Wed, 16 Aug 2006 09:57 (GMT+1)
IVDF version: 6.35.01.101

Aliases:
• Kaspersky: Trojan-Dropper.Win32.Delf.yx
• Sophos: Troj/Delf-DKS
• Grisoft: Dropper.Generic.GKO
• Eset: Win32/TrojanDropper.Delf.YX
• Bitdefender: Trojan.Downloader.Delf.ST

Programming language:
The malware program was written in Delphi.

More Details
__________________
Kiran Kumar R
Kiran.dks is offline  
Old 27-03-2007, 12:24 AM   #21 (permalink)
Alpha Geek
 
Maverick340's Avatar
 
Join Date: Mar 2004
Posts: 635
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Yep . This happened to two of my friends too. The main problem is how are the accounts being hacked? This is a very grave problem. As users keep trying to reprot instances of Account being Hacked to Google using the contact us page on orkut.
__________________
You and Me forever be ...
--
PSpwned
Maverick340 is offline  
Old 27-03-2007, 12:33 AM   #22 (permalink)
TooR
 
alok4best's Avatar
 
Join Date: Dec 2006
Location: 192.168.1.100
Posts: 519
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Accounts are being hacked because their respective owners are not alert.U cud be using a Comp on which Keylogger is installed..or u can be a victim of phising,fake web pages,trojans,viruses..etc etc...
__________________
I wish !!
alok4best is offline  
Old 27-03-2007, 12:40 AM   #23 (permalink)
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Always be caredul when using links from tinyurl, snipurl, urlcut and such. If possible ask the person who sent you the link, if that link has been actually sent by them and what it points to and maybe even ask for original link rather. These url snipping services have been misused a lot.
__________________
http://www.bash.org/?258908
mehulved is offline  
Old 27-03-2007, 11:08 AM   #24 (permalink)
ax3
Cool as a CUCUMBAR ! ! !
 
ax3's Avatar
 
Join Date: Dec 2003
Posts: 5,052
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

1 good lesson 2 b learnt : NEVER PUBLISIZE UR ORKUT ID .......


whot say ppl ?
ax3 is offline  
Old 27-03-2007, 11:13 AM   #25 (permalink)
Google Bot
 
Pathik's Avatar
 
Join Date: Aug 2005
Posts: 9,772
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Quote:
Originally Posted by tech_your_future
Always be caredul when using links from tinyurl, snipurl, urlcut and such. If possible ask the person who sent you the link, if that link has been actually sent by them and what it points to and maybe even ask for original link rather. These url snipping services have been misused a lot.
these links r not cloaked...
even if u click on them than after some time wen the page just starts to load u can see the original url in the status bar..
Pathik is offline  
Old 27-03-2007, 12:17 PM   #26 (permalink)
101101
 
Join Date: Nov 2006
Location: 10110
Posts: 139
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

its a spam ya...
__________________
Finding answers is simple, all you need to do is come up with the correct questions.
crystal_pup is offline  
Old 27-03-2007, 05:21 PM   #27 (permalink)
Alpha Geek
 
Maverick340's Avatar
 
Join Date: Mar 2004
Posts: 635
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

Quote:
Originally Posted by alok4best
Accounts are being hacked because their respective owners are not alert.U cud be using a Comp on which Keylogger is installed..or u can be a victim of phising,fake web pages,trojans,viruses..etc etc...
Nahi yaar. These tow friends of mine arent simpletons. They wouldn't have left passwords astray. Theres is something more to it .
__________________
You and Me forever be ...
--
PSpwned
Maverick340 is offline  
Old 14-04-2007, 11:55 AM   #28 (permalink)
Right Off the Assembly Line
 
Join Date: Oct 2006
Posts: 5
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

about forum ethics you people should learn what you are doing. i dont want to speak more. i seen the whole forum and this thing has not helped me in anything. i am sorry for this but i am quitting
neilsequeira is offline  
Old 30-04-2007, 12:27 AM   #29 (permalink)
K750
Guest
 
Posts: n/a
Default Re: WARNING: Orkut ID Hacked and Testimonial written in some language...!!

i never recieved such things , since i joined orkut
 
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by gohan89
- by Sujeet
- by Tenida
- by iinfi
- by icebags
- by gohan89

Advertisement




All times are GMT +5.5. The time now is 09:25 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2