{"id":867,"date":"2011-02-24T16:02:28","date_gmt":"2011-02-24T07:02:28","guid":{"rendered":"http:\/\/www.joewein.net\/blog\/?p=867"},"modified":"2011-02-26T08:31:16","modified_gmt":"2011-02-25T23:31:16","slug":"the-find-your-stalkers-scam","status":"publish","type":"post","link":"https:\/\/joewein.net\/blog\/2011\/02\/24\/the-find-your-stalkers-scam\/","title":{"rendered":"The &#8220;Find your stalkers&#8221; Facebook scam"},"content":{"rendered":"<p>Today I received a strange Facebook message. Supposedly one of my friends (an old classmate of mine in Germany) had posted on my wall, but the posting was in English. Now this German friend, unless he happens to forward me an English joke, always writes to me in German. There were several of these wall posts (please DO NOT CLICK on those links!):<\/p>\n<blockquote><p>\n23 February at 17:35:<br \/>\nAccording to http:\/\/goo.gl\/6hr4J you&#8217;re my top stalker. Creep.<\/p>\n<p>23 February at 17:35:<br \/>\nSecret tool shows who stalks your pics http:\/\/tinyurl.com\/procreeper<\/p>\n<p>23 February at 17:35:<br \/>\nHey! This is awesome<br \/>\nInsane! Awesome tool to see who looks at your pics >> http:\/\/goo.gl\/XsUqi<\/p>\n<p>23 February at 17:35:<br \/>\nHey! This is awesome<br \/>\nNew FB tool shows who stalks your profile&#8211; http:\/\/goo.gl\/FTx5T<\/p>\n<p>23 February at 17:43:<br \/>\nHey, whats happening?<br \/>\nSecret tool shows who stalks your pics http:\/\/goo.gl\/DxvMD\n<\/p><\/blockquote>\n<p>So I contacted my friend and asked him if it was really him who&#8217;d written that or if his facebook account had been hacked. He replied that he wasn&#8217;t him.<\/p>\n<p>I investigated the links, which use the Google URL shortening service to hide the<br \/>\ntarget URL:<\/p>\n<p>tinyurl.com\/procreeper => procreeper.info<br \/>\ngoo.gl\/6hr4J => theprochecker.info\/?h<br \/>\ngoo.gl\/DxvMD => myprochecker.info\/?i<br \/>\ngoo.gl\/FTx5T => procheckers.info\/?e<br \/>\ngoo.gl\/XsUqi => theprochecker.info\/?b<\/p>\n<p>Domains procreeper.info, myprochecker.info, procheckers.info and theprochecker.info are all hosted at the same IP address (98.126.9.210, <a href=\"http:\/\/www.google.com\/search?q=%22Krypt+Technologies%22+scam\">Krypt Technologies<\/a>) and use the same name servers (ns1.imgurnot.com, ns2.imgurnot.com). The registrant is hidden behind a WHOIS proxy. The reverse DNS name of the host is &#8220;<a href=\"http:\/\/www.ip-adress.com\/whois\/wowchatroulette.info\">wowchatroulette.info<\/a>&#8220;.<\/p>\n<p>Here are other domains that appear connected to these domains (this is probably just the tip of the iceberg):<\/p>\n<ul>\n<li>fb-creeper.info<\/li>\n<li>fb-creeper.info<\/li>\n<li>fbcheckers.info<\/li>\n<li>fbcheckersnow.info<\/li>\n<li>fbcreeper.info<\/li>\n<li>fbcreeper.info<\/li>\n<li>fbcreeperonline.info<\/li>\n<li>fbcreeperonline.info<\/li>\n<li>fbcreepers.info<\/li>\n<li>fbcreepers.info<\/li>\n<li>fbisfun.info<\/li>\n<li>fbpromo.info<\/li>\n<li>myfbcheckers.info<\/li>\n<li>myprocreeper.info<\/li>\n<li>newfbcheckers.info<\/li>\n<li>omgfbisfun.info<\/li>\n<li>procreep.info<\/li>\n<li>procreeper.info<\/li>\n<li>procreeperonline.info<\/li>\n<li>procreepers.info<\/li>\n<li>profilechecker.info<\/li>\n<li>profileseek.info<\/li>\n<li>profilespy.info<\/li>\n<li>profileview.info<\/li>\n<li>profileviewers.info<\/li>\n<li>thefbcheckers.info<\/li>\n<li>thefbcreeper.info<\/li>\n<li>thefbcreeper.info<\/li>\n<\/ul>\n<p>These sites have messages such as:<\/p>\n<blockquote><p>Find YOUR Stalkers<\/p>\n<p>Find out who spends excessive time with your photos, reading your old wall posts, and looking at your friends list.\n<\/p><\/blockquote>\n<p>This is a scam designed to trick people into running a script on Facebook that will have a message sent to all their Facebook friends and to get them to also visit such websites. Anti-malware site <a href=\"http:\/\/about-threats.trendmicro.com\/Malware.aspx?language=us&#038;name=HTML_FBSPAM.ASM\">TrendMicro warns<\/a>:<\/p>\n<blockquote><p>Malware type : Spyware<br \/>\nDestructive : No<br \/>\nPlatform : Windows 2000, XP, Server 2003<br \/>\nEncrypted : Yes<br \/>\nIn the wild : Yes<\/p>\n<p>This malware uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed. Specifically, it poses as a Facebook stalker finder to be able to infect Facebook user accounts<\/p>\n<p>(&#8230;)<\/p>\n<p>This malware may be hosted on websites that run a malicious script when accessed by unsuspecting users.<\/p>\n<p>It poses as a legitimate Facebook application. It propagates by sending IMs and status messages with links to websites where it can be downloaded.<\/p>\n<p>This spyware executes when a user accesses certain websites where it is hosted.\n<\/p><\/blockquote>\n<p>See also this <a href=\"http:\/\/blog.trendmicro.com\/facebook-stalker-tracker-tool-turns-users-into-spammers\/?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+Anti-MalwareBlog+%28Trend+Micro+Malware+Blog%29\">TrendMicro blog post<\/a> on the subject.<\/p>\n<p>If you have received wall posts like that in the name of a friend, click on the X to the right of the posts to delete them and alert your friend! Do not click on any of the links in the malicious posts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today I received a strange Facebook message. Supposedly one of my friends (an old classmate of mine in Germany) had posted on my wall, but the posting was in English. Now this German friend, unless he happens to forward me &hellip; <a href=\"https:\/\/joewein.net\/blog\/2011\/02\/24\/the-find-your-stalkers-scam\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21,2],"tags":[],"class_list":["post-867","post","type-post","status-publish","format-standard","hentry","category-scams","category-spam"],"_links":{"self":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/comments?post=867"}],"version-history":[{"count":13,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/867\/revisions"}],"predecessor-version":[{"id":873,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/867\/revisions\/873"}],"wp:attachment":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/media?parent=867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/categories?post=867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/tags?post=867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}