With the advent of social networking, numerous websites have made
their foray into this sector with each providing a unique way to
help you to connect with your friends, families and other
professionals from the fields of your interest. Various features
are made available to the end-users that may include the ability to
find out who has viewed your profile. However, not every social
networking site provides this feature, especially Facebook.
On numerous instances, as a Facebook user, we find posts or
applications which claim that they can help you to find –
“Who has visited your profile”,
“What is your Death Date”. However, do we ever
give a thought that how genuine are these claims or what exactly is
perpetrated using these apps?
Nonetheless, whatever might be the outcome, since Facebook does not
provide this feature, then anything woven around the APIs of
Facebook in order to provide such features need to be scrutinized
more closely and warrants an investigation, especially when these
applications are presented as if Facebook has developed these for
its users.
During the course of our investigation, we, at eScan, came across
more than 1000 registered domains, 1400+ free domains and 20+ IP
servers that served/processed the content and were a part of the
infrastructure for this entire operation. The first domain was
registered as on 2012-07-18, which was approximately a year
ago.
Now, we were curious to find out the identity of the entire team
behind this campaign and decided to name this operation as
“#ItsPartyParty”, based on the online status update of
the first person who was tracked down and is a part of the
team.
During the research, it was still unknown about the exact usage of
the Facebook API (Application Programming Interface) and its
security implications. However, in the late stages of investigation
eScan Research Team came across a server which hosted a recently
registered domain.
Moreover, it was also detected that this same team of cyber
criminals was involved in deploying Facebook related phishing
pages, with the sole intention of stealing login credentials.
However, the number of phishing attempts was far too less when
compared to ProfileVisitor based infections. Due to voluminous
nature of the data coupled with various other factors, it was
virtually impossible for us to find each and every phishing
attempt. Hence, the eScan research team stopped the manual process
of gathering phishing evidence after processing 50 records and
finding two phishing domains. Moreover, during the research we
observed that the frequency at which domains and servers are being
changed without changing the overall logic of the application, as
well as the naming convention of these domains is highly
suspicious.
Business Logic
While going through the code
and observing the usage of regular Facebook API, it was amply clear
that serving of advertisements is one of the primary business logic
of this team. Along with the advertising revenue, the said FaceBook
apps also had access to the message inbox of its victims. Secondly,
due to existence of a few phishing domains and their subsequent
blockade is good enough evidence to prove the malicious intent of
those involved.
Conclusion
The only aspect of Facebook
which is completely hidden from anyone’s view are your inbox
messages and this app gains access to this very thing, which
otherwise would have required a legitimate username and password.
What do they gain by accessing the FB inbox messages is one
question, we will leave for you and the investigating agencies to
ponder upon. Second question is for Facebook –
shouldn’t apps and the existing app API Privileges, be
verified and scrutinized?
The task of the researchers is limited to conducting the research
and informing various organizations about the same. However,
hosting service providers / domain registrars play a pivotal role
in mitigating these threats by initiating preventive measures
against these domains and servers. The role of law enforcement
agencies is to track and take to task those who are responsible for
these nefarious acts. Inactive participation from any of these
organizations effectively decreases the impact and allows the
perpetrators to continue doing their activities.
The complete research can be accessed
here
Note:
• PublicDomainRegistry (PDR) responded to our report and
took preventive action against the erring domains. This action by
PDR resulted in suspension of 700+ domains. Also, CERT-In has been
notified and they are investigating; however at the time of writing
this, we were yet to receive any formal communication from Aust
Domains, CERT-AU and Can-CERT. Also the servers associated with
these IP addresses and few of the domains belonging to AustDomains
are still active.
• In addition to this a new version of the binary has also
been uploaded on one of the malicious servers, at the time of
writing.
– The author is MD CEO, eScan
