Malicious Web Attack Using Executable With facebook.com in Name
As we were working through URLs identified as suspicious due to our GTI technology, one of the URLs that presented itself was an average ā.comā site that loaded a php. As we processed this ā it was interesting to see that this php actually reached out to download a file that ended with the string facebook.com.exe ā as this ā.comā site was very social-network friendly ā it would be easy to see how an average user, without web protection in place, would not even realize what was going on. ...