{"id":154,"date":"2014-05-02T13:53:13","date_gmt":"2014-05-02T13:53:13","guid":{"rendered":"http:\/\/www.xlabs.com.br\/blog\/?p=154"},"modified":"2021-08-27T11:53:25","modified_gmt":"2021-08-27T14:53:25","slug":"suposto-whats-app-para-windows-se-trata-de-um-malware","status":"publish","type":"post","link":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/","title":{"rendered":"Suposto Whats-App para Windows se trata de um malware"},"content":{"rendered":"\n<p>Recentemente percebemos uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do Whats-App para Windows.<\/p>\n\n\n\n<p>O analista ao verificar mais detalhadamente a proposta de download de uma nova ferramenta de chat para computadores com Windows, verificou que n\u00e3o se tratava de um download genu\u00edno, assim enviando o artefato para os sistemas da <a href=\"https:\/\/www.xlabs.com.br\/\" target=\"_blank\" rel=\"noreferrer noopener\">XLabs<\/a> para uma an\u00e1lise din\u00e2mica e mais detalhada do artefato suspeito encontrado.<\/p>\n\n\n\n<p>Como podemos perceber, mais de 4 mil pessoas j\u00e1 curtiram a p\u00e1gina do Facebook que cont\u00e9m os links maliciosos em apenas 20 horas de cria\u00e7\u00e3o da p\u00e1gina.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter is-resized\"><a href=\"\/blog\/wp-content\/uploads\/2014\/05\/Wats-App_Malware.jpg\"><img decoding=\"async\" src=\"\/blog\/wp-content\/uploads\/2014\/05\/Wats-App_Malware-300x202.jpg\" alt=\"Wats-App_Malware\" class=\"wp-image-155\" width=\"523\" height=\"352\" srcset=\"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/Wats-App_Malware-300x202.jpg 300w, https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/Wats-App_Malware.jpg 888w\" sizes=\"(max-width: 523px) 100vw, 523px\" \/><\/a><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter is-resized\"><a href=\"\/blog\/wp-content\/uploads\/2014\/05\/Whats-App_horas.jpg\"><img decoding=\"async\" src=\"\/blog\/wp-content\/uploads\/2014\/05\/Whats-App_horas-300x239.jpg\" alt=\"Whats-App_horas\" class=\"wp-image-160\" width=\"525\" height=\"418\" srcset=\"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/Whats-App_horas-300x239.jpg 300w, https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/Whats-App_horas.jpg 663w\" sizes=\"(max-width: 525px) 100vw, 525px\" \/><\/a><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>Os links maliciosos levam as vitimas a baixarem um arquivo zip contendo o execut\u00e1vel, que se trata de um Trojan Banker.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter is-resized\"><a href=\"\/blog\/wp-content\/uploads\/2014\/05\/Wats-App_Malware_Website.jpg\"><img decoding=\"async\" src=\"\/blog\/wp-content\/uploads\/2014\/05\/Wats-App_Malware_Website-300x157.jpg\" alt=\"Wats-App_Malware_Website\" class=\"wp-image-157\" width=\"532\" height=\"278\"\/><\/a><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>O resultado da an\u00e1lise de nossas ferramentas no artefato, pode ser encontrado sob o protocolo <a href=\"http:\/\/thorweb.xlabs.com.br\/ThorWeb\/resultado.jsp?protocolo=09028B7C1F7A88EEB3E3AA09722960C9\" target=\"_blank\" rel=\"noopener noreferrer\">09028B7C1F7A88EEB3E3AA09722960C9<\/a><\/p>\n\n\n\n<p>Para auxiliar e evitar a infec\u00e7\u00e3o de computadores na rede de sua empresa, recomendamos que fa\u00e7am o bloqueio em seus firewall&#8217;s aos dom\u00ednios e IP&#8217;s que possuem liga\u00e7\u00f5es com o malware:<br><strong>whatsapp2014.org<br>mtez.de<br>200.98.201.18<\/strong><\/p>\n\n\n\n<p>A equipe da <a href=\"https:\/\/www.xlabs.com.br\/\" target=\"_blank\" rel=\"noreferrer noopener\">XLabs<\/a> est\u00e1 pronta para prestar suporte a desinfec\u00e7\u00e3o deste malware aos nossos clientes atrav\u00e9s de nosso atendimento.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recentemente percebemos uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do Whats-App para Windows. O analista ao verificar mais detalhadamente a proposta de download de uma nova ferramenta de chat para computadores com Windows, verificou que n\u00e3o se tratava de um download genu\u00edno, assim enviando o artefato para os [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1687,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Suposto Whats-App para Windows \u00e9 um malware &ndash; XLabs Security Blog<\/title>\n<meta name=\"description\" content=\"Uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do suposto Whats-App para Windows \u00e9 um malware\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Suposto WhatsApp para Windows \u00e9 um malware &ndash; XLabs Security Blog\" \/>\n<meta property=\"og:description\" content=\"Recentemente percebemos uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do Whats-App para Windows.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"XLabs Security Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/xlabs\" \/>\n<meta property=\"article:published_time\" content=\"2014-05-02T13:53:13+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-27T14:53:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/suposto-whats-app-para-windows-se-trata-de-um-malware-blog-post-xlabs.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"488\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Mauricio Corr\u00eaa\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Suposto WhatsApp para Windows \u00e9 um malware &ndash; XLabs Security Blog\" \/>\n<meta name=\"twitter:description\" content=\"Recentemente percebemos uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do Whats-App para Windows.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/suposto-whats-app-para-windows-se-trata-de-um-malware-blog-post-xlabs.png\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mauricio Corr\u00eaa\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/\"},\"author\":{\"name\":\"Mauricio Corr\u00eaa\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/person\/7d0839d8f5b967c3daa45aa01f3fdd3d\"},\"headline\":\"Suposto Whats-App para Windows se trata de um malware\",\"datePublished\":\"2014-05-02T13:53:13+00:00\",\"dateModified\":\"2021-08-27T14:53:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/\"},\"wordCount\":220,\"publisher\":{\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#organization\"},\"articleSection\":[\"Casos de Seguran\u00e7a\"],\"inLanguage\":\"pt-BR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/\",\"url\":\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/\",\"name\":\"Suposto Whats-App para Windows \u00e9 um malware &ndash; XLabs Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#website\"},\"datePublished\":\"2014-05-02T13:53:13+00:00\",\"dateModified\":\"2021-08-27T14:53:25+00:00\",\"description\":\"Uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do suposto Whats-App para Windows \u00e9 um malware\",\"breadcrumb\":{\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"In\u00edcio\",\"item\":\"https:\/\/www.xlabs.com.br\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Suposto Whats-App para Windows se trata de um malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#website\",\"url\":\"https:\/\/www.xlabs.com.br\/blog\/\",\"name\":\"XLabs Security Blog\",\"description\":\"Seguran\u00e7a da Informa\u00e7\u00e3o\",\"publisher\":{\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.xlabs.com.br\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#organization\",\"name\":\"XLabs Security\",\"url\":\"https:\/\/www.xlabs.com.br\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2020\/11\/Logotipo.png\",\"contentUrl\":\"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2020\/11\/Logotipo.png\",\"width\":478,\"height\":168,\"caption\":\"XLabs Security\"},\"image\":{\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.instagram.com\/xlabs.security\",\"https:\/\/www.linkedin.com\/company\/xlabs-security\/\",\"https:\/\/www.youtube.com\/channel\/UCPbGDmCQI7_UcAPmvVLi58g?view_as=subscriber\",\"https:\/\/www.facebook.com\/xlabs\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/person\/7d0839d8f5b967c3daa45aa01f3fdd3d\",\"name\":\"Mauricio Corr\u00eaa\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f0734e5fb6afc04d038e66cae478a8a0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f0734e5fb6afc04d038e66cae478a8a0?s=96&d=mm&r=g\",\"caption\":\"Mauricio Corr\u00eaa\"},\"url\":\"https:\/\/www.xlabs.com.br\/blog\/author\/mauricio-correa\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Suposto Whats-App para Windows \u00e9 um malware &ndash; XLabs Security Blog","description":"Uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do suposto Whats-App para Windows \u00e9 um malware","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/","og_locale":"pt_BR","og_type":"article","og_title":"Suposto WhatsApp para Windows \u00e9 um malware &ndash; XLabs Security Blog","og_description":"Recentemente percebemos uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do Whats-App para Windows.","og_url":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/","og_site_name":"XLabs Security Blog","article_publisher":"https:\/\/www.facebook.com\/xlabs","article_published_time":"2014-05-02T13:53:13+00:00","article_modified_time":"2021-08-27T14:53:25+00:00","og_image":[{"width":1000,"height":488,"url":"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/suposto-whats-app-para-windows-se-trata-de-um-malware-blog-post-xlabs.png","type":"image\/png"}],"author":"Mauricio Corr\u00eaa","twitter_card":"summary_large_image","twitter_title":"Suposto WhatsApp para Windows \u00e9 um malware &ndash; XLabs Security Blog","twitter_description":"Recentemente percebemos uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do Whats-App para Windows.","twitter_image":"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2014\/05\/suposto-whats-app-para-windows-se-trata-de-um-malware-blog-post-xlabs.png","twitter_misc":{"Escrito por":"Mauricio Corr\u00eaa","Est. tempo de leitura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/#article","isPartOf":{"@id":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/"},"author":{"name":"Mauricio Corr\u00eaa","@id":"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/person\/7d0839d8f5b967c3daa45aa01f3fdd3d"},"headline":"Suposto Whats-App para Windows se trata de um malware","datePublished":"2014-05-02T13:53:13+00:00","dateModified":"2021-08-27T14:53:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/"},"wordCount":220,"publisher":{"@id":"https:\/\/www.xlabs.com.br\/blog\/#organization"},"articleSection":["Casos de Seguran\u00e7a"],"inLanguage":"pt-BR"},{"@type":"WebPage","@id":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/","url":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/","name":"Suposto Whats-App para Windows \u00e9 um malware &ndash; XLabs Security Blog","isPartOf":{"@id":"https:\/\/www.xlabs.com.br\/blog\/#website"},"datePublished":"2014-05-02T13:53:13+00:00","dateModified":"2021-08-27T14:53:25+00:00","description":"Uma campanha publicit\u00e1ria de links patrocinados no Facebook de uma ferramenta, que se trataria do suposto Whats-App para Windows \u00e9 um malware","breadcrumb":{"@id":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.xlabs.com.br\/blog\/suposto-whats-app-para-windows-se-trata-de-um-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"In\u00edcio","item":"https:\/\/www.xlabs.com.br\/blog\/"},{"@type":"ListItem","position":2,"name":"Suposto Whats-App para Windows se trata de um malware"}]},{"@type":"WebSite","@id":"https:\/\/www.xlabs.com.br\/blog\/#website","url":"https:\/\/www.xlabs.com.br\/blog\/","name":"XLabs Security Blog","description":"Seguran\u00e7a da Informa\u00e7\u00e3o","publisher":{"@id":"https:\/\/www.xlabs.com.br\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.xlabs.com.br\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/www.xlabs.com.br\/blog\/#organization","name":"XLabs Security","url":"https:\/\/www.xlabs.com.br\/blog\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2020\/11\/Logotipo.png","contentUrl":"https:\/\/www.xlabs.com.br\/blog\/wp-content\/uploads\/2020\/11\/Logotipo.png","width":478,"height":168,"caption":"XLabs Security"},"image":{"@id":"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.instagram.com\/xlabs.security","https:\/\/www.linkedin.com\/company\/xlabs-security\/","https:\/\/www.youtube.com\/channel\/UCPbGDmCQI7_UcAPmvVLi58g?view_as=subscriber","https:\/\/www.facebook.com\/xlabs"]},{"@type":"Person","@id":"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/person\/7d0839d8f5b967c3daa45aa01f3fdd3d","name":"Mauricio Corr\u00eaa","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/www.xlabs.com.br\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f0734e5fb6afc04d038e66cae478a8a0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f0734e5fb6afc04d038e66cae478a8a0?s=96&d=mm&r=g","caption":"Mauricio Corr\u00eaa"},"url":"https:\/\/www.xlabs.com.br\/blog\/author\/mauricio-correa\/"}]}},"_links":{"self":[{"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/posts\/154"}],"collection":[{"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/comments?post=154"}],"version-history":[{"count":13,"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/posts\/154\/revisions"}],"predecessor-version":[{"id":1686,"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/posts\/154\/revisions\/1686"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/media\/1687"}],"wp:attachment":[{"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/media?parent=154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/categories?post=154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.xlabs.com.br\/blog\/wp-json\/wp\/v2\/tags?post=154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}