This report, which is based upon information from law enforcement and complaints
submitted to the IC3, details recent cyber crime trends and new twists to previously-existing
cyber scams.
Social Network Misspelling Scam
During December 2010, the IC3 discovered misspellings of a social network site being
used as a social engineering ploy. Misspelling the domain name of this site would
redirect users to websites coded to look similar to the actual website. The website
users were redirected to answer three or four simple survey questions. Upon answering
those questions, users were offered a choice of three free gifts. Multiple brands
were observed as being offered as gifts, including gift cards to retail stores and
various brands of laptops.
After clicking on one of the gifts, users were further redirected to other websites
claiming to give free gifts for completing surveys. The surveys typically asked
for name, address, phone number, and e-mail address. A user could spend hours filling
out multiple surveys and never receive any of the gifts advertised.
Fake Online Receipt Generator Targets Unsuspecting Online Marketplace Merchant
A new scam aims to swindle online marketplace sellers by generating fake receipts.
This Receipt Generator is an executable file that has been circulating on hacking
forums recently. This is a particularly interesting scam - because it does not target
regular PC users, it targets the sellers on online marketplace websites. This is
what the would-be social engineer sees when running the program:
The social engineer can fill in a variety of information, including item name, price,
and the date the order was taken. Additionally, it allows them to choose between
the .com, .co.uk, .fr, and .ca marketplace portals. When they hit "Generate," an
HTML file is created in the program folder which looks like this:
The program produces what appears to be a genuine marketplace receipt and a copy
of the "Printable Order Summary," similar to the documents resulting from legitimate
marketplace purchases. Note the small details, such as "Total before tax," "Sales
tax," and other particulars that make the receipt convincing.
Many sellers on these markets will ask the buyer to send them a copy of the receipt
should the buyer run into trouble, have orders go missing, lose the license key
for a piece of software, and so on. The scammer relies on the seller to accept the
printout at face value without checking the details. After all, how many sellers
would be aware someone went to the trouble of creating a fake receipt generator?
Sellers must remain ever vigilant about this scam, which has been a popular topic
in recent hacker forums. The VirusTotal detection rate is currently 1/43 – detected as Hacktool.Win32.Amagen.A.
Malicious Code In .gov E-mail
A recent malware campaign, disguised as a holiday greeting from the White House,
targeted government employees. The recipient received the below e-mail with links
to what masqueraded as a greeting card, but when they clicked on the link, it attempted
to download a file named "card.exe." The executable program proved to be an information-stealing
Trojan, which would disable the recipient’s computer security notifications, software
updates, and firewall settings. The malware also installed itself into the computer’s
registry, enabling the code to be executed every time the computer was rebooted.
At the time of review, this particular malicious code sample had a low antivirus
detection rate of 20%, with only 9 out of 43 antivirus companies reporting detection.
From: sender@whitehouse.gov [mailto: sender@whitehouse.gov]
Sent: Wednesday, December 22, 2010 10:33 PM
To: recipient's name
Subject: Merry Christmas, recipient's name
Recipient’s name here,
As you and your families gather to celebrate the holidays, we wanted to take a moment
to send you our greetings. Be sure that we're profoundly grateful for your dedication
to duty and wish you inspiration and success in fulfillment of our core mission.
Greeting card:
hxxp://xtremedefenceforce.com/card/
hxxp://elvis.com.au/card/
Merry Christmas!
___________________________________________
Executive Office of the President of the United States
The White House
1600 Pennsylvania Avenue NW
Washington, DC 20500
Source: FBI, February 2011
-----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG @FayetteFP
Showing posts with label fake. Show all posts
Showing posts with label fake. Show all posts
Monday, February 14, 2011
Tuesday, January 11, 2011
Christmas and Holiday Sales Were Attack Targets According to December Top 10 Malware List
(BUSINESS WIRE)--GFI Software, a leading IT solutions provider for small and medium-sized enterprises, today revealed continuing high levels of Trojan and rogue malware circulating during December, with data revealing a surge in activity, boosted by themed activity around the Christmas and New Year holiday period. The top 10 data is compiled from monthly scans performed by GFI's award-winning anti-malware solution, VIPRE® Antivirus, and its antispyware tool, CounterSpy®, as a service of GFI Labs™.
Users were targeted with a variety of infected email, web links and other delivery mechanisms promising festive information, discount offers, Christmas e-cards and free software. The month also saw the big movie release of the season, Disney’s TRON Legacy, targeted by a wide array of SEO poisoned links, unwanted installs and other malware fakery, while a spate of fake iTunes emails caught several people off-guard, resulting in users running afoul of a malicious script that took advantage of a known Java exploit. GFI researchers also uncovered an Amazon receipt generator scam aimed at fooling retailers into honoring fraudulent receipts during the busy holiday shopping season.
December once again saw significant activity from Trojan threats, which continue to dominate the overall malware landscape. Seven of the top 10 malware detections were Trojans, with those seven accounting for almost 35% of all malware detections for the month. In addition to a range of Trojans, Worms also created major problems during December. Most significant was Worm.Win32.Downad.Gen (v), appearing at number seven in December's top 10, a detection for the Downadup worm, otherwise known as Conficker and Kido.
Taking advantage of a vulnerability in Windows Server service which allows remote code execution when file sharing is enabled, the Worm spreads across networks as well as removable drives, taking advantage of weak administrator passwords along the way. It commonly turns off some system services and anti-malcode protection, exposing infected systems to additional infection from other malware.
“Following on from the increased themed threat traffic we saw in November around Thanksgiving, Black Friday and Cyber Monday, criminals once again attempted to take advantage of Christmas and the holiday season with themed attacks designed to drive users towards infected sites and to trick them into opening infected email and executables. Themed attacks, along with themed SEO poisoning and fake application installs, are firmly established as a successful means for malware creators to distribute malcode and create disruption for organizations and families alike,” said Tom Kelchner, communications and research analyst for GFI Software.
“December is a challenging month for computing security, with many businesses shut for a prolonged period and consumers at home for the holidays. Casual computer use rises and vigilance can drop, creating opportunities for malware infection that would otherwise not happen the rest of the year. The top 10 serves as a stark reminder that IT security should not be taken for granted at any time,” Kelchner added.
The problem of fake software was highlighted by FraudTool.Win32.FakeVimes!delf (v), number nine on this month’s top 10. This is a heuristic detection for files associated with the FakeVimes family of rogue security products, illustrating the continued growth of fake and compromised security applications as a means to circulate and covertly install malware onto PCs.
ThreatNet is GFI Lab’s monitoring system that retrieves real-time data from VIPRE installations. Statistics come from tens of thousands of machines running VIPRE.
-----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG @FayetteFP
Users were targeted with a variety of infected email, web links and other delivery mechanisms promising festive information, discount offers, Christmas e-cards and free software. The month also saw the big movie release of the season, Disney’s TRON Legacy, targeted by a wide array of SEO poisoned links, unwanted installs and other malware fakery, while a spate of fake iTunes emails caught several people off-guard, resulting in users running afoul of a malicious script that took advantage of a known Java exploit. GFI researchers also uncovered an Amazon receipt generator scam aimed at fooling retailers into honoring fraudulent receipts during the busy holiday shopping season.
December once again saw significant activity from Trojan threats, which continue to dominate the overall malware landscape. Seven of the top 10 malware detections were Trojans, with those seven accounting for almost 35% of all malware detections for the month. In addition to a range of Trojans, Worms also created major problems during December. Most significant was Worm.Win32.Downad.Gen (v), appearing at number seven in December's top 10, a detection for the Downadup worm, otherwise known as Conficker and Kido.
Taking advantage of a vulnerability in Windows Server service which allows remote code execution when file sharing is enabled, the Worm spreads across networks as well as removable drives, taking advantage of weak administrator passwords along the way. It commonly turns off some system services and anti-malcode protection, exposing infected systems to additional infection from other malware.
“Following on from the increased themed threat traffic we saw in November around Thanksgiving, Black Friday and Cyber Monday, criminals once again attempted to take advantage of Christmas and the holiday season with themed attacks designed to drive users towards infected sites and to trick them into opening infected email and executables. Themed attacks, along with themed SEO poisoning and fake application installs, are firmly established as a successful means for malware creators to distribute malcode and create disruption for organizations and families alike,” said Tom Kelchner, communications and research analyst for GFI Software.
“December is a challenging month for computing security, with many businesses shut for a prolonged period and consumers at home for the holidays. Casual computer use rises and vigilance can drop, creating opportunities for malware infection that would otherwise not happen the rest of the year. The top 10 serves as a stark reminder that IT security should not be taken for granted at any time,” Kelchner added.
The problem of fake software was highlighted by FraudTool.Win32.FakeVimes!delf (v), number nine on this month’s top 10. This is a heuristic detection for files associated with the FakeVimes family of rogue security products, illustrating the continued growth of fake and compromised security applications as a means to circulate and covertly install malware onto PCs.
ThreatNet is GFI Lab’s monitoring system that retrieves real-time data from VIPRE installations. Statistics come from tens of thousands of machines running VIPRE.
Top 10 detections for December | |||||||||||||||||||
| Detection | Type | Percent | |||||||||||||||||
| Trojan.Win32.Generic!BT | Trojan | 21.93 | |||||||||||||||||
| Trojan-Spy.Win32.Zbot.gen | Trojan | 3.79 | |||||||||||||||||
| Trojan.Win32.Generic.pak!cobra | Trojan | 3.14 | |||||||||||||||||
| Trojan.Win32.Generic!SB.0 | Trojan | 2.78 | |||||||||||||||||
| Exploit.PDF-JS.Gen (v) | PDF Exploit | 1.79 | |||||||||||||||||
| INF.Autorun (v) | Trojan | 1.63 | |||||||||||||||||
| Worm.Win32.Downad.Gen (v) | Worm | 1.27 | |||||||||||||||||
| Trojan.ASF.Wimad (v) | Trojan | 0.77 | |||||||||||||||||
| FraudTool.Win32.FakeVimes!delf (v) | Fake App 0.73 | ||||||||||||||||||
| Trojan.Win32.Meredrop | Trojan | 0.72 |
-----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG @FayetteFP
Labels:
christmas,
december,
detections,
fake,
fayette front page,
georgia,
georgia front page,
holiday,
malware,
obama worm,
pc,
trojan,
virus,
web,
windows
Thursday, October 7, 2010
Fake iTunes Bill Can Drain Your Bank Account
The following article is from Eastman's Online Genealogy Newsletter and is copyright by Richard W. Eastman. It is re-published here with the permission of the author. Information about the newsletter is available at http://www.eogn.com.
I received one of these email messages a few days ago. Luckily, Gmail placed it in my spam folder so I didn't see it until today when I went looking for it. You have to hand it to these scam artists: they certainly are clever at devising methods of stealing your money.
I wrote a couple of days ago at http://goo.gl/nvl9 about a "trojan" email message that steals your user IDs and passwords to your online banking account. This new scam is a different Trojan message with a very clever delivery method.
The new scam sends a fake "iTunes receipt" email message to millions of people. The message appears to be completely authentic, except for the price shown in your bill. The message I received was for nearly $1,000. That's part of the trap.
Most people are likely to take action when seeing an "incorrect amount" appear on their bill. (I didn't do that because I never saw the "bill" in my spam folder until I went looking for it later, after reading about the new scam.) Most people will click on the "report a problem" link that is included in the email message. However, that link takes you to a rogue web page that downloads the same Zeus trojan malware as described in the earlier article to your Windows computer. (Linux and Macintosh computers will not be affected.)
The program then waits for the user to log onto a list of targeted banks and financial institutions, and then steals login credentials and other data which are immediately sent to a remote server hosted by cybercriminals. It can also modify, in a user’s browser, the genuine web pages from a bank’s web servers to ask for personal information such as payment card number and PIN, one time passwords, etc.
Panda Labs released a statement explaining the infection process:
"After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected web page containing the Zeus Trojan, which is specifically designed to steal personal data."
Here is the full announcement from Panda Labs:
Massive Phishing Attack Uses iTunes as Lure to Steal Bank Details, Reports PandaLabs
ORLANDO, Fla., Oct. 4 -- PandaLabs, Panda Security's antimalware laboratory, has discovered that Apple's popular iTunes platform has become a major target for hackers looking to steal credit card data from the service's millions of users.
Victims receive a cleverly-crafted email informing them that they have made an expensive purchase on iTunes. The user, having never made the purchase to begin with, is concerned by the email and naturally tries to resolve the problem – in this case by clicking on the proffered (fake) link. An example of this fraudulent iTunes receipt can be seen here: http://www.flickr.com/photos/panda_security/5050360091/
After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected Web page containing the Zeus Trojan, which is specifically designed to steal personal data. This phishing attack was uncovered shortly after a similar phishing attack targeting LinkedIn users appeared last week, which appears to have originated in Russia.
"Phishing is nothing new," said Luis Corrons, Technical Director of PandaLabs. "What never ceases to surprise us is that the techniques used to trick victims continue to be so simple, but the design and content is so very well-orchestrated. It's very easy to fall into the trap. When using services such as iTunes, it is absolutely crucial that users never go to the website via email, but rather from the platform itself where they can verify their account status."
This technique has been reported to the Anti-Phishing Working Group, which has started to block some of the Web addresses linked to in the fake email.
PandaLabs advises all users to be wary of any emails related to iTunes, regardless of how genuine they seem. Users who think they may have been affected are urged to scan their computers thoroughly to locate and remove any possible active threats. [Windows] Users who do not have an antivirus installed can use Panda Cloud Antivirus, a free security service available at www.cloudantivirus.com.
More information is available in the PandaLabs Blog.
About PandaLabs
Since 1990, its mission has been to detect and eliminate new threats as rapidly as possible to offer our clients maximum security. To do so, PandaLabs has an innovative automated system that analyzes and classifies thousands of new samples a day and returns automatic verdicts (malware or goodware). This system is the basis of collective intelligence, Panda Security's new security model which can even detect malware that has evaded other security solutions.
Currently, 99.4 percent of malware detected by PandaLabs is analyzed through this system of collective intelligence. This is complemented through the work of several teams, each specialized in a specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc.), who work 24/7 to provide global coverage. This translates into more secure, simpler and more resource-friendly solutions for clients.
More information is available in the PandaLabs blog: http://www.pandalabs.com.
-----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG
www.FayetteFrontPage.com
Twitter: @FayetteFP
I received one of these email messages a few days ago. Luckily, Gmail placed it in my spam folder so I didn't see it until today when I went looking for it. You have to hand it to these scam artists: they certainly are clever at devising methods of stealing your money.
I wrote a couple of days ago at http://goo.gl/nvl9 about a "trojan" email message that steals your user IDs and passwords to your online banking account. This new scam is a different Trojan message with a very clever delivery method.
The new scam sends a fake "iTunes receipt" email message to millions of people. The message appears to be completely authentic, except for the price shown in your bill. The message I received was for nearly $1,000. That's part of the trap.
Most people are likely to take action when seeing an "incorrect amount" appear on their bill. (I didn't do that because I never saw the "bill" in my spam folder until I went looking for it later, after reading about the new scam.) Most people will click on the "report a problem" link that is included in the email message. However, that link takes you to a rogue web page that downloads the same Zeus trojan malware as described in the earlier article to your Windows computer. (Linux and Macintosh computers will not be affected.)
The program then waits for the user to log onto a list of targeted banks and financial institutions, and then steals login credentials and other data which are immediately sent to a remote server hosted by cybercriminals. It can also modify, in a user’s browser, the genuine web pages from a bank’s web servers to ask for personal information such as payment card number and PIN, one time passwords, etc.
Panda Labs released a statement explaining the infection process:
"After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected web page containing the Zeus Trojan, which is specifically designed to steal personal data."
Here is the full announcement from Panda Labs:
Massive Phishing Attack Uses iTunes as Lure to Steal Bank Details, Reports PandaLabs
ORLANDO, Fla., Oct. 4 -- PandaLabs, Panda Security's antimalware laboratory, has discovered that Apple's popular iTunes platform has become a major target for hackers looking to steal credit card data from the service's millions of users.
Victims receive a cleverly-crafted email informing them that they have made an expensive purchase on iTunes. The user, having never made the purchase to begin with, is concerned by the email and naturally tries to resolve the problem – in this case by clicking on the proffered (fake) link. An example of this fraudulent iTunes receipt can be seen here: http://www.flickr.com/photos/panda_security/5050360091/
After clicking the link, the victim is asked to download a fake PDF reader. Once installation is complete, the user is redirected to an infected Web page containing the Zeus Trojan, which is specifically designed to steal personal data. This phishing attack was uncovered shortly after a similar phishing attack targeting LinkedIn users appeared last week, which appears to have originated in Russia.
"Phishing is nothing new," said Luis Corrons, Technical Director of PandaLabs. "What never ceases to surprise us is that the techniques used to trick victims continue to be so simple, but the design and content is so very well-orchestrated. It's very easy to fall into the trap. When using services such as iTunes, it is absolutely crucial that users never go to the website via email, but rather from the platform itself where they can verify their account status."
This technique has been reported to the Anti-Phishing Working Group, which has started to block some of the Web addresses linked to in the fake email.
PandaLabs advises all users to be wary of any emails related to iTunes, regardless of how genuine they seem. Users who think they may have been affected are urged to scan their computers thoroughly to locate and remove any possible active threats. [Windows] Users who do not have an antivirus installed can use Panda Cloud Antivirus, a free security service available at www.cloudantivirus.com.
More information is available in the PandaLabs Blog.
About PandaLabs
Since 1990, its mission has been to detect and eliminate new threats as rapidly as possible to offer our clients maximum security. To do so, PandaLabs has an innovative automated system that analyzes and classifies thousands of new samples a day and returns automatic verdicts (malware or goodware). This system is the basis of collective intelligence, Panda Security's new security model which can even detect malware that has evaded other security solutions.
Currently, 99.4 percent of malware detected by PandaLabs is analyzed through this system of collective intelligence. This is complemented through the work of several teams, each specialized in a specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc.), who work 24/7 to provide global coverage. This translates into more secure, simpler and more resource-friendly solutions for clients.
More information is available in the PandaLabs blog: http://www.pandalabs.com.
-----
Community News You Can Use
Click to read MORE news:
www.GeorgiaFrontPage.com
Twitter: @gafrontpage & @TheGATable @HookedonHistory
www.ArtsAcrossGeorgia.com
Twitter: @artsacrossga, @softnblue, @RimbomboAAG
www.FayetteFrontPage.com
Twitter: @FayetteFP
Labels:
email,
fake,
fayette front page,
georgia,
georgia front page,
itunes,
phishing,
receipt,
scam,
trojan
Subscribe to:
Posts (Atom)


