Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Tuesday, 6 January 2015

Universities Targeted with "Library Account" phish

Many universities across the country have been targeted with phishing emails that warn their students that their "Library Account" is going to expire. As with so many cybercrime issues, these crimes could be addressed much differently if the Powers That Be were aware that these were not individual cases, but an on-going campaign across victims across the country!

Towards that end, I've collected full text examples of many of these phish, with links to the University web pages where there students have been warned. Hopefully we can start warning people of national on-going campaigns like this BEFORE they are victimized!

While I was reviewing University Phish for this project, I was especially impressed with the phishing details shared at University of Michigan (Go Blue!) and University of Pennsvylvania. Both are great examples of giving students enough details to understand the scope of the risk at hand.

January 2014 Library Account phish


January 9, 2014 - George Washington University
Subject: Library Account
Dear User,

Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once! To reactivate your account, simply visit the following page and login with your university account. After logging in, your account is reactivated and it will redirect you to your Library Account.

February Library Account phish


February 21, 2014 - Flinders University
Have you received an email asking you to “validate” your Library Account? This email is attempting to steal Flinders user credentials and is not legitimate.

Don’t follow the links in the email, just delete it. The library will never ask you to login to verify your details or activate your account.

May Library Account phish


May 23, 2014 - Lehigh University

June Library Account phish


June 26, 2014 - University of Minnesota
From: Library
Date: Thu, Jun 26, 2014 at 8:47 AM
Subject: Library Account
To:
Dear User,
Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once!

To reactivate your account, simply visit the following page and login wilth your library account.

Login Page:
xxxxxxxxxxxxxxxxxx
Sincerely,
University of Minnesota Libraries
499 Wilson Library
309 19th Avenue South
Minneapolis, Minnesota 55455
(612) 624-3321 (voice)
(612) 626-9353 (fax)

September Library Account phish


September 10, 2014 - University of Pennsylvania

From: Jonathan Heller < jheller@pobox.supenn.edu >
Subject: Library Account Access
Date: Wed, Sep 10, 2014 2:11 PM

Dear User,
Your access to your library account is expiring soon and it won't be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK REMOVED)

If you are not able to login, please contact Library Services Manager at jheller@pobox.upenn.edu .



Sincerely,
Jonathan Heller
Library Services Manager
Access & Delivery Services
Penn Libraries
University of Pennsylvania
(215) 898-8956
jheller@pobox.upenn.edu

September 17, 2014 - University of North Carolina Health Sciences Library
Alert: Phishing Emails Impersonate UNC Library

Some members of the UNC community have received false emails that appear to be from the Library.

These emails state that “access to your library account is expiring soon and it won’t be accessible for you.” The email directs the recipient to a link that appears to be from the Library.

October Library Account Phish


October 8, 2014 - UC Denver's Auraria Library
October 9, 2014 - University of Colorado Health Sciences Library
The University has been recently subjected to a phishing attack. The subject line of these new phishing messages is “Library Account Access”. These emails are designed to appear as if they are coming from the library concerning a library account activation. The phishing emails also contain links to malicious web sites that ask for your University information (Name and student/employee ID).


October 10, 2014 - Miami University of Ohio

From: XXX XXX [mailto:xxxxxxxx@miamioh.edu]
Sent: Friday, October 10, 2014 12:45 PM
To: xxxxxxxx@miamioh.edu
Subject: Library Account Access

Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK)

If you are not able to login, please contact Library Services Manager at xxxxxxxx@miamioh.edu.



Sincerely,

Alison Withers
Library Services Manager
Access and Delivery Services
University Library
Miami University
513-529-2938

October 30, 2014 - Virginia Commonwealth University

To:
From: Access Services Manager
Date: 10/30/2014 11:54AM
Subject: Library Account Access

Dear User,
Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library account.

(Link redacted, actual link goes to login.vcu.edu.cavc.tk)

If you are not able to login, please contact Library Services Manager at kbonis@vcu.edu.



Sincerely,

Kerry Bonis
Library Services Manager
Access & Delivery Services
Main Library
Virginia Commonwealth University
(804) 827-3968

November Library Account phish


November 13, 2014 - Illinois Institute of Technology
IIT faculty, staff and students may have received an email to “All Members of the University of Illinois” notifying you about a new library system that requires you to activate a new library account. Do not respond to this email. It is a phishing attempt to collect IIT campus-wide ID numbers (CWIDs).

Library users affiliated with Illinois Tech gain access to subscription databases when off-campus by entering their CWID. Releasing that information to a third-party may result in access to our databases being limited or cut off. You can always safely access the library website by using the IIT Portal links, or going directly to the library website. If you believe your CWID has been compromised, please contact the OTS support desk.


November 17, 2014 - Southern Methodist University

Sample Phishing Email

Subject: Library Account Access
Sender: Jane Sippell

Dear User,
Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

Note – this link appears in the email:

https://libcat.smu.edu/cgi_bin/ldapauth.cgi_loginType=E25JFHNfCD7…

The actual destination does not point to the SMU library catalog but to a web address at http://libcat.smu.edu.cvre.tk

http://libcat.smu.edu.cvre.tk/cgi_bin/ldapauth.cgi_loginType=E25JFHNfCD7v…

If you are not able to login, please contact Access Services Manager at jsippell@smu.edu.



Sincerely,

Jane Sippell
Access Services Manager
Access & Delivery Services
Central University Libraries
Southern Methodist University
(214) 919-5931
jsippell@smu.edu
November 17, 2014 - University of Arizona

From: library (EMAIL ADDRESS REMOVED)
Subject: Library account
Date: November 17, 2014 at 8:46:39 AM MST
Reply-To: (EMAIL ADDRESS REMOVED)

Dear User,
Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once!

To reactivate your account, simply visit the following page and login with your library account.

Login Page:

(URL REMOVED)

Sincerely,

The University of Arizona Libraries
(ADDRESS, PHONE NUMBER AND URL REMOVED)


November 18, 2014 - Washington University in St. Louis
Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to this service. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK)

If you are not able to login, please contact Access Services Manager at *********@wustl.edu.

Sincerely,


November 19, 2014 - Ball State University Library
University Libraries was alerted that some members of the Ball State community received an email message stating their library account was soon to expire. The email said to reactivate the account by clicking on a web address included in the message. This was a phishing scam and the campus Office of Information Security took steps block access to the phony site.

December Library Account Phish


December 1, 2014 - Harvard University
December 1, 2014 - McGill University (Canada)

From: Library
Subject: Library Account
Sent: Monday, December 01, 2014 8:49 AM
To:

Dear User,
Your library account has expired, therefore you must reactivate
it immediately or it will be closed automatically. If you intend
to use this service in the future, you must take action at once!

To reactivate your account, simply visit the following page
and login with your library account.

Login Page:

Sincerely,

McGill Library
McLennan Library Building
3459 rue McTavish
Montreal, Quebec
H3A 0C9
December 1, 2014 - Cornell University
Subject: Library Account
Date: December 1, 2014

Dear User,

Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once! To reactivate your account, simply visit the following page and login with your library account.

Login Page:
(BAD LINK)

Sincerely,

Cornell University Library, Ithaca, NY 14853 | (607) 255-4144


December 3, 2014 - University of Tennessee Knoxville
Dear User,

Your library account has expired, therefore you must reactivate it immediately or it will be closed automatically. If you intend to use this service in the future, you must take action at once!

To reactivate your account, simply visit the following page and login with your library account.

Login Page:

http://www.lib.utk.edu/reactivation?service

Sincerely,



University of Tennessee
University Libraries
Email: library@utk.edu
Tel: (865) 974-4351

December 15, 2014 - California State University Long Beach
December 18, 19, 20, 2014 - University of Michigan - (Hail to the Victors! Go Blue! WELCOME COACH HARBAUGH! Watched you play in 1985 while I was a Wolverine myself!!!) (oops) (blush)

Date: Thursday, December 18, 2014
Subject: Library Account Access

Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to the library services. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

[LINK REMOVED]

If you are not able to login, please contact [LINK REMOVED] for immediate assistance.

Sincerely,



Access Services Manager
University of Michigan Library
(734) 936-2921
[LINK REMOVED]
Date: Friday, December 19, 2014
Subject: U-M library System Problem
Dear [Your Name],

You are receiving this message because your login and off-campus access may have been compromised.

Your access will be inactive in 3 days. Because of some security problems, we decided to make some changes (Upgrade) and this is due to the implementation of a new version of Central Authentication System(CAS) and Umich WebLogin.
This means while you are off-campus or on-campus you will have no access to library's internal web services.

You can activate it by going again simply login to University of Michigan Library Weblogin System with your U-M LoginID and reactive your access.
Offer that Logout your account and close your browser.

Please note: If you get an Authentication Error ,just try 2 times to login again. Because System will automatically block your IP and Account and you should contact Systems Help Desk to Unlock.


University of Michigan Library
818 Hatcher Graduate Library South
913 S. University Avenue
Ann Arbor, MI 48109-1190
(734) 764-0400
[LINK REMOVED]
Date: Friday, December 19, 2014
Subject: ADMIN

Dear Web-mail Account User,

Your e-mail Account have Exceed the 20 GB e-mail Storage Set-Up by your Service Provider/Admin. You have to contact your Service Provider on Help Desk Support Portal below in less than 48 hours to avoid Suspension of your Web-mail Account if you dont Verify your e-mail account. To keep your Account Safe, Kindly Click the Help Desk Support Blue Portal below:

umich.edu-helpdesk [LINK REMOVED]


SERVICE DESK - IT HELP DESK
©COPYRIGHT 2014 WEB-TEAM. ALL RIGHT RESERVED.

December 23, 2014 - Wake Forest University
Dear User,

Your access to your library account is expiring soon and it won’t be accessible for you. You must reactivate your account in order to continue to have access to the library services. For this purpose, click the web address below or copy and paste it into your web browser. After logging in, your access is reactivated and you will be redirected to your library profile.

(LINK)

If you are not able to login, please contact James Hart at hartja@wfu.edu for immediate assistance.


Sincerely,

James Hart
Access Services
ZSR Library
Wake Forest University
336-758-4967
hartja@wfu.edu

December 23, 2014 - UAB Library

Wednesday, 12 November 2014

Phishing Success Rates and Google Phish

Last week a group of Google employees led by Elie Bursztein joined UCSD researchers Andreas Pitsillidis and Stefan Savage in presenting the findings of a study on phishing to the ACM Internet Measurement Conference in Vancouver, British Columbia. Their paper, Handcrafted Fraud and Extortion: Manual Account Hijacking in the Wild (12 page PDF) was picked up broadly in the press, and as usual, wildly misinterpreted.

At least 110 articles referring to the study were found in a simple Google News search with headlines ranging from the somewhat accurate:

  • Manual Phishing Gmail Attacks Found To Be Very Effective - Top Tech News, Nov 9, 2014
  • Google Study Finds Email Scams Are More Effective Than You'd Expect - Huffington Post, Nov 7, 2014
  • Old-time phishing scams are working just fine, Google finds - Naked Security, Nov 11, 2014
to the extreme bending of the facts for headline value such as these:
  • Phishing attacks on email accounts are successful 45 percent of the time - Firstpost, Nov 10, 2014
  • Phishing scams work 45% of the times: Google study - Times of India, Nov 10, 2014
  • Have You Been Scammed? Phishing Emails Successful 45% of the Time - Crave Online, Nov 11, 2014
  • A scary number of you are still falling for phishing scams, says Google - Nov 10, 2014

What did Google and UCSD Actual Say about Phishing?

First, the 45% quote. For the 100 Google/Gmail phishing sites that the researchers studied, they found that depending on the structure of the page, as few as 3% of the visitors filled out the phishing form and submitted their data. Overall 13% of the visitors to the webforms shared their personal data with the phishers, while in the most extreme example, 45% of the visitors to the phishing web page completed the form and submitted their personal data.

There were several interesting findings in the study. A few that I found interesting included:

  • 35% of phishing sites target victims' email
  • 21% of phishing sites target banking credentials
  • A growing number of phishing sites are targeting App Stores and Social networking credentials
  • Account takeovers are primarily Fast and Foreign:
    • 20% of compromised Google accounts were logged into within 30 minutes
    • The top countries of origin for hijackers were China, Ivory Coast, Malaysia, Nigeria, and South Africa
  • The easiest way to have your account restored is to have registered an SMS telephone number for out of band contact.

Manual Hijacking

The focus of this study was the process of Manually Hijacking accounts belonging to Google users. Because of that focus, it is not clear how broadly the observed behaviors can or should be projected onto other types of phishing. At Malcovery Security we observe 600 to 800 newly created phishing sites per day. This study focused primarily on Gmail/Google phish from January 2014, and for part of the study focused specifically on 100 Gmail phishing websites.

Google provided some statistics on how widely the problem of manual hijacking has been seen in the past. Over calendar 2012-2013, Google's security teams found that approximately 9 manual hijacking cases per day per million active users occurred. With over 500 million subscribers, Google is dealing with thousands of such account hijacks per day.

With Google participating in the research, researchers were able to determine that when an account is taken over, the criminals login to the account and search the email history and address books to determine how best to monetize the account. It seems that every week someone will make the comment in my presence "Yes, I have malware on my computer, but the worst that might happen is they get my email password!" But think about what is possible with that? How would you reset your password at your Bank? Amazon.com? eBay? On most of those sites, clicking "I Forgot My Password" results in an email being sent with a "Reset My Password" link! If the criminal finds an email from your bank in your email history, they now know exactly which bank to visit to click the "I Forgot My Password!" The email account is the key to the entire balance of your account!

The researchers also found that the scam we first wrote about in 2009 in the post Traveler Scams: Email Phishers Newest Scam is still quite prevalent. In this scam, because the criminal has access to your recent sent emails and address book, they are able to contact your friends and family with news of a tragedy while traveling where they desperately need money wired overseas to help them through the crisis. I've met many individuals who have wired money to their friends before realizing it was a scam! They often have stories of how they KNEW the email was truly from their friend, because when they asked questions, their friend replied with details only the friend would know. Often these details made use of prior "private" conversations in the phishing victim's email sent items box!

Popular Email Phish from Malcovery's ThreatHQ System

In the past seven days, Malcovery Security confirmed 416 distinct phishing URLs related to Google and their properties. These URLs were hosted on 207 distinct domain names on 174 different IP addresses. By country, the United States is the most prominent host of phishing sites, not just for Google, but for nearly every brand that does business in the USA. Of those 174 IP addresses, 90 are in the United States.

Google phish locations: November 5-12, 2014

90United States of America
8Great Britain
7Turkey
6Australia
5Canada
5Chile
5Germany
4Indonesia
4India
4Italy
4Netherlands
4Romania
4Russia
4Singapore
4Spain
3France
3Thailand
2Brazil
2Hong Kong
2South Africa
1Japan
1Korea
1Mauritius
1Ukraine
This popular phish appeared on the domains bloo8.net, iyfcolombia.org, beingmedicalep.com, lifeofease.us, microcenterengineering.com, manosartesanasdelaregion.com, ouzophilippos.com, acount-verification.com and many ohters.

Although this phishing site is PRIMARILY imitating DropBox, it still steals Gmail and other email credentials:
The domain hosting this phish was "t-online.de".
This version brings in many cable-provider logos for email address choices, rather than relying on "Other Email" as some of the others do:
This version brings the logos of many Chinese language email providers into the mix:
One of the earlier forms of the phish:
These just a few examples of the "look and feel" of some of the 400+ Google-related phishing URLs we've seen in the past seven days at Malcovery security. Most of them were seen many times each!

Tuesday, 29 July 2014

SFR phish: the Gateway to all French banks

Back in April, we wrote about the French power company, EDF, being used as a universal phishing target in our article, Multi-Brand French Phisher uses EDF Group for ID Theft. Since that time we are seeing that those targeting French speaking victims are choosing yet another large utility to serve as proxy for all of the French banking world. This time the phishing lures are for SFR.

This phish has been especially popular this year. Malcovery's PhishIQ service has seen more than 1,000 SFR phish on more than 330 hacked servers so far this year, including dozens just in the month of July 2014. More importantly though, the attackers are growing more sophisticated! The attack described below is one of the most sophisticated phish we've seen to date, employing "man-in-the-middle" logins where SFR credentials are tested before the victim is allowed to proceed, and nearly a dozen customized bank security procedure questions being processed.

In a typical example of these phish, the victim receives an email that appears to be from SFR informing them that an error was made in their bill, "Ce mail vous a été envoyé dans le but de vous informer qu une erreur est survenue lors de l établissement de la dernière facture" and to "Cliquer ici pour ouvrir le formulaire de remboursement" (Click here to open the refund form). The victim is also warned that they need to fill out the form completely, or they won't get their refund (in some cases 95 Euros!):

Veuillez accepter nos excuses par cette erreur comptable. SFR : Service comptabilité de SFR Toute omission, mauvaise saisie, ou non réponse a ce mail entrainera automatiquement une amputation de la somme de quatre-vingt-quinze (95) euros sur votre compte, et aucune réclamation de sera acceptée.

While there are several versions of the SFR phish, the most sophisticated that we have encountered so far can be seen on a British horse enthusiasts website (obviously hacked). What makes this one particularly compelling is that it begins by requiring the victim to be using their true SFR userid and password. On the originating screen, the user is told to "Connectez-vous" by entering his userid (Identifiant) and password (Mot de passe).

The Action of this form of the phishing site actually passes the userid and password to SFR and confirms whether or not a true identifier has been used. If false information is provided, the phishing victim receives a message back informing him that

Vos coordonnées n'ont polo été reconnues. -- Your details have not been recognized.
Veuillez recommencer. -- Please try again.
Suite à 5 erreurs sur votre mot de passe, -- After 5 errors on your password
votre compte est bloqué. -- Your account will be blocked.

So, with a little incentive to not lie to the criminal, and a fairly strong reason to believe they are really speaking with SFR, the victim continues to page two after providing true login credentials.

On the second page, the victim is invited to choose their bank from a long list of French banks. Depending on which bank they choose, they will be prompted for appropriate additional verification details used by that bank. Banks on the list include:

  • AXA Banque
  • Banque AGF / Allianz
  • Banque de Savoie
  • Banque Dupuy de Parseval
  • Banque Marze
  • Banque Palatine
  • Banque Populaire
  • Banque Postale
  • Barclays
  • BforBank
  • Binck.fr
  • BNP
  • BNP Paribas La NET Agence
  • Boursorama Banque
  • BPE
  • Caisse d'Epargne
  • CIC
  • Coopabanque
  • Crédit Agricole
  • Crédit Cooperatif
  • Crédit du Nord
  • Crédit Mutuel
  • Crédit Mutuel de Bretagne
  • Crédit Mutuel Massif Central
  • Crédit Mutuel Sud-Ouest
  • e.LCL
  • Fortis Banque
  • Fortuneo Banque
  • Groupama Banque
  • HSBC
  • ING Direct
  • LCL
  • Monabanq
  • Societe Generale
  • Société Marseillaisle de Crédit
  • Autre Banque
Here are some examples: (Click on any image to enlarge)

Some banks require the visitor to enter their 3DSecure code

AXA Banque has a custom code for their clients

Banque Postale has security questions, such as:
  • Quel est le prénom de l'aîné(e) de vos cousins et cousines ?
  • Quel était le prénom de votre meilleur(e) ami(e) d'enfance ?
  • Quel était votre dessin animé préféré ?
  • Quel a été votre lieu de vacances préféré durant votre enfance ?

Caisse d'Epargne also provides a personalized Client code.

Even the "Cyberplus" electronic password generators used by Banque Populaire are included in this phish!

Some banks also require information about the victim's birthplace


After successfully acquiring both your SFR.com userid and password, and the necessary information to take over the bank account of the phishing victim, the criminal sends you on your way, after congratulating you on your success!
(The update was successful. SFR thanks you for using its Bank Assurance services. You can continue browsing the site with full security.)

After seeing this message briefly, the visitor is forwarded to the true www.SFR.fr website.

Thursday, 29 May 2014

A Social Facebook Phish - is your friend acting strange?

I'm always proud when my students do a great write up on a new attack, and doubly so when that analysis comes from my nephew, Chris Warner!

Chris was logged in to Facebook today when one of his friends started chatting with him. It was pretty obvious to Chris that his friend had been the victim of an Account Takeover (ATO) and thta he was really chatting with a criminal who was inviting him to visit a Facebook phishing site. Chris gathered up an evidence package and submitted it to IC3.gov with his analysis prior to contacting me. With his permission, I'm sharing what he saw (editing his friend's identity out for her privacy.)

Original URL user sees is of the format:

http://(USER FIRST NAME)-photos.uglyfacebookpeople,commm

URL is intentionally messed up, presumably to avoid detection by Facebook systems.

URL redirects to http://accounts.login.userid.266765.facebooclk.com/lp/fbn/?next=http%3A%2F%2F%2videos%2F%3AJ%4ID%1A

Action file is security.php

Following the action file results in visiting accounts.login.userid.497031.facebooclk.com/blam/

Which directs you to a "Flash Player Update" site that I assume is a virus. http://198.52.200.49/install_flashplayer13x32_mssd_aaa_aih.ex

There are other files that were on the site, but it is down now.

WHOIS INFO(SAME FOR FACEBOOCLK.COM AND UGLYFACEBOOKPEOPLE.COM):


Registrar Abuse Contact Phone: +1-2013775952
Domain Status: clientTransferProhibited
Registry Registrant ID: DI_36635864
Registrant Name: Dave Brider
Registrant Organization: none
Registrant Street: 505 45th st
Registrant City: new york
Registrant State/Province: New York
Registrant Postal Code: 10003
Registrant Country: US
Registrant Phone: +1.6463392283
Registrant Email: yogurtman7@mail.com
Registry Admin ID: DI_36635864
Admin Name: Dave Brider
Admin Organization: none
Admin Street: 505 45th st
Admin City: new york
Admin State/Province: New York
Admin Postal Code: 10003
Admin Country: US
Admin Phone: +1.6463392283
Admin Email: yogurtman7@mail.com
Happy hunting!

--Chris Warner


Thanks, Chris! You did a great job on that write-up! Hope it helps save someone from being a victim!!

Friday, 11 April 2014

Phishers, Framesets, and Grocery Surveys

Like most criminals, or let's face it, most programmers, Phishers are lazy. They like to be able to create one website and have it live for an extended period of time. Unfortunately for them, victim companies either smash new phishing sites as fast as they can, or they hire companies to do it for them. At Malcovery Security we concentrate on INTELLIGENCE rather than takedown, so our focus is in understanding what the sites can teach us about the criminal behind the attack, and how the many attacks against your brand are related to each other and to attacks against other brands.

A friend of ours shared a link to a website today that was imitating Centra, a convenience and grocery chain throughout Ireland.

The accompanying spam message promises that they will pay us 150 Euros just for taking their survey!

For the convenience of the consumer, rather than having to wait for a check (cheque) in the mail, you can just enter all of your Credit Card information, and your Date of Birth and some other personal details, and they'll deposit the money right into your credit account!

As we looked at the log files, we found an interesting fact. NONE of the more than 900 visitors to the website had visited the site DIRECTLY. They were all being referred from other URLs. This is our indicator that the spam messages did NOT contain a link to the domain shown above. Instead, they were pointing at websites with Chinese domain names!


...
[10/Apr/2014:01:06:08 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:07:46 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:07:52 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:08:28 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:08:51 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:09:14 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:09:24 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:09:28 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:09:42 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:09:45 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:09:55 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:10:27 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html
[10/Apr/2014:01:10:31 GET /Centra/centra/ http://asp.sti.com.cn/Bonibon/HausSurvey.html

...

[11/Apr/2014:00:46:22 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:00:58:02 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:01:06:46 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:01:16:22 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:01:18:38 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:01:18:48 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:01:23:23 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:01:25:27 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
[11/Apr/2014:01:25:49 GET /Centra/centra/ http://www.jctz.cn/Bonibon/HausSurvey.html
...

When we look at the websites on "asp.sti.com.cn" and "www.jctz.cn" we see that both of them actually consist ONLY of a "FrameSet" that sends us to the location of the CENTRA phish:

The logs ALSO reveal that another brand is being hosted on the same server!


...
[10/Apr/2014:05:19:16 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:20:03 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:20:09 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:28:47 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:30:31 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:37:56 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:48:45 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:50:27 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:53:44 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html
[10/Apr/2014:05:57:39 GET /texc/ http://mnks.1039.cn/Bonibon/HausSurvey.html

Since most of the time when I'm in the UK I am running dawn to dusk in meetings, Tesco is the only store I've actually ever shopped in, since there is one on every street corner in London. The phishers have correctly updated their currency to use Pounds instead of Euros: "TESCO Supermarkets will add £150 credit to your account just for taking part in our quick survey." but other than that, this is the same phish!

And, as with the other, the actual advertised URL from the spam campaign is hosted in China, and simply updates the content with a Frame SRC = .

Remnants in the logs make it seem likely that this phisher has also targeted Woolworths (many 404 messages in the very early part of the phish for paths with /wps/woolworths/ in the path. Very likely that this is a throw-back to the Woolworths phish from 2012. (Woolworths is a food chain in Australia - they got so many of these scams that they did television news announcements warning about it - see for example: Scam Alert (a Current Affair November 2012). Those spam messages looked like this:

Subject: Customer Satisfaction Survey! Win 150$

Congratulations!

You have been selected by Woolworths Online Department to take part in our quick and easy reward survey. In return we will credit $150 to your account - Just for your time!

Helping us better understand how our members feel, benefits everyone.

With the information collected we can decide to direct a number of changes to improve and expand our services. The information you provide us is all non-sensitive and anonymous. No part of it is handed down to any third party groups. It will be stored in our secure database for maximum of 3 days while we process the results of this nationwide survey.

To access the form, please click on the link below :

Thursday, 20 March 2014

American Express's new Phishing Criminal Brings Game!

Every time I start to think that I've seen everything with regards to phishing the criminals shake things up and get me excited again. Today I have to say the American Express phishers are bringing their A Game to the table again. While there are several different groups of phishers attacking most financial institutions, the criminals behind this particular attack are at least showing some creativity. Let's take a look at the spam message first.

We had two primary spam subject lines for this campaign. On March 17, 2014 the Malcovery Spam Data Mine gathered:

468 copies = Subject: Important: Personal Security Key
290 copies = Irregular card activity

The messages were BEAUTIFUL! Here's one:

Isn't that gorgeous? Every single link in that email is actually just another copy of the phishing URL. No matter what you click on, the phishing process starts. And what a process it is! Just in the samples that we had at Malcovery Security, we saw 574 distinct URLs on 77 different web hosts! (the full list is available as amex.urls.txt.

The AmEx Phishing Payload

Why am I writing about this three days later? BECAUSE THE PHISH IS STILL LIVE!

Just a few minutes ago, I revisited one URL per webhost and found that 40 of the 77 servers were still delivering payload.

What was the payload?

Here's a sample from one of those 40 sites:

A small box containing the words "Connecting to server..." appears, but in the background, the machine is trying to pull content from these scripts (defanged below):


(script) src equals http://theblazingfiddles.com/responsive/rhone.js
(script) src equals http://haus-an-der-treene.de/irrigated/bewaring.js
(script) src equals http://qualifyformedi-cal.com/mortician/amicably.js
(script) src equals http://ufofurniture.com.au/curries/searchlights.js

But actually between the 40 sites I was able to access this morning (March 20, 2014) there were a total of 38 redirectors!


hxxp: (slash) (slash) nebucom.com (slash) instanced (slash) inconsolable.js
hxxp: (slash) (slash) e-translation.pl (slash) ditty (slash) appetizing.js
hxxp: (slash) (slash) grupovordcab.com (slash) expiration (slash) eddies.js
hxxp: (slash) (slash) user22809.vs.easily.co.uk (slash) healed (slash) pulsation.js
hxxp: (slash) (slash) cescconstructionsupply.com (slash) diminished (slash) somalian.js
hxxp: (slash) (slash) majstri.net (slash) donning (slash) slaved.js
hxxp: (slash) (slash) ohsspiritwear.com (slash) nike (slash) robbing.js
hxxp: (slash) (slash) songingeternally.com (slash) maracaibo (slash) your.js
hxxp: (slash) (slash) 03629e3.netsolhost.com (slash) altaic (slash) scarify.js
hxxp: (slash) (slash) mobifone-sy.com (slash) inflated (slash) minstrels.js
hxxp: (slash) (slash) shashwathomes.com (slash) pleader (slash) socialized.js
hxxp: (slash) (slash) www.netpolis.gr (slash) emulate (slash) loved.js
hxxp: (slash) (slash) theblazingfiddles.com (slash) responsive (slash) rhone.js
hxxp: (slash) (slash) haus-an-der-treene.de (slash) irrigated (slash) bewaring.js
hxxp: (slash) (slash) qualifyformedi-cal.com (slash) mortician (slash) amicably.js
hxxp: (slash) (slash) ufofurniture.com.au (slash) curries (slash) searchlights.js
hxxp: (slash) (slash) amerapremier.com (slash) cesar (slash) viewers.js
hxxp: (slash) (slash) www.deacomunicazione.it (slash) doyen (slash) undermining.js
hxxp: (slash) (slash) orbitek.hosting24.com.au (slash) trespasses (slash) earthly.js
hxxp: (slash) (slash) www.mypafamilylawyer.com (slash) desultory (slash) interrelated.js
hxxp: (slash) (slash) blog.myragold.com (slash) hastening (slash) contemporaries.js
hxxp: (slash) (slash) loveworks365.com (slash) howe (slash) corsets.js
hxxp: (slash) (slash) SNC.NO-IP.ORG (slash) drywalls (slash) liquefy.js
hxxp: (slash) (slash) conseguidomaquinaria.com (slash) hollyhocks (slash) propels.js
hxxp: (slash) (slash) 034ED86.NETSOLHOST.COM (slash) lodestone (slash) shilled.js
hxxp: (slash) (slash) almesa.gr (slash) furious (slash) zygotes.js
hxxp: (slash) (slash) hosted.proaal.com (slash) enchanted (slash) handel.js
hxxp: (slash) (slash) hnuaaa.org (slash) spitfires (slash) winks.js
hxxp: (slash) (slash) www.tstn.org (slash) churchyard (slash) wealthy.js
hxxp: (slash) (slash) filtron.gr (slash) skited (slash) menages.js
hxxp: (slash) (slash) 3914f5c7a46c5f05.lolipop.jp (slash) andre (slash) fastidiously.js
hxxp: (slash) (slash) geeologee.com (slash) bawls (slash) cubbyholes.js
hxxp: (slash) (slash) ghs.boehmenkirch.de (slash) executrix (slash) straps.js
hxxp: (slash) (slash) besttrainer.co.nz (slash) phrasings (slash) vehicle.js
hxxp: (slash) (slash) ftp.fasady-zateplovani.eu (slash) conduces (slash) garrote.js
hxxp: (slash) (slash) sewhot.ca (slash) househusbands (slash) piing.js
hxxp: (slash) (slash) animalspirits-lva.de (slash) instruction (slash) propounds.js
hxxp: (slash) (slash) wildtrackpictures.com (slash) dracula (slash) archenemy.js
Each of those actually does a "document location" to forward you to the actual phishing page, which was hosted on five different URLS: hxxp: (slash) (slash) e4business.net (slash) americanexpress (slash)
hxxp: (slash) (slash) paitoanderson.com:8080 (slash) americanexpress (slash)
hxxp: (slash) (slash) advisorbuysell.com (slash) americanexpress (slash)
hxxp: (slash) (slash) advisor-connect.info (slash) americanexpress (slash)
hxxp: (slash) (slash) 173.246.103.84 (slash) americanexpress (slash)

The Phish Itself

Here's a walk-through of the five page phish.

(Each of those three pages actually had this footer on the bottom! Good to see they included a link to the Fraud page at AmEx!)

When you were finished, you got a friendly thank you . . . letting you know your certificate was all set up . . .

and then got forwarded to the real AmEx page:

Monday, 17 February 2014

Interac Phishers try their hand at IRS

Last week Malcovery Security had an interesting phish show up claiming to be related to the IRS. This one turns out to be a great example of the (activate 1940 horror movie narrator voice) The POWER OF CROSS BRAND INTELLIGENCE (/activate). Here's what the website looked like:


Phish from: bursafotograf.com / profiles / interac / RP.do.htm

In this phish, the "big idea" is that you can escalate your IRS Tax Refund if you specify which bank you would like the refund to be deposited into. When you click the bank's logo, you are taken to a phishing site for that brand and asked to provide your Userid and Password, which are then emailed to the phisher. Here's an example of the page you would see if you clicked on the Regions Bank logo (graphic courtesy of PhishTank submission 2254700.)

Things get quite fascinating though when we hide the graphics:

Why would an IRS phish have ALT TEXT including for four of the largest Canadian banks? By looking at the source code for the phishing page, we see that this is a very lightly rebranded Interac phish: First, the website Title is "INTERAC e-Transfer" ...

INTERAC is a very interesting money transfer system used in Canada that allows anyone to send money to anyone else simply by using either their email address or cell phone text messaging service. A Transaction code is texted/emailed from the payer to the recipient, allowing the recipient to login to the Interac service and choose what account, and what bank, they would like to receive the funds into.

The phish has some Javascript at the top that includes variables like "var provinceList = new Array ("Alberta", "British Columbia", "New Brunswick", "Newfoundland and Labrador", "Nova Scotia", "Ontario", "Prince Edward Island", "Saskatchewan");" and a pull down menu with options "Select Institution", "Select Province or Territory" and "Select Credit Union."

As we continue into the table of graphics, we see that the phisher has changed his graphics and links to refer to the American banks, with code such as:


href = chasecustomerprofile
img src = chasecustomerprofile/css/images/chaseNew.gif .... but with "alt=CIBC"

href = navy/index.htm
img src = imgs/nfculogo.png .... but with "alt=President's Choice Financial"

href = suntrust
img src = imgs/suntrust.png .... but iwth "alt = RBC Royal Bank"

etc . . .

Phishing Cross-Brand Intelligence

It seems fairly clear that we should be able to find more phishing sites that used the original Interac code, and of course we can in the Malcovery PhishIQ system.

Here is a phish that was seen on June 21, 2013 on the website freevalwritings.com / wp / interacsessions / RP.do.htm

And another first seen on May 28, 2013 on the website anglaisacote.com / interac / RP.do.htm (note the common path on both of these that matches the current IRS phish = "interac/RP.do.htm" RP.do.htm is used on the REAL Interac website.

Phishing & Spam Cross-Brand Intelligence

An interesting thing about phishing emails that differentiates them from standard spam. While normal spam is often sent via botnets, phishing emails tend to be sent from the same IP address over a period of time. When we use Malcovery PhishIQ to examine the IRS version of the Interac phish, which attempts to steal money from Bank of America, Chase Bank, Navy Federal Credit Union, SunTrust, Regions Bank, Wells Fargo, USAA, and Citi, we see that the originally advertised URL was actually "130.13.122.25 / irsjspmessageKey-IG09210358i /". That URL forwarded visitors to the website "ernursusleme.com / Connections / irsonlinedeposit /" which then forwarded the visitors to "bursafotograf.com / profiles / interac / RP.do.htm" which is where the screenshot at the top of this article was captured.

So, to find spam messages related to this phish, it seems reasonable to search the Malcovery Spam Data Mine for emails that advertised URLs on 130.13.122.25.

We found two sets of spam messages that advertised URLs on that host in our spam collection. One batch from January 8, 2014 and the other batch from January 28th and January 29th, 2014.

The January 28th and January 29th emails claimed to be from "From: USAA (USAA.Web.Services@customer.usaa.com)" with an email subject of "New Insurance Document Online".

Two of the emails were sent from 122.3.92.116 (Philippines) and one email was sent from 70.166.118.54 (Cox). What other emails were sent from those IP addresses?

Here are the emails from 122.3.92.116

Date: Subject: From NameFrom Email
Dec 13, 2013Your account has been limited until we hear from youservice@ intl.paypal.comsurvey.research-3086@ satisfactionsurvey.com
Dec 13, 2013Your account has been limited until we hear from youservice@ intl.paypal.comsurvey.research-3086@ satisfactionsurvey.com
Dec 14, 2013Your account has been limited until we hear from youservice@ intl.paypal.comsurvey.research-3086@ satisfactionsurvey.com
Dec 16, 2013Confirmation - personal information updateUSAAUSAA.Web.Services@ customermail.usaa.com
Dec 18, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Dec 18, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Dec 18, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Dec 23, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Dec 30, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Dec 31, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Dec 31, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Dec 31, 2013INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Jan 5, 2014Notification of Limited Account AccessPayPalPayPal@ abuse.epayments.com
Jan 7, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 7, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 7, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 8, 2014View Your USAA Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 8, 2014View Your USAA Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 8, 2014View Your USAA Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 8, 2014View Your USAA Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 8, 2014View Your USAA Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 8, 2014View Your USAA Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 8, 2014View Your USAA Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 17, 2014Canada Tax send you an INTERAC e-Transfernotify@ payments.interac.canotify@ payments.interac.ca
Jan 19, 2014Your dispute has been ended 01/20/2014: Get your money backPayPalpaypal.feedback@ email.com
Jan 19, 2014Your dispute has been ended 01/20/2014: Get your money backPayPalpaypal.feedback@ email.com
Jan 20, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 20, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 20, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 20, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 20, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 21, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 21, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 21, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 21, 2014View and Sign Your USAA Insurance PolicyUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 21, 2014Your dispute has been ended 01/20/2014: Get your money backPayPalpaypal.feedback@ email.com
Jan 28, 2014New Insurance Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Jan 28, 2014New Insurance Document OnlineUSAAUSAA.Web.Services@ customermail.usaa.com
Feb 8, 2014Canada Revenue send you an INTERAC e-TransferTD Canada Trustnotify@ payments.interac.ca
And here are the emails from 70.166.118.54

Date: Subject: From NameFrom Email
Jan 29, 2014New Insurance Document OnlineUSAAUSAA.Web.Services@customermail.usaa.com
Feb 3, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 3, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 3, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 3, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 3, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 3, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 4, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 4, 2014INTERAC e-Transfer Receivednotify@ payments.interac.canotify@ payments.interac.ca
Feb 8, 2014Canada Revenue send you an INTERAC e-TransferRBC Royal Banknotify@ payments.interac.ca
Feb 9, 2014Canada Revenue send you an INTERAC e-TransferRBC Royal Banknotify@ payments.interac.ca
Feb 11, 2014Wells Fargo ATM/Debit Card Expires SoonWells Fargo Onlinealerts@ notify.wellsfargo.com
Feb 11, 2014Wells Fargo ATM/Debit Card Expires SoonWells Fargo Onlinealerts@ notify.wellsfargo.com

The Power of Cross-Brand Intelligence

To summarize, we started with a new IRS phish, and through some comparisons in the Phishing and Spam Data Mines, ended with phish for USAA, PayPal, Wells Fargo, and Interac all being linked together. Investigators interested in learning more are encouraged to reach out!

Friday, 24 January 2014

Consumer Reports on Smart Phone safety, Malware, and Phishing

Every year Consumer Reports does a "State of the Net" survey. I've found it to consistently be one of the most interesting and accurate measures of what's going on with regards to Computer Safety for the average American Computer user. Jeff Fox of Consumer Reports and I have spoken in the past about the great program that he's been running for many years. (We first met at an October 1st launch of Cyber Security Awareness Month at the National Press Club). I somehow failed to report on their 2013 report, so I'm catching up now.

This was based on their January 2013 survey, covering experiences for American consumers in 2012. Hopefully we'll have the next year of data in a couple months (it is usually published in their June issue.

Their Lead Article was on Smart Phone security, which found:

  • Half of all American homes have a Cell phone
  • 7.1 Million had their phone Lost, Stolen, or Broken beyond Repair
  • 69% of Americans don't back up their smart phones
  • 64% do not use a password or screen lock!
  • Only 8% use "Remote Wipe", 22% use a "Phone Finder", and 15% use Anti-virus
How well do Consumer Reports survey respondents and you protect mobile phone data?
"Click to see Consumer Reports InfoGraphic"

So much great content in their survey . . .

This article -- How Safe is your Home Computer? found:

  • 43% report being afflicted by "Heavy Spam"

    I really want to call attention to that number, because so many of my computer security friends are calling spam a "solved problem". That is ABSOLUTELY NOT the experience of the average American. Perhaps companies using the best state of the art technology are experiencing reduced volumes of spam, but 43% of Americans report they are still experiencing "Heavy Spam!"

  • 9.8 Million adults had Facebook trouble

    Either accounts taken over by an unauthorized person, had their reputation harmed, or were harassed, threatened, or defrauded.

  • 58.2 Million users had Malware issues

    to an extent that their computer's features or performance were impacted, costing $3.9 Billion in direct repairs and clean-up costs. 5% of them had to take their computer to a third party to have it repaired! I especially like the way that Consumer Reports asks this question. We know that Symantec says 18 computers are infected by new malware EVERY SECOND with a global cost of $110 Billion per year, but the question CR asks here is "How many of those infections actually lead to a real problem for the consumers?"

  • 9.2 million gave up personal data on Phishing sites

    Hundreds of thousands actually lost money from a bank account as a result. Among the big-name companies whose names successful phishers used most often, according to Consumer Reports: Bank of America, Chase, Facebook, PayPal, and Visa.

This article -- Protect Credit Cards from Scams mentions that their survey found:

  • Nearly 20 million credit-card fraud victims

    19.5 million consumers with Unauthorized charges on their cards

    CR Tip to Protect yourself: Report fraudulent charges immediately. If credit was used instead of debit on a bank card, you're probably liable for up to only $50. (That limit doesn't apply to debit charges.)

  • Lost, hijacked, stolen

    18.4 million consumers were notified by Companies, government agencies, or other organizations that their personal info had been lost, hijacked, or stolen.

    CR Tip to Protect yourself: If notified of a data breach, use the free credit monitoring that's usually offered. Add a fraud alert to your credit reports. Close affected accounts and change passwords on others. Check for incorrect charges or withdrawals after the breach.

  • Personal data compromised

    10 million consumers lost money from an account (other than credit card), had personal data used for a fraudulent purpose, or had a new credit account opened in their name by an unauthorized person.

    CR Tip to Protect yourself: Don't click on links or open attachments in e-mail purporting to be from government agencies. Have your bank alert you to possible fraudulent activity.

Great work, as usual, Consumer Reports! Please keep it up!

Friday, 10 January 2014

Target Database Breach "Phishing" Email leads to . . .

Several folks that also do security research called and texted and Facebook messaged today asking if we had seen "the New Target Phishing email"? We're normally pretty good folks to ask about that sort of thing, since Malcovery Security has both a Spam Data Mine, which is often a good source for such messages, and our PhishIQ system. I thought if it existed to the point that there was "buzz" about it, I should have hundreds of copies. But I didn't. I had three. Kinda.

Here's what the emails actually looked like.

I'll tell you what it does in just a minute.

By the way, if you find phishing sites and aren't sure what to do with them, we LOVE collecting phish! Use Malcovery's PhishIQ Report Phish page to send us any links!

Target Gift Card Spam

When I ran my search, I found all of the "normal" Target spam. People love to use Target to convince people to give up their personal contact information through the "Impossible to get Gift Card" scam.

We've blogged about Gift Card spam and related malware on several occasions including:

  • Cyber Monday 2010 - when we warned about scams using Victoria Secrets and Oliver Garden gift cards. In that scam you have to complete a series of "tasks" in order to earn your gift card, after going through several steps where you think you have "won" something. The final tasks back then were things like "Stay three nights in a Red Horse Inn hotel's luxury suite" or "buy a new car from General Motors!" but LONG before you found out about those tasks, the criminals already had your email, home address, cell phone number, and your agreement to let them share that data with other marketing firms.

  • A Day in the Life of Spam (2009) - in that blog I tried to fully categorize 10,583 spam messages received on October 4, 2009. 28 of the emails were "Giveaway gotchas" -- gift cards, plane tickets, cell phones, laptops that you had "won" if you would just perform some tasks.

  • We also told you about the Member Source Media LLC case where the FTC fined Chris Sommer $200,000 for running his spam scam where he sent email for "Free Products that Weren't Free".

So, today, I wasn't surprised to see spam with subjects and senders like these:

Share Your Opinion. Do you Love TargetShopping OpinionShoppingOpinion@ramblerose.info
Share Your Opinion. Do you Love TargetTarget Shopping SurveyTargetShoppingSurvey@ramblerose.info
Shopped Target LatelyShoppingOpinionShoppingOpinion@ramblerose.info
Special: Snag a $100 Target Gift Card!SavingCenterUSASours@frigidfiz.com
Complete the Target Shopping SurveyShoppingOpinionShoppingOpinion@ramblerose.info
Chance to Get a $100 Target Reward! Complete Sponsor OffersSavingCenterUSABakewell@frigidfiz.com
Back to School Savings - get a $100 Target Gift CardSavingsCenterUSAKeels@coldfiz.com

Here's what these usually look like (or at least the more high end ones):

Target Phish? Not really ...!

All of those are normal, everyday occurrences. But these caught my eye!

Alert to Target Shoppers - your identity is at risk.Local Alerttps0128@yahoo.com

So what happens if you click on the links in the email? Let's find out!

Here's the Fiddler capture of the redirect stream: So, clicking on the link where it says "Has your identity been stolen - CLICK HERE to check the database" or where it says "CHECK TO SEE IF YOUR IDENTITY HAS BEEN STOLEN - CLICK HERE NOW!" takes you through a chain of "automatically redirected" websites:

  • www.mb01.com
  • www.maxbounty.com
  • khvx.secoptim.com
  • rewardzone.surveyblogonlne.com

All of those numbers out next to the URLs? Those are the Affiliate Codes and Redirect Codes, so the scammers can make sure to direct you to the correct scam and to make sure the right spammer gets credit for his hard work stealing your time, money, and possibly identity.

and then your "Political Opinion Survey" starts up . . .

The Fine Print

Before we go win our $1000 Shopping Voucher, make sure to read the fine print on that one . . .

rewardzone.surveyblogonlne.com is not sponsored by or affiliated with This Website. This Website has not authored, participated in, or in any way reviewed this advertisement or authorized it. The trial products offered on the last page pay this website for leads generated. *Free trial offers may require shipping and handling. See manufacturer's site for details as terms vary with offers.

You'll also want to pay special attention to

How Do We Use The Personal Information?

How Do We Use The Personal Information?

We may use the Personal Information for any legally permissible purpose in our sole discretion Ad Serving Companies

We may use third party ad networks or ad serving companies to serve advertisements on our websites. We may pass the Personal Information about you to these companies so that they can deliver targeted advertisements that they believe will be of interest to you. The information passed to these companies may include, but is not limited to, your IP address, e-mail address, name, mailing address, telephone number, date of birth, gender, and any other information you provide to us. Web pages that are served by these companies will be subject to their own applicable privacy policies, if any.

Marketing Partners

We may share, license or sell your Personal Information to third parties for various marketing purposes, including their online (e.g., e-mail marketing) and offline (e.g., telemarketing, cell phone text messaging, skip tracing, and direct mail) marketing programs.

That's just part of it, there are many additional things they can do with your data!

Back to the Survey

There was a third question, but you get the idea. I finish question 3, it congratulates me and then sends me to get my reward! Wait? Where is the Target Gift Card? Well, I guess $1,000 shopping voucher at Sears/JCPenney/Kohl's/Macy's will have to do for now. Oh! And there is only ONE remaining! I better snag that!

By our Fiddler trace, you can see that we've just been handed off from one Affiliate marketing program to another. We are leaving the "rewardzone" system, and headed to the "shopping-sweepstakes.com" system, with "t.afftrackr.com" making sure that everyone is going to get paid for their participation in scamming us.

So, here we go ... we said we wanted the $1,000 Sears/Macy's/Kohl's/JCPenney card, so we choose one and start our NEXT survey

After it "calculated my eligibility" it asked me for my email address. I accidentally hit "Back" then and now it is begging me not to go!

Oh goodie! More prizes! Hey? Wasn't I supposed to be getting $1,000 from JCPenney? I just got a big pay cut for all my hard work here. But that's cool, I shop at WalMart too. I'll take $150 Walmart card, I guess . . . Oh. Actually, our Fiddler tells us that we've swapped systems again...We're now on at www.marktflow.com.

But wait! We ALWAYS read the fine print!

Got that? You must complete 2 silver, 2 gold, and 8 platinum offers ... WITHIN ONE CALENDAR DAY! So, it's 6:00 PM for me now, so I have 6 hours to do all the offers, or I get NOTHING.

In case the website goes down later, here's a local copy of some of the "example offers" that you have to finish TODAY!

OK? Let the Privacy Rape Begin!

Here comes the personal information extract . . . first, we're going to need a PHONE NUMBER, EMAIL, BIRTHDATE, and GENDER. Why? Because $150 Walmart Gift Card, that's why!

OK, you get the point. . . I have 13 more questions to go . . . see the Progress Bar? We are SO CLOSE to getting our gift card! Let's skip through the rest of the questions for now, but ask yourself, "what is likely to happen now that I've told these people that I have a house, a car, I'm planning to move, I like to go on vacation, I have a pet, an active checking account, and at least $15,000 in debt, as well as the next 13 questions . . .

  • Are you currently employed full time?
  • Are you interested in continuing your education?
  • Do you have health insurance?
  • Do you ever pay out of pocket for prescription drugs?
  • Do you smoke?
  • Does anyone at your home suffer from Asthma?
  • Back Pain?
  • Diabetes?
  • Joint Pain?
  • Sleep Apnea?
  • Anxiety or Depression?
  • Have you had a colonoscopy?
Remember. This guy has your email address and your telephone number. Whew! At least our 20 questions are done, right?

And then we start getting all the pop-up offers!

Wait! My home address? My birthday? Oh yeah, I forgot...they have to ship me my Gift Card, so of COURSE they need my home address! Duh!

Just in case though, it might be worth noting in Fiddler that we are no longer talking to MarktFlow. Through T.AffTrackr.com (passing along the credit so the right scammers keep getting paid) we are now seeing offers from "www.offersfromqh.com" associated with "www.qualityhealth.com".

FINALLY! All I have to do is confirm my Email Address (I gave them a valid email: privacyrape@gmail.com wonder if it will start getting spam?) and now I will have my card! It says right there this is the Last Step, right?

Not quite. "YOU MUST INSTALL TO CONTINUE?" What am I installing?

My favorite part there, see the part where it says "I want to earn points for searching the web?" Make ShopAtHome.com my Default Search Provider. Make ShopAtHome.com my Default New Tab. (So, every time your browser opens a new tab, you reload the SearchAtHome.com website. How convenient!)

NOW, All I have to do it complete those 2 Silver, 2 Gold and 8 Platinum offers!

So, I have to EITHER buy a set of Santoku Cooking Knives, (which I can return and keep one $100 knife for FREE!) or sign up for CreditReport.com. I already have a Credit Report service, so I guess I'll buy the knives. That's one down!

Now I can either get Vitamins (don't believe in them), Dr. Seuss Book Club (don't have kids at home), Amora Coffee (I drink Starbucks and already have a local roaster's coffee delivered to the house), a Hunting Knife (I don't hunt), Disney Movie Club (no kids at home), or M-Go Movie Rentals (I already have NetFlix AND Hulu). Hmmm. $150 Walmart Gift Card though ... Shoot. I guess I'll buy some Dr. Seuss books for my nieces.

Wait ... The Gold Offers are mostly the Silver offers I didn't want! And I have to buy TWO of them! I can choose from M-Go movie rentals, a Non-stick ceramic skillet (only $79.95), Dr. Seuss book club sign-up, Disney Movie Club sign up, Sedona Beauty products sign up, or Amora Coffee sign up. Well, I don't have kids at home, and already have NetFlix, I'm already beautiful, and I already have coffee delivered to the house, so I guess I go for the Ceramic Skillet. Cool! It comes with free scissors! ($79.95 plus shipping) and . . . shoot I guess you can never have too much coffee!

Wait. I have to do EIGHT Platinum Offers?? Hmmm... I already bought the knives as my Silver, so I guess I buy the MuscleXLerator, because $150 Walmart Gift Card, and . . .

Oh heck. I'll take the Free Hunting Knife, Sign up from Freester.com, Get ProtectMyID by Experian (don't you wonder if these companies know so many of their referrals are from criminals? I wonder if they care?) Pimsleur Language Learning, because my Rosetta Stone has been on my shelf for two full years and I still can't speak Mandarin, (speaking of heavily spam-advertised products! Pimsleur! Shame on you!) How many is that . . . Shoot. I still need three more.

Well? I guess I'll get ActionProWhite teeth Whitener so I can have that inhuman glow in the dark smile, Join the Disney Movie Club (I can cancel at any time) and well, I do have a lot of wrinkles around my eyes, but that's because I smile so much. Come on Sedona Beauty Secrets!

NOW THAT, Ladies and Gentlemen, is How you get a Free $1000 Target Gift Card, except they actually plan to give me a $150 WalMart gift card instead . . . *IF* I complete 2 Silver, 2 Gold, and 8 Platinum tasks.

$1000 Target Gift Card? Tell the Spammers No Thank You!