MalwareCleaning

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Wednesday, November 14, 2012

Diablo account phishing

Posted on 6:04 AM by Unknown

Do you love the smell of phishing in the morning? I surely don't. In today's post we will be reviewing a phishing attempt for Diablo or Diablo III.

The following mail ended up in my mailbox:

You need to login as soon as possible to avoid account closing

There are other, less fancy examples:

Same trick as in the previous example. You need to "verify" your account


Subjects of the mail can vary, but these are the most common:
- Blizzard Notification About Diablo III Account
- Diablo III Account-Notice
- Diablo III Account - login validation‏
- You must verify your identity as the registered account .World of  Warcraft - Diablo III account (s).

The introduction in the email reads:

Greetings!   It has come to our attention that you are trying to sell your personal Diablo III account(s). As you may not be aware of, this conflicts with the EULA and Terms of Agreement. If this proves to be true, your account can and will be disabled.  It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership.


Let's move on to the actual link in the phishing mail. When clicked you'll land on the following page:

An exact copy of the real login page at Battle.net















Below you can find the list of URLs I've gathered in the past days, do not visit any of them as they may harm your computer (or even worse, your Diablo account ;-) ).

hxxp://battle.net.noreply-login.com
hxxp://cn15mcc.com
hxxp://eu.diablo.net.account.oy-login.in
hxxp://eu.diablo.net.account.ts-login.in
hxxp://eu.diablo.net.ca.zx-login.in
hxxp://eu.diablo.net.jiagedi.info
hxxp://eu.diablo.net.tianzhou58.info
hxxp://us.battle.com.wwowus.com
hxxp://us.battle.net.w.llweb.asia
hxxp://us.battle.net.ccus.asia
hxxp://us.battle.net.ddeu.asia
hxxp://us.battle.net.eacc.cn.com
hxxp://us.battle.net.en.oo-rs.com
hxxp://us.battle.net.en.qq-rs.com
hxxp://us.battle.net.en.uu-rs.com
hxxp://us.battle.net.ffus.asia
hxxp://us.battle.net.ggwow.asia
hxxp://us.battle.net.hhwow.asia
hxxp://us.battle.net.iieu.asia
hxxp://us.battle.net.llus.asia
hxxp://us.battle.net.login.en.ddus.asia
hxxp://us.battle.net.login.en.yykiki.com
hxxp://us.battle.net.login.en.zkiki.com
hxxp://us.battle.net.ok.jjweb.asia
hxxp://us.battle.net.ok.kk-rs.com
hxxp://us.battle.net.ok.qw-rs.com
hxxp://us.battle.net.ok.uuweb.asia
hxxp://us.battle.net.ok.yywow.asia
hxxp://us.battle.net.ppwow.asia
hxxp://us.battle.net.rreu.asia
hxxp://us.battle.net.uuwow.asia
hxxp://us.battle.net.w.llweb.asia
hxxp://us.battle.net.w-u.asia
hxxp://us.battle.net-bizzard-d3-com.account-com.net
hxxp://us.diablo.net.en.rk-login.in




Most of the domains seem to be set up by the same person, someone named "Jin Yu":
Registrant Contact:
   Jin Yu
   Yu Jin jinyu2000@yahoo.cn
   +86.324242434233 fax: +86.324242434233
   ShengLiLu
   Shangraoshi Jiangxi 610041
   CN

Other email addresses associated with Jin Yu:
329409115@qq.com
service@511web.com


Almost all of the IP addresses are originating from China. The hosting companies are as follows, and seem to not care (or know) that malware and phishing pages are set up:

Beijing Weishichuangjie Technical Development Co. - IPvoid Result
DEEPAK MEHTA FIE - IPvoid Result
New World Telecom Ltd., Hong Kong - IPvoid Result
XIN XIN LING - IPvoid Result


Thanks to IPvoid you can easily see other sites hosted there, seems there is more of the same. (read: more malware & phishing pages are hosted)




Conclusion

Stay away from phishing mails like the ones pointed out in this post. There are several variants, some more graphical than others, but in the end they serve the same purpose:
Trying to steal your login credentials!

I'm sure that even when you open the mail, alarm bells should be going off if you simply check the URL, it's pointing to another address than the usual login page.

To be clear, the real webpage to login for your Battle.net account is:
https://battle.net/login/en/

If you're ever in doubt, visit the website directly and do not click on any links in emails from unknown senders. Use add-ons like WoT and/or NoScript to stay protected against these types of threats.
You can also use the URL scanning services at VirusTotal or URLvoid to double-check a URL.



Read More
Posted in battle.net, blog update, d3, diablo, diablo III, diablo phishing, phishing, scam, spam | No comments

Friday, August 10, 2012

A word on XDocCrypt/Dorifel/Quervar

Posted on 5:39 AM by Unknown
I'm sure everyone has heard by now about the so called XDocCrypt/Dorifel/Quervar malware.

It has mostly damaged machines in The Netherlands, but reports have come in from other countries (including the United States) as well. I myself have seen this infection on 08/08/2012, my initial thought was: ransomware. However, there isn't any message displayed, so it's either a failed ransomware attempt or the malware simply wants to annoy users.

This virus infects Office files, reverses the extension and adds “.scr” behind it (this is also known as the RTLO unicode hole, which makes it easy to hide the original file extensions. - I remember a blogpost from not too long, about this hole targeting users of the Arabic language, let me know if you find it - ). Renaming does not solve the issue, you cannot open the documents.



Office files affected by the malware


As is depicted in the figure above, Word and Excel files have their extension reversed, so now the files appear to be .scr files, which is the format for a Screensaver. The .jpg file is not affected in any way.

The files are encrypted with RC4, which is a very common encryption algorithm in the cryptography. SurfRight has developed a tool to decrypt (and recover) your files:
Dorifel decrypter



The malware has probably been downloaded by the Citadel or Zeus (aka Zbot) malware.


Zeus sample:

remyf.exe
Result: 12/42
MD5: 30e7785cb9eafcea34fe930631fbba07
VirusTotal Report
Anubis Report



Let's take a look at a few Dorifel samples:

Acquisit.exe
Result: 15/42
MD5: d913394b8011b317f6d916507ffb7f2f
VirusTotal Report
Anubis Report


gis-woz4_v8.exe
Result: 12/42
MD5: a311cd6f67cb112cba78a27b87320fc3
VirusTotal Report
Anubis Report


DGRAYP.exe
Result: 24/42
MD5: f05f4f5be8431f746e59fe409a0b9bb1
VirusTotal Report
Anubis Report


Y6TK9B.exe
Result: 11/42
MD5: c1fa3618d7b54ab6a7a25857d7b30b3c
VirusTotal Report
Anubis Report



The malware tries to connect to one of the following IP addresses:
184.82.162.163 - IPvoid result
184.22.103.202 - IPvoid result


Where it will attempt to download the following file:

a.exe
Result: 13/42
MD5: 493887a87cd95b004f9ffbbaaecd1ac6
VirusTotal Report
Anubis Report



I haven't taken an in-depth look at it, but besides encrypting your Office files, I have seen the malware will kill itself when you open up Task Manager. Not sure what the point is there. It also doesn't seem to start up again automatically.

It does create an .lnk file to the dropped malware and puts that as an autorun entry, so it will start every time the machine starts.



Conclusion

The infection vector (how it spreads) is via phishing or spam email, so as usual:

- Don't open attachments from unknown senders - ever.
- Some antivirus already detected Dorifel generically, so update your antivirus.

- If you're in a corporate network, use a strong spamfilter. It will prevent a lot of troubles if correctly configured.
- Educate your users: raise the general awareness. Not even a spamfilter stops 100% of all the spam, there's always a chance something slips through.




Thanks to @erikremmelzwaal from Medusoft for most of the samples.

External sources:
  • http://blog.fox-it.com/2012/08/09/xdoccryptdorifel-document-encrypting-and-network-spreading-virus/
  • http://www.damnthoseproblems.com/?p=599
Read More
Posted in blog update, Dorifel, encryption, exprez, malware, phishing, Quervar, ransomware, sasfis, spam, XDocCrypt | No comments

Wednesday, April 11, 2012

Hacked Hotmail accounts... and the consequences

Posted on 4:14 AM by Unknown
It's a trend I'm seeing more and more, even with some of my relatives:

Their Hotmail account is getting hacked, and from then on is being used by scammers or malware authors to spread their malicious intent.

In almost all cases, you'll receive an email with (No Subject), and the only content is a link pointing to some website. But wait: it seems that all those websites have (probably an outdated version of) Wordpress installed.

When you click the link, you will be redirected to either a scam/phishing page or scareware/rogueware.

Either way, you'll first get the following message:


Message you receive when clicking on the link

So let's take a closer look at the 2 scenarios you get on your plate:

Scenario #1 - scam


Scam page

In scenario number one, you'll be presented with an awesome News page, where you can read several testimonials of how great working from home is.

It also has some fascinating news stories on how to make lots of money by simply being at your comfortable home. This includes reactions on the articles - of course this is all fake.

If you click on any of the links on this website, you'll be ultimately redirected to - hxxp://internetprofitpacket.com

Administrative Contact:
WhoisGuard
WhoisGuard Protected
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US


UrlQuery Result:
Suspicious
http://urlquery.net/report.php?id=40849

URLvoid Result:
1/25 (4.00%)
http://www.urlvoid.com/scan/internetprofitpacket.com/


Ultimately you land on the following page:


Landing page where you'll need to pay

After paying a small price, you'll get lifetime access to the Internet Profit Package ! What honor !

Obviously, you'll get scammed and your credit card details might get stolen.


Scenario #2 - scareware

Likewise as in scenario #1, you'll get the nice message that you got here thanks to your friend.


Seems like you're infected ... right ?

You'll then be presented with a pop-up indicating critical process activity has been found and a scan will be launched... (I think we all know this one by now) :


Fake Explorer window indicating numerous infections

If you click on any button, a file will be downloaded with the name of setup.exe.

In this case, the file was downloaded from:
hxxp://fail-safetylow.info/bb61f9bcec711d56/29/setup.exe

This site and several other rogueware pages are hosted on the IP:
64.120.207.107


Several other rogueware sites are hosted on this IP


We'll now see some more details about the downloaded file:

setup.exe
Result: 5/40
MD5: 8b0c16a50c0bca1eb0b45bd411eb30e5
VirusTotal Report
ThreatExpert Report
Anubis Report

This file drops another executable:

Protector-hfpt.exe
Result: 5/42
MD5: f04cb906356f19a1dbf68c62f162c4e7
VirusTotal Report
Anubis Report


The payload is a rogueware called "Windows Antibreaking System" :


Windows Antibreaking System setup screen



Windows Antibreaking System main screen


Prevention

- Most important of all: use a strong password ! You can verify your current password, or create a new one to check its strength on the following website: http://www.passwordmeter.com

- Second important rule:
don't use the same password for each and every website !

- Be wary when receiving such a mail, even if it's from someone you know.

- Use browser extentions to verify the integrity of an image or URL. Useful add-ons are for example WOT or NoScript.

- Keep your Antivirus and browser, as well as your browser add-ons up-to-date.

- If it is too late and a 'scan' is already starting, immediately close your browser by bringing up Task Manager (CTRL + ALT + DEL) and killing your browser's process:
  • a) For Google Chrome: chrome.exe or chrome.exe *32
  • b) For Mozilla Firefox: firefox.exe or firefox.exe *32
  • c) For Microsoft's Internet Explorer: iexplore or iexplore.exe *32


Desinfection

If the harm is already done and you are getting warnings, messages or pop-ups stating you are infected and you need to take 'immediate action' to clean your computer, follow the guide below at BleepingComputer's to rid yourself of this malware:

BleepingComputer's Virus Removal


Also, if you know the sender personally, notify him/her that they've been hacked and they need to change their password. If you don't know the sender, immediately remove the email.

In Hotmail, you even have a useful option if you know the sender. Open the email, select Mark as and click on My friend's been hacked!


Help your friend by stating (s)he's been hacked


If you happen to have a Wordpress website, be sure to update it regularly as well as any Wordpress plugins you may have installed. This website will aid you in the matter: Hardening WordPress



Conclusion

Don't fall for either of these, in both cases you'll lose a lot of money !

Follow the above prevention tips to decrease the chance of your computer becoming infected.
Read More
Posted in blog update, cracked hotmail, fakeAV, hacked hotmail, Hacked Hotmail accounts, malware, phishing, rogueware, scam, Windows Antibreaking System | No comments

Tuesday, April 10, 2012

Free Riot codes scam

Posted on 3:38 AM by Unknown
Below you can find a list of confirmed phishing and scam websites.


Update - 14/04/2012 - 21:35 CET
: Both the Facebook page and hxxp://freeriotcodes.com are offline now. There is one other Facebook page (+ 21,000 likes) and a few other websites which are still up & running, but I expect them to be down soon. Great work Riot Games !


Update - 13/04/2012 - 18:07 CET: It seems the domain(s) is (are) accessible again. I have however received an email from Riot and they will be working on the issue as well:

Riot Games working on the issue

Update
- 12/04/2012 - 17:07 CET
: Yesterday I reported the domain hxxp://freeriotcodes.com to their domain registrar, GoDaddy.com. They have acted very fast and the domain is already inaccessible. Great work !



However, the page on Facebook still exists, and a new post has been made explaining the current unavailability of their scam:


'Free Riot Codes' apologising for the inconvenience











I have reported the page to Facebook as well reported it to Riot Games themselves. Hopefully the Facebook page will be offline soon.

Note: another Facebook page is currently trying to scam people. It will be taken offline soon:
hxxp://www.facebook.com/RPCodeGiveaways
--- End Updates

Facebook. A social networking place. For some a dream come true, for others a true nightmare. Guess in which category phishers, scammers and malware authors reside ?


In today's post we will be highlighting a scam specifically focusing on players of the game League of Legends, an action real-time strategy game developed and published by Riot Games.

The scam page on Facebook in question is:
hxxp://www.facebook.com/pages/Free-Riot-codes/141669939249958

Currently, it already has over 41,000 likes:


More and more people are liking the page, thus might be getting scammed



On Youtube as well as on Google+ and Twitter it is -for now- pretty calm. Only a few video's and tweets promoting this scam:


On Twitter, Google+ and Youtube they are also promoting their website, but not as heavily as on Facebook


Some example website where you can get "free" riot points  or "free" riot codes are: 
hxxp://freeriotcodes.com            
hxxp://blogs.gamenov.us/lol
hxxp://cheatsjungle.com/league-of-legends-promotional-code-generator-2
hxxp://cheatsjungle.com/league-of-legends-riot-points-generator
hxxp://elohell.org
hxxp://free-riotcodes.info

hxxp://free-riotpointscodes.com
hxxp://free3600rp.byethost22.com
hxxp://freehackgames.org/league-of-legends-riot-points-generator-3-2-version              
hxxp://freeleaguecodes.com      

hxxp://freeleaguecodes.net       
hxxp://freeleagueoflegendsriotpoints.com
hxxp://freeleagueoflegendsriotpointcodes.com     
hxxp://freeleagueoflegendskins.co.uk         
hxxp://freelolriotcodes.com     

hxxp://freelolriotcodes.netii.net   
hxxp://freelolriotpointz.blogspot.com      
hxxp://freelolrpcodez.weebly.com  

hxxp://freelolskins.com            
hxxp://freeriotcodes.filegame.net              
hxxp://freeriotcodes.info   

hxxp://freeriotcodes.org           
hxxp://freeriotcodes.weebly.com              
hxxp://freeriotcodesgift.com   

hxxp://freeriotpoints.me       
hxxp://freeriotpointsclub.com  
hxxp://freeriotpointscode.com 

hxxp://freeriotpointsgenerators.blogspot.com    
hxxp://freeriotpointsleagueoflegends.blogspot.com         
hxxp://freeriotpointsnow.com              
hxxp://freeriotpointss.com              
hxxp://freerpcodes.com              
hxxp://freerpcodes.tk              
hxxp://getfreeriotcodes.blogspot.com              
hxxp://getfreeriotcodes.com              
hxxp://getfreeriotpoints.com    

hxxp://getfrenocturneskin.webs.com          
hxxp://getriotcodes.com       

hxxp://getriotpoints.info       
hxxp://getriotpointscodes.com    

hxxp://getriotpointsforfree.com 
hxxp://getriotpointsfree.com
hxxp://gogamecheats.com/league-of-legends-free-riot-points  
hxxp://hackerzzs.blogspot.com               
hxxp://hackscheatsgamesprograms.blogspot.com 
hxxp://league-gamers.com
hxxp://leagueoflegends.byethost33.com
hxxp://leagueoflegends2012hack.blogspot.com             
hxxp://leagueoflegendsrphack.com              
hxxp://leaguerp.com   

hxxp://leaguerpgifts.com        
hxxp://leagueoflegendsgenerator.wordpress.com
hxxp://leagueoflegendsrpcodegenerator.blogspot.com    
hxxp://leagueoflegendsrpcodegenerator.weebly.com
hxxp://leagueflegendvoteasestribunall.gaming.lc
hxxp://live.rpgiveaway.com             

hxxp://lolhacktool.blogspot.com 
hxxp://lolfreeriotpoints.blogspot.com              
hxxp://lolmultihack2012.blogspot.com 

hxxp://lolpromobundles.blogspot.com             
hxxp://lolriotpointcodes.blogspot.com              
hxxp://lolrpgenerator.webs.com         

hxxp://lordhacks.com/league-of-legends-hack
hxxp://lordhacks.com/league-of-legends-promotional-code-generator
hxxp://oisn.mypressonline.com/league
hxxp://rafflesforprizes.com

hxxp://riot-codes.com
hxxp://riot-points.free-cards.info   
hxxp://riot.edgehacking.com              
hxxp://riot.freecodesgiveaway.com              
hxxp://riotcodegenerator.com              
hxxp://riotcodes.hacksfiles.com              
hxxp://riotcodes.net              
hxxp://riotcodesforfree.org              
hxxp://riotcodesfree.com              
hxxp://riotcodesfree.net

hxxp://riotgames.qualtrics.com  
hxxp://riotpointcodes.org
hxxp://riotpoints.cu.cc   
hxxp://riotpoints.net
hxxp://riotpointsadderforfree.blogspot.com
hxxp://riotpointscampaign.com        
hxxp://riotpointscodes.info  

hxxp://riotpointsgeneratorfree.blogspot.com           
hxxp://riotpointsfree.com   

hxxp://riotpointsgenerator.co
hxxp://riotpointsgenerator.org   
hxxp://riotpointshop.com        
hxxp://riotpoints-free.com

hxxp://rpcodes.info 
hxxp://rpfree.com
hxxp://rprewards.com
hxxp://rp-free.blogspot.com              
hxxp://rpgiveaway.com              
hxxp://videogamehacks.net/riot-points-generator

hxxp://xpandhacks.net/league-of-legends-riot-points-generator
hxxp://xpandhacks.com/league-of-legends-riot-points-generator-2                

You can +1 it, share it on Facebook, Tweet it ... Share the scam with everyone you like ;-) .

The first link in bold is the one that is visited -and used the most. All you have to do to get your Riot Points for free is to follow these 3 easy steps:

Step 1 - Share it on Facebook
Step 2 - Post the following message once on your wall and 5 times on a Different Game Page on Facebook:
WOW! I just got my League of Legends Riot Code for free! So excited! Thanks hxxp://freeriotcodes.com !
Step 3 - Click "Like and Confirm"


Step 2 in the process - posting on Facebook. In this specific scam, it is not being posted automatically to your wall, you actually have to share it yourself


That's it, 3 simple steps and then you'll be able to download your Riot Points or codes free of charge !

... But wait, there's a timer on the page indicating you'll have to wait before the next giveaway:




Somehow, I got lucky and, through one of the other websites, I was able to visit the download page and acquire my points !

However, ultimately I have to complete a survey to finally download my Riot points. I am getting redirected to several other scams and so on. You can win a smartphone, the new iPad, an iPhone, trendy boots, a Macbook ....

In some cases only your phone number is sufficient, in others you'll have to fill in complete information like your full address, email address ...

Some examples of dubious file sharing websites, which are also showing a popup with some Javascript behind it (another survey scam):
hxxp://cleanfiles.net
hxxp://fileice.net
hxxp://fileme.us
hxxp://fileml.com
hxxp://filenix.com
hxxp://matrixmega.com
hxxp://oceanfiles.me
hxxp://sharecash.org
hxxp://sharkyfiles.com 
hxxp://skippyfile.com 
hxxp://speedyfiles.net
hxxp://tinyfileshost.com
hxxp://topfiles.me


Let's get back to the scam site itself - hxxp://freeriotcodes.com
Registrant:
Hal Medus
10612 Parliament Ave
Garden Grove, California 92840
United States

Administrative Contact:
Medus, Hal hackzforyou@gmail.com
10612 Parliament Ave
Garden Grove, California 92840
United States
6572017037


UrlQuery Result:
Suspicious
http://urlquery.net/report.php?id=40190

URLvoid Result:
2/25 (8.00%)
http://www.urlvoid.com/scan/freeriotcodes.com/



Conclusion

Pretty straightforward: do not click on any of these scams, how tempting they might be! You will not receive a prize, you will not receive a free iPhone and you will certainly not receive any Riot Points or Riot codes! Certainly, never fill in your login credentials!

Some tips:
[*] Install WOT - WOT is a community-based tool and is therefore very useful for these kinds of scams, whereas other users can warn you about the validity.
More information and to download WOT: http://www.mywot.com/

[*] When in doubt, use any of the following URL scanners:
https://www.virustotal.com/#url
http://www.urlvoid.com
http://urlquery.net

[*] The most important one of them all:
if it looks too good to be true, it probably is!
Read More
Posted in blog update, facebook scam, free riot code scam, free riot codes, free riot points, free riot points scam, League of Legends, LoL, phishing, Riot codes scam, survey scam | No comments

Tuesday, December 6, 2011

New Facebook scam

Posted on 6:26 AM by Unknown
A new Facebook scam is spreading today, 6th of December. The interesting thing is that I have seen it posted in Dutch as well.

The method used is the same as in previous Facebook scams, see for example my earlier post:
New Facebook scam

Here is the post in question (in Dutch):


Classical scam post to lure users into clicking the link.

Here's what it reads:
WOW! Mijn profiel is ALLEEN VANDAAG AL 12 keer bekeken.. en ik kan zien dat er behoorlijk wat stalkers bijzitten LOL! Kijk zelf wie jou allemaal in de gaten houdt op #removed#

In English:

WOW! My profile has been seen 12 time ALREADY ONLY TODAY .. and I can see that quite a few stalkers are included LOL! See for yourself who's keeping an eye on yoy on #removed#



The link has been shortened by the bit.ly URL shortening service. While this service is not malicious on itself, it can also be used by persons with malicious intent, whether it would be hackers, malware authors, ... Or in this case scammers.

Let's review some stats for the bit.ly link first:


98 clicks on this link in the last hour



Top countries, including: France, Germany, The Netherlands



Facebook.com is the most referring site


At the moment of writing, there have been over 1,000 clicks on the link so far. I have already reported it to bit.ly and it should be taken down soon.

UPDATE: bit.ly has already issued a warning for when you click on the link. (12/07/2011)


Now let us analyse where the bit.ly link is taking us. The link can redirect you to different websites, but they will all (so far) redirect you to a page similar to this one (depending on your location):


Who is viewing your Facebook profile ?


You probably don't remember my post from February this year, but the concept is the same: you can supposedly view who's been "stalking", or viewing, your profile. This to attract users on clicking the link. Who doesn't want to see this, right ? Here is my post from early this year:
Facebook rogue applications still lurking around

You can presented with a screen like this (I have several, but I will only post one as example):

Are you the "lucky" winner ?

As stated previously, the concept is the same. Before you can see who's been viewing your profile, you need to fill in a short service to continue.

You may have won a prize, you may have won an iPad, you may have won free ringtones, you may have won a free iPhone application, etc, etc, etc, .... This is of course all a lie.
Remember: if it looks too good to be true, it probably is !

You have to fill in your email address and/or phone number to continue as well. At the end you will end up losing a lot of money, leaving your email address in the open and maybe worse.

Remember: if you click the link while logged in to Facebook, it will also post it on your own wall.



Conclusion

Conclusion is pretty straightforward: do not click on any of the links ! If in doubt, send your friend on Facebook (or if someone sent you the link) via PM if he or she knows what this is about.

To remove this from your or your friend's wall, click on the X on the message, and choose to "Report/Mark as spam" or "Remove Post".

You can also use a linkscanner to verify the integrity of a link on either http://www.urlvoid.com or https://www.virustotal.com/

To get some information on a bit.ly (or other URL shortener serivce) link, you can use any of the following websites:
- http://www.getlinkinfo.com/
- http://longurl.org/
- http://www.longurlplease.com/ (includes Firefox extension)

To report a malicious bit.ly link use:
http://bitly.com/a/report_spam

For any other question, do not hesitate to post a comment !
Read More
Posted in blog update, facebook, phishing, scam, spam, spim | No comments

Wednesday, April 13, 2011

Increase in Dutch banking phishing

Posted on 6:07 AM by Unknown
Recently I made a post on Malware Disasters about an increase of targeted phishing in the last few monts. The focus was mainly on Dutch (and Belgian) customers of respectively Rabobank and ING, two major banks.

Here's a small excerpt:

The last few months there was an increase in a phishing campaign targeted on customers from Rabobank and ING, two major banks in The Netherlands and Belgium. Some examples of a phishing mail:


Phishing email for ING with the subject “Account Verificatie” (or in English: “Account Verification”)

You can read the full article here:
http://malwaredisasters.blogspot.com/2011/04/increase-in-dutch-banking-phishing.html

You can also download a Dutch (Nederlands) translation from the following link:
Click HERE to download. (hosted on Uploading.com)





Conclusion

The following tips do not only apply to the above story, but apply to any other (suspicious) email you receive:
  • Do not click on any of the links (or anything for that matter) in the email you have received.
  • Do not reply to the email.
  • Delete the email immediately, certainly if you are not a customer of the aforementioned bank or did not order anything, changed your password, and so on.

  • If you really need to access or check your bank account, visit the website directly by typing the address in your browser’s address bar. Also verify the URL starts with https instead of http.
  • Another useful trick is to hover over the link in the email. In the bottom left corner you should be able to see the real address behind the URL displayed.
  • When in doubt, you can double-check using URL scanning services such as VirusTotal or URLVoid
Read More
Posted in blog update, ING, phishing, rabobank, spam, spear phishing | No comments

Saturday, February 26, 2011

Windows Live Phishing

Posted on 3:38 AM by Unknown

This morning I received an email claiming that the database and email account center for Windows Live would be upgraded. They need to delete all unused account and to make sure that yours won't be deleted, you have to notify the Windows Live team.


Email subject: Account Alert!!
Windows Live Team Alert Confirmation


You need to reply with your User name, Password, Date of Birth and Country or Territory. In reality this is a typical phishing campaign for retrieving your login details.


In the last 2 paragraphs it also states:

"YOUR DETAILS WILL NOT BE SHARED"
-> this is to comfort you so you know that your credentials are safe
and
"Warning!!! Account owner that fails to verify his/her account after two weeks of receiving this warning will lose his or her account permanently."
-> This is your typical scare tactic; if you don't do as instructed, your email account will be deleted.



Conclusion

In reality, Windows Live will not send you any emails instructing you to send your password to them so they can verify it is still active. Also, they won't delete your account without a valid reason.

Never reply to these kinds of messages, delete the email and you're good to go.

Read More
Posted in blog update, hotmail, phishing, spam, windows live | No comments

Tuesday, February 15, 2011

Facebook rogue applications still lurking around

Posted on 11:16 AM by Unknown

Recently I made a post on Malware Disasters about rogue applications on Facebook.

Here's a small excerpt:

For quite some time now there are rogue applications trying to convince you that you are able to check whoever viewed your profile. There are a lot of different names for this rogue application, some but not all include:


  • creep exterminators
  • catch them being creepy
  • creepy profile peekers
  • privacy bros
  • we catch stalkers


Profile Creeps application



You can read the full article here:
http://malwaredisasters.blogspot.com/2011/02/facebook-rogue-applications-still.html



Conclusion

Conclusion is quite simple: never trust an application on Facebook that promises things that look too good to be true. When things look too good to be true, they probably are ;) .

Always be careful when allowing applications access to your data and/or wall.

Read More
Posted in blog update, facebook, malware, phishing, scam | No comments

Saturday, February 5, 2011

Scam tactic still active

Posted on 1:16 PM by Unknown
In a previous post I already warned you about New scam/phishing tactics .

Recently I received a similar email, telling me my Google Earth boarding pass is ready.
Apparently the same guys are back trying their tactic once again.

The subject of the email was
Google Earth Enhancement: Your Boarding Pass is Ready


Email from 'The Earth Team'


Banner urging you to download the 2011 version


The domain where you can 'buy' Google Earth is listed below. Note it might still be active, so be careful with the link(s).

hxxp://earth-online-locations.com
Result: 1/17 (6 %)
Domain Hash: 080a81b600bddf891a7b473e5958ab9f
URLVoid
VirusTotal


Conclusion

Basically the same as in my previous post. Simply delete the email and don't look back.

If you really want to download Google Earth, you can download it directly (and for free) from http://www.google.com/earth/index.html


Read More
Posted in blog update, google earth, phishing, scam, spam | No comments

Thursday, December 2, 2010

new rogue domain: privacyguard2010.com

Posted on 12:44 PM by Unknown
Whois record for privacyguard2010.com

Registrant Contact:
Name: Bayangol Duureg, Undsen Khuuliyn Gudamj 24
Address: 15111 N. Hayden Rd., Ste 160, PMB 353
City: Ulaanbaatar
Country: Mongolia

hxxp://privacyguard2010.com
Result: 3/17 (18 %)
Domain Hash: fec975d80b19c2ec3ce80fac1cd7800b
URLVoid
Note: this page does not trigger a "scan" of your computer, however, you can download a malicious file. Visit at own risk !

Some related domains:
hxxp://pcprotectioncenter.com/
hxxp://privacycorrector.com/
hxxp://pcoptimizer2010.com/
hxxp://psccenter.com/
hxxp://controlcenter2011.com/


The following file was downloaded:
setup.msi
Result: 1/43 (2.3%)
MD5: 92577052e1f4f51cb74d37727d032168
VirusTotal
ThreatExpert Report

This file drops:
PCoptimizer2010.exe
Result: 2/43 (4.7%)
MD5: 6ad932b045a4ac666659d496a81af52d
VirusTotal
Anubis Report
ThreatExpert Report

Screenshot examples:

PrivacyGuard 2010 home page


When executing the file (PCoptimizer2010.exe)
PrivacyGuard 2010 installation wizard
Read More
Posted in blog update, fakeAV, malware, phishing, rogueware | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • League of Legends RP hack
    I recently blogged about a (still current) scam targeting players of the online game League of Legends: Free Riot codes scam . When re-check...
  • test for the blog
    Just testing ... :-)
  • Facebook Support. Personal data has been changed!
    There appears to be a new malicious email being sent out with the subject: " Facebook Support. Personal data has been changed! ID7530...
  • WinMHR: Free Malware Detector
    Today I checked out WinMHR brought to you by: Team Cymru Now, what exactly is WinMHR ? (This is copied from the website) WinMHR is... Free ...
  • Malware Puzzle
    A malware (crossword) puzzle you say? Yes! Why not? I've made a puzzle about malware (and security) related keywords. It comes in .PNG f...
  • Brazilian banking Trojan tricks
    So I encountered what I suspect to be a banker focused on Brazilian banks. (Win32/Bancos) Part 1 - spam mail : Fiscal note Mail from: mail.u...
  • Increase in Dutch banking phishing
    Recently I made a post on Malware Disasters about an increase of targeted phishing in the last few monts. The focus was mainly on Dutch (an...
  • Gina Lisa Facebook scam
    Yet another Facebook scam, this time luring users with a sextape from Gina Lisa, whom is apparently a German model: Yet another Facebook sca...
  • A word on XDocCrypt/Dorifel/Quervar
    I'm sure everyone has heard by now about the so called XDocCrypt/Dorifel/Quervar malware. It has mostly damaged machines in The Netherla...
  • FedEx spam loads malware
    Received an email from (supposedly) FedEx today, seems my parcel was unable to be delivered: Print your receipt!     Mail details: Subject: ...

Categories

  • ACH transfer
  • adobe
  • adobe exploit
  • ADP
  • adware
  • affiliate
  • all your data are belong to us
  • antimalware
  • asprox
  • bancos
  • banking trojan
  • basic malware cleaning
  • battle.net
  • blackhole exploit kit
  • blog update
  • botnet
  • brazilian banking trojan
  • brucon
  • change facebook color
  • conduit
  • cracked hotmail
  • credit card blocked
  • crimeware kit
  • CVE-2006-0003
  • CVE-2010-0840
  • CVE-2012-4681
  • cybercrime
  • d3
  • diablo
  • diablo III
  • diablo phishing
  • DLL injection
  • Dorifel
  • dorkbot
  • encryption
  • end of july
  • exploit
  • exploit kit
  • exprez
  • facebook
  • facebook dislike button
  • facebook event
  • facebook scam
  • Facebook spam
  • facepalm
  • Fake Symantec security check
  • fakeAV
  • fareit
  • FedEx
  • FedEx spam
  • first post
  • flv media player
  • foistware
  • free riot code scam
  • free riot codes
  • free riot points
  • free riot points scam
  • free RP generator
  • fun
  • gina lisa
  • google earth
  • google image poisoning
  • google images
  • hacked hotmail
  • Hacked Hotmail accounts
  • hakin9
  • Hewlett-Packard ScanJet
  • hotfile
  • hotmail
  • illegal games
  • infostealer
  • ING
  • IP and RP Hack Download
  • java
  • java exploit
  • kuluoz
  • lame old malware
  • League of Legends
  • League of Legends MultiHack Generator
  • League of Legends RP generator
  • League of Legends RP hack
  • linkedIN
  • LoL
  • LoL RP Hack
  • low detection
  • malvertising
  • malware
  • malware analysis
  • malware analysis lab
  • malware cleaning
  • malware lab
  • malware puzzle
  • malware tools
  • medfos
  • messenger
  • MSN
  • neosploit exploit kit
  • paypal
  • paypal spammail
  • PC Speed Maximizer
  • pcspeedplus
  • PDF
  • phishing
  • poker games
  • potentially unwanted program
  • pricegong
  • PUP
  • pushdo
  • Quervar
  • Question and Answer
  • rabobank
  • ransomware
  • rapidshare
  • redkit exploit kit
  • RemovalTool.exe
  • Riot codes scam
  • Riot points scam
  • roguevertising
  • rogueware
  • rootkit
  • sasfis
  • scam
  • scareware
  • security
  • security conference
  • security.nl
  • skype
  • skype worm
  • social engineering
  • spam
  • spear phishing
  • spim
  • survey scam
  • team cymru
  • technoviking
  • tepfer
  • test
  • trojan
  • twitter
  • United Parcel Service
  • UPS
  • UPS spam
  • verizon spam
  • video
  • vmware
  • wellsfargo
  • whitesmoke
  • Windows Antibreaking System
  • windows live
  • WinMHR
  • worm
  • XDocCrypt
  • yontoo
  • youtube
  • youtube comment spam
  • youtube spam
  • youtube top comments
  • zeus

Blog Archive

  • ▼  2013 (18)
    • ▼  September (2)
      • Malware: the blame game
      • PayPal spam leads to malware cocktail
    • ►  August (2)
    • ►  July (1)
    • ►  June (3)
    • ►  May (2)
    • ►  April (1)
    • ►  March (1)
    • ►  February (3)
    • ►  January (3)
  • ►  2012 (14)
    • ►  November (1)
    • ►  October (2)
    • ►  September (2)
    • ►  August (3)
    • ►  July (1)
    • ►  June (2)
    • ►  April (3)
  • ►  2011 (15)
    • ►  December (1)
    • ►  September (1)
    • ►  June (1)
    • ►  April (3)
    • ►  March (1)
    • ►  February (5)
    • ►  January (3)
  • ►  2010 (14)
    • ►  December (3)
    • ►  November (1)
    • ►  October (6)
    • ►  September (2)
    • ►  August (1)
    • ►  March (1)
Powered by Blogger.

About Me

Unknown
View my complete profile