MalwareCleaning

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, June 12, 2012

LinkedIn spam, exploits and Zeus: a deadly combination ?

Posted on 1:46 PM by Unknown
Is this the perfect recipe for a cybercriminal ?:
  1. Hacking LinkedIn's password (and possibly user-) database.
  2. Sending an email to all obtained email addresses, which is urging you to check your LinkedIn inbox as soon as possible.
  3. A user unawarely clicking on the link.
  4. An exploit gets loaded. Malware gets dropped. Malware gets executed.
  5. User's computer is now a zombie (part of a botnet).

I would definitely say YES.

A reader of my blog contacted me today, he had received an email from LinkedIn which was looking phishy. We can verify that Step 1 is accomplished, by the simple fact that in the "To" and/or "CC" field of the email below, there are about ~100 email addresses. A quick look-up of a few of them on LinkedIn reveals the unconvenient truth...

Here's the email in question:


Reminder from LinkedIn. You got a new message !


Subjects of this email might be:
"Relationship LinkedIn Mail‏", "Communication LinkedIn Mail‏", "Link LinkedIn Mail" or "Urgent LinkedIn Mail‏". No doubt the subjects of this email will vary, and are not limited to these four.


Step 1 and step 2 of the cybercrook's scheme are already fulfilled. Now he just has to wait until someone clicks on one of the links. Which brings us to point 3.

Suppose someone clicks on the link. What will happen exactly ? This depends on the version of these programs that may be installed on your computer:
  • Adobe Reader
  • Java

In some cases, your browser will crash. In other cases, the page will just appear to sit there and nothing happens. In unfortunate cases, the exploit will begin doing its work. As said before, a mixed flavor of Adobe & Java exploits are used.

In this case, we will review the specific Adobe exploit. We will check with Process Explorer what exactly is happening:


The green highlighting indicates the spawning of a new process

What's this ? There's a process from Adobe Reader loaded under our Internet Explorer ? Which seems to spawn a .dll file ? Which in turn spawns another file .... Okay, you get the point here.

The PDF file has several embedded files, which are dropping malicious executables and executing them. After the process of spawning and dropping processes and executables, the malware will also clean-up any leftovers, including the PDF file at first:


Message from Adobe Reader it has crashed. Have a guess why

After the user clicks OK, everything looks fine. Right ? No, of course not. Ultimately, there's a malicious executable which will start every time the computer boots.

Interesting to note is, that there is also an attempt to exploit CVE-2006-0003. An exploit from 2006 nonetheless !

Step 3 and 4 have also been accomplished now. The user clicked on the link, the exploit(s) got loaded and the user is now infected. With what you may ask ? Well, let's review all the associated files:


The initial Java exploit - set.jar -
(when I first uploaded this sample a few hours before this blogpost, there were ZERO detections)

Result: 2/42
MD5: b0697a5808e77b0e8fd9f85656bd7a80
VirusTotal Report
ThreatExpert Report

I just now re-uploaded set.jar (17:47:41 UTC), it has now 6 detections. Most probably the Blackhole exploit kit is responsible for this attack. Microsoft identifies the file as
"Exploit:Java/CVE-2010-0840.NQ".
The corresponding CVE can be found here.



"I got Java patched, always", you might say. Great ! How about Adobe Reader ?
c283e[1].pdf
Result: 11/38
MD5: ad5c7e3e018e6aa995f0ec2c960280ab
VirusTotal Report
PDFXray Report
MWTracker Report


Thanks to PDFiD, we are able to see there's an AcroForm action and 6 embedded files. Basically, AcroForm is just another way to execute JavaScript in a PDF document. Embedded files are... files hidden in your PDF document:


PDFiD results



Here's our first dropped file - calc[1].exe
Result: 5/38
MD5: 4eead3bbf4b07bd362c74f2f3ea72dc4
VirusTotal Report
ThreatExpert Report
Anubis Report


Calc[1].exe will drop other files. Examples:


amutwa.exe
Result: 9/42
MD5: e7e25999ef52e5886979f700ed022e3d
VirusTotal Report
ThreatExpert Report
Anubis Report


nyyst.exe
Result: 10/42
MD5: fbc4bb046449fd9cef8a497941457f4f
VirusTotal Report
ThreatExpert Report
Anubis Report


The malware will try to 'phone home' or connect to the following IP addresses:
188.40.248.150 - IPVoid Result
46.105.125.7 - IPVoid Result

The IPs above (188.40.248.150 in particular) are part of a known botnet.

After all 4 steps have been executed, Step 5 of the process is completed as well and the machine will be successfully part of a botnet. The Zeus botnet. For more information about Zeus, you can read upon the (limited in information, but sufficient) Wikipedia article:
Zeus (Trojan Horse)

There are also numerous articles on the Zeus botnet, the takedowns by Microsoft (whether they were successful or not, I'll leave in the middle), and many other reports.



Conclusion

So, what did we learn today ? If you do not know the answer to this question, please re-read the article again.

PATCH PATCH PATCH people ! Keep ALL of your software up-to-date ! This means Adobe, Java, but don't forget other software, for example VLC, Windows Media Player.... You get the picture.

This also includes installing your Windows patches, keeping your browser up-to-date as well as any plugins or add-ons you might have installed.

If possible, avoid using Adobe and/or Java. There are alternatives. An alternative for Adobe is for example Sumatra PDF. Just don't forget to patch the alternatives as well !

Finally, use an up-to-date Antivirus product to keep your machine safe should you not have done any patching. Chances are you might still be infected, but are already less likely.

If you are in a corporate or business network, take the necessary actions and include several layers of protection. This also includes informing your users to not click on everything in an email ! Applying the appropriate Security Rights on a machine can prevent you from having a whole lot of work.... and lack of sleep ;-) .


Note:
If you are interested in the files discussed in this post, contact me on Twitter:
@bartblaze

Read More
Posted in adobe exploit, blog update, CVE-2006-0003, CVE-2010-0840, exploit, java exploit, linkedIN, low detection, malware, PDF, spam | No comments

Tuesday, April 24, 2012

You HAVE to check this picture

Posted on 7:22 AM by Unknown
In today's post, we'll be highlighting an older trick that's being used again by spammers and malware authors.

I received the following mail:


"Excuse me,I got to show you this picture in attachment. I can't tell who gave it to me sorry but this chick looks a lot like your ex-gf. But who's that dude??."


Some other example mails with a similar subject and content:
RE:Check the attachment you have to react somehow to this picture
Hello ,
I have a question- have you seen this picture of yours in attachment?? Three facebook friends sent it to me today... why did you put it online? wouldn't it harm your job? what if parents see it? you must be way cooler than I thought about you man :)))) .

RE:You HAVE to check this photo in attachment man
Hi there ,
But I really need to ask you - is it you at this picture in attachment? I can't tell you where I got this picture it doesn't actually matter... The question is is it really you???.

There are a few more but I'll stop there. In all cases, you HAVE to check the picture in attachment, how else can you be sure it's not you in an embarrasing photo ;-) ?

Attached is a file called IMG9837.dat. In fact, an executable is embedded with the exact same name:


An Adobe icon is used to trick the user


When executing this file, it will phone home or call back (this term is used for malware that is connecting to a remote address for either receiving instructions or downloading additional malware) to the following IP: 92.246.166.131


Scanreport by IPvoid - http://ipvoid.com/scan/92.246.166.131


In this case, the malware downloads an additional executable called fas.exe. Let's review some more information about both files:


IMG9837.exe
Result: 26/42
MD5: bc3f1b422b01781ad23bd33340ece671
VirusTotal Report
ThreatExpert Report
Anubis Report


fas.exe
Result: 3/41
MD5: 6ffb6ce20915dfb7f723d46fcea87b3f
VirusTotal Report
ThreatExpert Report
Anubis Report


In this case, fas.exe will load one of the known fake Defragger rogues, for example:


System Defragmenter. This rogueware also hides your Desktop and Start Menu
(picture: bleepingcomputer.com)




Prevention

- Be wary when receiving such emails, even if it's from someone you know.
- Don't open attachments from unknown senders - ever.



Desinfection

If the harm is already done and you are getting warnings, messages or pop-ups stating you are infected and you need to take 'immediate action' to clean your computer, follow the guide below at BleepingComputer's to rid yourself of this malware:

BleepingComputer's Virus Removal


Conclusion

Pretty simple. Never open any emails from unknown senders, and certainly not attachments.

Keep your Antivirus and Operating System up-to-date, as well as your applications (for example Adobe and Java) !

Follow the steps above should you have been hit by this spam campaign/rogueware.
Read More
Posted in blog update, fakeAV, malware, rogueware, spam | No comments

Wednesday, April 11, 2012

Hacked Hotmail accounts... and the consequences

Posted on 4:14 AM by Unknown
It's a trend I'm seeing more and more, even with some of my relatives:

Their Hotmail account is getting hacked, and from then on is being used by scammers or malware authors to spread their malicious intent.

In almost all cases, you'll receive an email with (No Subject), and the only content is a link pointing to some website. But wait: it seems that all those websites have (probably an outdated version of) Wordpress installed.

When you click the link, you will be redirected to either a scam/phishing page or scareware/rogueware.

Either way, you'll first get the following message:


Message you receive when clicking on the link

So let's take a closer look at the 2 scenarios you get on your plate:

Scenario #1 - scam


Scam page

In scenario number one, you'll be presented with an awesome News page, where you can read several testimonials of how great working from home is.

It also has some fascinating news stories on how to make lots of money by simply being at your comfortable home. This includes reactions on the articles - of course this is all fake.

If you click on any of the links on this website, you'll be ultimately redirected to - hxxp://internetprofitpacket.com

Administrative Contact:
WhoisGuard
WhoisGuard Protected
+1.6613102107
Fax: +1.6613102107
11400 W. Olympic Blvd. Suite 200
Los Angeles, CA 90064
US


UrlQuery Result:
Suspicious
http://urlquery.net/report.php?id=40849

URLvoid Result:
1/25 (4.00%)
http://www.urlvoid.com/scan/internetprofitpacket.com/


Ultimately you land on the following page:


Landing page where you'll need to pay

After paying a small price, you'll get lifetime access to the Internet Profit Package ! What honor !

Obviously, you'll get scammed and your credit card details might get stolen.


Scenario #2 - scareware

Likewise as in scenario #1, you'll get the nice message that you got here thanks to your friend.


Seems like you're infected ... right ?

You'll then be presented with a pop-up indicating critical process activity has been found and a scan will be launched... (I think we all know this one by now) :


Fake Explorer window indicating numerous infections

If you click on any button, a file will be downloaded with the name of setup.exe.

In this case, the file was downloaded from:
hxxp://fail-safetylow.info/bb61f9bcec711d56/29/setup.exe

This site and several other rogueware pages are hosted on the IP:
64.120.207.107


Several other rogueware sites are hosted on this IP


We'll now see some more details about the downloaded file:

setup.exe
Result: 5/40
MD5: 8b0c16a50c0bca1eb0b45bd411eb30e5
VirusTotal Report
ThreatExpert Report
Anubis Report

This file drops another executable:

Protector-hfpt.exe
Result: 5/42
MD5: f04cb906356f19a1dbf68c62f162c4e7
VirusTotal Report
Anubis Report


The payload is a rogueware called "Windows Antibreaking System" :


Windows Antibreaking System setup screen



Windows Antibreaking System main screen


Prevention

- Most important of all: use a strong password ! You can verify your current password, or create a new one to check its strength on the following website: http://www.passwordmeter.com

- Second important rule:
don't use the same password for each and every website !

- Be wary when receiving such a mail, even if it's from someone you know.

- Use browser extentions to verify the integrity of an image or URL. Useful add-ons are for example WOT or NoScript.

- Keep your Antivirus and browser, as well as your browser add-ons up-to-date.

- If it is too late and a 'scan' is already starting, immediately close your browser by bringing up Task Manager (CTRL + ALT + DEL) and killing your browser's process:
  • a) For Google Chrome: chrome.exe or chrome.exe *32
  • b) For Mozilla Firefox: firefox.exe or firefox.exe *32
  • c) For Microsoft's Internet Explorer: iexplore or iexplore.exe *32


Desinfection

If the harm is already done and you are getting warnings, messages or pop-ups stating you are infected and you need to take 'immediate action' to clean your computer, follow the guide below at BleepingComputer's to rid yourself of this malware:

BleepingComputer's Virus Removal


Also, if you know the sender personally, notify him/her that they've been hacked and they need to change their password. If you don't know the sender, immediately remove the email.

In Hotmail, you even have a useful option if you know the sender. Open the email, select Mark as and click on My friend's been hacked!


Help your friend by stating (s)he's been hacked


If you happen to have a Wordpress website, be sure to update it regularly as well as any Wordpress plugins you may have installed. This website will aid you in the matter: Hardening WordPress



Conclusion

Don't fall for either of these, in both cases you'll lose a lot of money !

Follow the above prevention tips to decrease the chance of your computer becoming infected.
Read More
Posted in blog update, cracked hotmail, fakeAV, hacked hotmail, Hacked Hotmail accounts, malware, phishing, rogueware, scam, Windows Antibreaking System | No comments

Tuesday, April 10, 2012

Free Riot codes scam

Posted on 3:38 AM by Unknown
Below you can find a list of confirmed phishing and scam websites.


Update - 14/04/2012 - 21:35 CET
: Both the Facebook page and hxxp://freeriotcodes.com are offline now. There is one other Facebook page (+ 21,000 likes) and a few other websites which are still up & running, but I expect them to be down soon. Great work Riot Games !


Update - 13/04/2012 - 18:07 CET: It seems the domain(s) is (are) accessible again. I have however received an email from Riot and they will be working on the issue as well:

Riot Games working on the issue

Update
- 12/04/2012 - 17:07 CET
: Yesterday I reported the domain hxxp://freeriotcodes.com to their domain registrar, GoDaddy.com. They have acted very fast and the domain is already inaccessible. Great work !



However, the page on Facebook still exists, and a new post has been made explaining the current unavailability of their scam:


'Free Riot Codes' apologising for the inconvenience











I have reported the page to Facebook as well reported it to Riot Games themselves. Hopefully the Facebook page will be offline soon.

Note: another Facebook page is currently trying to scam people. It will be taken offline soon:
hxxp://www.facebook.com/RPCodeGiveaways
--- End Updates

Facebook. A social networking place. For some a dream come true, for others a true nightmare. Guess in which category phishers, scammers and malware authors reside ?


In today's post we will be highlighting a scam specifically focusing on players of the game League of Legends, an action real-time strategy game developed and published by Riot Games.

The scam page on Facebook in question is:
hxxp://www.facebook.com/pages/Free-Riot-codes/141669939249958

Currently, it already has over 41,000 likes:


More and more people are liking the page, thus might be getting scammed



On Youtube as well as on Google+ and Twitter it is -for now- pretty calm. Only a few video's and tweets promoting this scam:


On Twitter, Google+ and Youtube they are also promoting their website, but not as heavily as on Facebook


Some example website where you can get "free" riot points  or "free" riot codes are: 
hxxp://freeriotcodes.com            
hxxp://blogs.gamenov.us/lol
hxxp://cheatsjungle.com/league-of-legends-promotional-code-generator-2
hxxp://cheatsjungle.com/league-of-legends-riot-points-generator
hxxp://elohell.org
hxxp://free-riotcodes.info

hxxp://free-riotpointscodes.com
hxxp://free3600rp.byethost22.com
hxxp://freehackgames.org/league-of-legends-riot-points-generator-3-2-version              
hxxp://freeleaguecodes.com      

hxxp://freeleaguecodes.net       
hxxp://freeleagueoflegendsriotpoints.com
hxxp://freeleagueoflegendsriotpointcodes.com     
hxxp://freeleagueoflegendskins.co.uk         
hxxp://freelolriotcodes.com     

hxxp://freelolriotcodes.netii.net   
hxxp://freelolriotpointz.blogspot.com      
hxxp://freelolrpcodez.weebly.com  

hxxp://freelolskins.com            
hxxp://freeriotcodes.filegame.net              
hxxp://freeriotcodes.info   

hxxp://freeriotcodes.org           
hxxp://freeriotcodes.weebly.com              
hxxp://freeriotcodesgift.com   

hxxp://freeriotpoints.me       
hxxp://freeriotpointsclub.com  
hxxp://freeriotpointscode.com 

hxxp://freeriotpointsgenerators.blogspot.com    
hxxp://freeriotpointsleagueoflegends.blogspot.com         
hxxp://freeriotpointsnow.com              
hxxp://freeriotpointss.com              
hxxp://freerpcodes.com              
hxxp://freerpcodes.tk              
hxxp://getfreeriotcodes.blogspot.com              
hxxp://getfreeriotcodes.com              
hxxp://getfreeriotpoints.com    

hxxp://getfrenocturneskin.webs.com          
hxxp://getriotcodes.com       

hxxp://getriotpoints.info       
hxxp://getriotpointscodes.com    

hxxp://getriotpointsforfree.com 
hxxp://getriotpointsfree.com
hxxp://gogamecheats.com/league-of-legends-free-riot-points  
hxxp://hackerzzs.blogspot.com               
hxxp://hackscheatsgamesprograms.blogspot.com 
hxxp://league-gamers.com
hxxp://leagueoflegends.byethost33.com
hxxp://leagueoflegends2012hack.blogspot.com             
hxxp://leagueoflegendsrphack.com              
hxxp://leaguerp.com   

hxxp://leaguerpgifts.com        
hxxp://leagueoflegendsgenerator.wordpress.com
hxxp://leagueoflegendsrpcodegenerator.blogspot.com    
hxxp://leagueoflegendsrpcodegenerator.weebly.com
hxxp://leagueflegendvoteasestribunall.gaming.lc
hxxp://live.rpgiveaway.com             

hxxp://lolhacktool.blogspot.com 
hxxp://lolfreeriotpoints.blogspot.com              
hxxp://lolmultihack2012.blogspot.com 

hxxp://lolpromobundles.blogspot.com             
hxxp://lolriotpointcodes.blogspot.com              
hxxp://lolrpgenerator.webs.com         

hxxp://lordhacks.com/league-of-legends-hack
hxxp://lordhacks.com/league-of-legends-promotional-code-generator
hxxp://oisn.mypressonline.com/league
hxxp://rafflesforprizes.com

hxxp://riot-codes.com
hxxp://riot-points.free-cards.info   
hxxp://riot.edgehacking.com              
hxxp://riot.freecodesgiveaway.com              
hxxp://riotcodegenerator.com              
hxxp://riotcodes.hacksfiles.com              
hxxp://riotcodes.net              
hxxp://riotcodesforfree.org              
hxxp://riotcodesfree.com              
hxxp://riotcodesfree.net

hxxp://riotgames.qualtrics.com  
hxxp://riotpointcodes.org
hxxp://riotpoints.cu.cc   
hxxp://riotpoints.net
hxxp://riotpointsadderforfree.blogspot.com
hxxp://riotpointscampaign.com        
hxxp://riotpointscodes.info  

hxxp://riotpointsgeneratorfree.blogspot.com           
hxxp://riotpointsfree.com   

hxxp://riotpointsgenerator.co
hxxp://riotpointsgenerator.org   
hxxp://riotpointshop.com        
hxxp://riotpoints-free.com

hxxp://rpcodes.info 
hxxp://rpfree.com
hxxp://rprewards.com
hxxp://rp-free.blogspot.com              
hxxp://rpgiveaway.com              
hxxp://videogamehacks.net/riot-points-generator

hxxp://xpandhacks.net/league-of-legends-riot-points-generator
hxxp://xpandhacks.com/league-of-legends-riot-points-generator-2                

You can +1 it, share it on Facebook, Tweet it ... Share the scam with everyone you like ;-) .

The first link in bold is the one that is visited -and used the most. All you have to do to get your Riot Points for free is to follow these 3 easy steps:

Step 1 - Share it on Facebook
Step 2 - Post the following message once on your wall and 5 times on a Different Game Page on Facebook:
WOW! I just got my League of Legends Riot Code for free! So excited! Thanks hxxp://freeriotcodes.com !
Step 3 - Click "Like and Confirm"


Step 2 in the process - posting on Facebook. In this specific scam, it is not being posted automatically to your wall, you actually have to share it yourself


That's it, 3 simple steps and then you'll be able to download your Riot Points or codes free of charge !

... But wait, there's a timer on the page indicating you'll have to wait before the next giveaway:




Somehow, I got lucky and, through one of the other websites, I was able to visit the download page and acquire my points !

However, ultimately I have to complete a survey to finally download my Riot points. I am getting redirected to several other scams and so on. You can win a smartphone, the new iPad, an iPhone, trendy boots, a Macbook ....

In some cases only your phone number is sufficient, in others you'll have to fill in complete information like your full address, email address ...

Some examples of dubious file sharing websites, which are also showing a popup with some Javascript behind it (another survey scam):
hxxp://cleanfiles.net
hxxp://fileice.net
hxxp://fileme.us
hxxp://fileml.com
hxxp://filenix.com
hxxp://matrixmega.com
hxxp://oceanfiles.me
hxxp://sharecash.org
hxxp://sharkyfiles.com 
hxxp://skippyfile.com 
hxxp://speedyfiles.net
hxxp://tinyfileshost.com
hxxp://topfiles.me


Let's get back to the scam site itself - hxxp://freeriotcodes.com
Registrant:
Hal Medus
10612 Parliament Ave
Garden Grove, California 92840
United States

Administrative Contact:
Medus, Hal hackzforyou@gmail.com
10612 Parliament Ave
Garden Grove, California 92840
United States
6572017037


UrlQuery Result:
Suspicious
http://urlquery.net/report.php?id=40190

URLvoid Result:
2/25 (8.00%)
http://www.urlvoid.com/scan/freeriotcodes.com/



Conclusion

Pretty straightforward: do not click on any of these scams, how tempting they might be! You will not receive a prize, you will not receive a free iPhone and you will certainly not receive any Riot Points or Riot codes! Certainly, never fill in your login credentials!

Some tips:
[*] Install WOT - WOT is a community-based tool and is therefore very useful for these kinds of scams, whereas other users can warn you about the validity.
More information and to download WOT: http://www.mywot.com/

[*] When in doubt, use any of the following URL scanners:
https://www.virustotal.com/#url
http://www.urlvoid.com
http://urlquery.net

[*] The most important one of them all:
if it looks too good to be true, it probably is!
Read More
Posted in blog update, facebook scam, free riot code scam, free riot codes, free riot points, free riot points scam, League of Legends, LoL, phishing, Riot codes scam, survey scam | No comments

Tuesday, December 6, 2011

New Facebook scam

Posted on 6:26 AM by Unknown
A new Facebook scam is spreading today, 6th of December. The interesting thing is that I have seen it posted in Dutch as well.

The method used is the same as in previous Facebook scams, see for example my earlier post:
New Facebook scam

Here is the post in question (in Dutch):


Classical scam post to lure users into clicking the link.

Here's what it reads:
WOW! Mijn profiel is ALLEEN VANDAAG AL 12 keer bekeken.. en ik kan zien dat er behoorlijk wat stalkers bijzitten LOL! Kijk zelf wie jou allemaal in de gaten houdt op #removed#

In English:

WOW! My profile has been seen 12 time ALREADY ONLY TODAY .. and I can see that quite a few stalkers are included LOL! See for yourself who's keeping an eye on yoy on #removed#



The link has been shortened by the bit.ly URL shortening service. While this service is not malicious on itself, it can also be used by persons with malicious intent, whether it would be hackers, malware authors, ... Or in this case scammers.

Let's review some stats for the bit.ly link first:


98 clicks on this link in the last hour



Top countries, including: France, Germany, The Netherlands



Facebook.com is the most referring site


At the moment of writing, there have been over 1,000 clicks on the link so far. I have already reported it to bit.ly and it should be taken down soon.

UPDATE: bit.ly has already issued a warning for when you click on the link. (12/07/2011)


Now let us analyse where the bit.ly link is taking us. The link can redirect you to different websites, but they will all (so far) redirect you to a page similar to this one (depending on your location):


Who is viewing your Facebook profile ?


You probably don't remember my post from February this year, but the concept is the same: you can supposedly view who's been "stalking", or viewing, your profile. This to attract users on clicking the link. Who doesn't want to see this, right ? Here is my post from early this year:
Facebook rogue applications still lurking around

You can presented with a screen like this (I have several, but I will only post one as example):

Are you the "lucky" winner ?

As stated previously, the concept is the same. Before you can see who's been viewing your profile, you need to fill in a short service to continue.

You may have won a prize, you may have won an iPad, you may have won free ringtones, you may have won a free iPhone application, etc, etc, etc, .... This is of course all a lie.
Remember: if it looks too good to be true, it probably is !

You have to fill in your email address and/or phone number to continue as well. At the end you will end up losing a lot of money, leaving your email address in the open and maybe worse.

Remember: if you click the link while logged in to Facebook, it will also post it on your own wall.



Conclusion

Conclusion is pretty straightforward: do not click on any of the links ! If in doubt, send your friend on Facebook (or if someone sent you the link) via PM if he or she knows what this is about.

To remove this from your or your friend's wall, click on the X on the message, and choose to "Report/Mark as spam" or "Remove Post".

You can also use a linkscanner to verify the integrity of a link on either http://www.urlvoid.com or https://www.virustotal.com/

To get some information on a bit.ly (or other URL shortener serivce) link, you can use any of the following websites:
- http://www.getlinkinfo.com/
- http://longurl.org/
- http://www.longurlplease.com/ (includes Firefox extension)

To report a malicious bit.ly link use:
http://bitly.com/a/report_spam

For any other question, do not hesitate to post a comment !
Read More
Posted in blog update, facebook, phishing, scam, spam, spim | No comments

Friday, September 2, 2011

Increase in malicious spam

Posted on 7:10 AM by Unknown


Rodel Mendrez from M86 Security labs has made an excellent post on a Massive Rise in Malicious Spam:

http://labs.m86security.com/2011/08/massive-rise-in-malicious-spam/





As he notes in his conclusion, "It seems spammers have returned from a holiday break and are enthusiastically back to work."





So I decided to check out if I had received some spam as well. Jackpot ;-) !






UPS notification























































Re: End of July Statement Required









Your credit card has been blocked











ACH Transfer Review







Most of the files are displaying a Word or PDF icon to trick

the user in opening the file:







Some examples of attachments, with their respective

VirusTotal results:



Invoice_08.17.2011_Collcod.exe

MD5: cf0397bb622e4ed9dfdeb07fcbfa9687

VirusTotal Report



MasterCard_invoce_ID73284783275943.doc.exe

MD5: 0b7eba77dd4bcea3c670c4a664e98778

VirusTotal Report



UPS_Document.exe

MD5: 17f9148b130a94ab1f50030ebbf2415a

VirusTotal Report



form-62091.exe

MD5: e18d8cb2a4264a3c559d7967b3c6ab99

VirusTotal Report



When opening either of these files, you can end up with a rogue.

One example rogueware I got was "System Repair":



System Repair rogueware



The dropped file that is launching the rogueware:



pusk3.exe

MD5: 27077c2058983bb76bd09cdad69f7bde

Result: 36/44 (81.8%)

VirusTotal
Report

ThreatExpert
Report

Anubis Report







Conclusion

Conclusion is pretty simple: Do not open any attachments from unknown senders.

If you happen to be infected with System Repair, you can for example use the guide on Bleepingcomputer:

http://www.bleepingcomputer.com/virus-removal/remove-system-repair


Read More
Posted in ACH transfer, blog update, credit card blocked, end of july, FedEx, malware, spam, UPS | No comments

Sunday, June 19, 2011

New Facebook scam

Posted on 1:11 PM by Unknown
There's a new Facebook scam actively spreading.

Titles as "Monstrously Erotic blonde", "This chick is awesomely crazy" and "Shows her boobs on national TV!" may appeal to the imagination.

Here's some examples:
Example #1

Example #2


Example #3

However, if you click on the link, it will not take you to a Blogger page but instead will redirect you right away to a page where you can see the "video":


You need to click "Jaa" twice to confirm you're over 18



It looks like a legit Facebook page and a Youtube video, but in fact it is all fake. If you click on "Jaa" (which appears to be Finnish for "Share"), you'll see the following page:


Ultimately you need to fill in a survey to see the video


Haven't we seen this type of scam before on Facebook ?
It is similar to the "See who stalks you on Facebook" application that was pretty viral some months ago.
I also made a blog post back then:
http://bartblaze.blogspot.com/2011/02/facebook-rogue-applications-still.html

You need to fill in a survey to see the video. Of course you might be attracted by the chance of winning an iPhone, but it is all fake.

The purpose of these scams are for you to send expensive text messages to 'unlock' the video. Don't be fooled, you'll only lose money by sending text messages !
Additionally, it will also make the same post on your wall (subject & link may vary), so your friends are targeted as well.




Prevention

Pretty straightforward: do not click on any of these links, how tempting they might be ! Ask your friend if he or she knows what it means, and slightly hover over the post until the 'X' becomes visible. You can then mark the post as spam, and it will be removed from your friend's wall.

It might also help to install the WOT extension into your browser. (Compatible with most modern browsers)
WOT is a community-based tool and is therefore very useful for these kinds of scams, whereas other users can warn you about the validity.
More information and to download WOT: http://www.mywot.com/




Conclusion

Although it's been a while since I encountered these types of scams, keep in mind that they may pop-up on your wall one day.

If so, follow the prevention tips mentioned above and all should be fine.


Read More
Posted in blog update, facebook, scam, spam | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • League of Legends RP hack
    I recently blogged about a (still current) scam targeting players of the online game League of Legends: Free Riot codes scam . When re-check...
  • test for the blog
    Just testing ... :-)
  • Facebook Support. Personal data has been changed!
    There appears to be a new malicious email being sent out with the subject: " Facebook Support. Personal data has been changed! ID7530...
  • WinMHR: Free Malware Detector
    Today I checked out WinMHR brought to you by: Team Cymru Now, what exactly is WinMHR ? (This is copied from the website) WinMHR is... Free ...
  • Malware Puzzle
    A malware (crossword) puzzle you say? Yes! Why not? I've made a puzzle about malware (and security) related keywords. It comes in .PNG f...
  • Brazilian banking Trojan tricks
    So I encountered what I suspect to be a banker focused on Brazilian banks. (Win32/Bancos) Part 1 - spam mail : Fiscal note Mail from: mail.u...
  • Increase in Dutch banking phishing
    Recently I made a post on Malware Disasters about an increase of targeted phishing in the last few monts. The focus was mainly on Dutch (an...
  • Gina Lisa Facebook scam
    Yet another Facebook scam, this time luring users with a sextape from Gina Lisa, whom is apparently a German model: Yet another Facebook sca...
  • A word on XDocCrypt/Dorifel/Quervar
    I'm sure everyone has heard by now about the so called XDocCrypt/Dorifel/Quervar malware. It has mostly damaged machines in The Netherla...
  • FedEx spam loads malware
    Received an email from (supposedly) FedEx today, seems my parcel was unable to be delivered: Print your receipt!     Mail details: Subject: ...

Categories

  • ACH transfer
  • adobe
  • adobe exploit
  • ADP
  • adware
  • affiliate
  • all your data are belong to us
  • antimalware
  • asprox
  • bancos
  • banking trojan
  • basic malware cleaning
  • battle.net
  • blackhole exploit kit
  • blog update
  • botnet
  • brazilian banking trojan
  • brucon
  • change facebook color
  • conduit
  • cracked hotmail
  • credit card blocked
  • crimeware kit
  • CVE-2006-0003
  • CVE-2010-0840
  • CVE-2012-4681
  • cybercrime
  • d3
  • diablo
  • diablo III
  • diablo phishing
  • DLL injection
  • Dorifel
  • dorkbot
  • encryption
  • end of july
  • exploit
  • exploit kit
  • exprez
  • facebook
  • facebook dislike button
  • facebook event
  • facebook scam
  • Facebook spam
  • facepalm
  • Fake Symantec security check
  • fakeAV
  • fareit
  • FedEx
  • FedEx spam
  • first post
  • flv media player
  • foistware
  • free riot code scam
  • free riot codes
  • free riot points
  • free riot points scam
  • free RP generator
  • fun
  • gina lisa
  • google earth
  • google image poisoning
  • google images
  • hacked hotmail
  • Hacked Hotmail accounts
  • hakin9
  • Hewlett-Packard ScanJet
  • hotfile
  • hotmail
  • illegal games
  • infostealer
  • ING
  • IP and RP Hack Download
  • java
  • java exploit
  • kuluoz
  • lame old malware
  • League of Legends
  • League of Legends MultiHack Generator
  • League of Legends RP generator
  • League of Legends RP hack
  • linkedIN
  • LoL
  • LoL RP Hack
  • low detection
  • malvertising
  • malware
  • malware analysis
  • malware analysis lab
  • malware cleaning
  • malware lab
  • malware puzzle
  • malware tools
  • medfos
  • messenger
  • MSN
  • neosploit exploit kit
  • paypal
  • paypal spammail
  • PC Speed Maximizer
  • pcspeedplus
  • PDF
  • phishing
  • poker games
  • potentially unwanted program
  • pricegong
  • PUP
  • pushdo
  • Quervar
  • Question and Answer
  • rabobank
  • ransomware
  • rapidshare
  • redkit exploit kit
  • RemovalTool.exe
  • Riot codes scam
  • Riot points scam
  • roguevertising
  • rogueware
  • rootkit
  • sasfis
  • scam
  • scareware
  • security
  • security conference
  • security.nl
  • skype
  • skype worm
  • social engineering
  • spam
  • spear phishing
  • spim
  • survey scam
  • team cymru
  • technoviking
  • tepfer
  • test
  • trojan
  • twitter
  • United Parcel Service
  • UPS
  • UPS spam
  • verizon spam
  • video
  • vmware
  • wellsfargo
  • whitesmoke
  • Windows Antibreaking System
  • windows live
  • WinMHR
  • worm
  • XDocCrypt
  • yontoo
  • youtube
  • youtube comment spam
  • youtube spam
  • youtube top comments
  • zeus

Blog Archive

  • ▼  2013 (18)
    • ▼  September (2)
      • Malware: the blame game
      • PayPal spam leads to malware cocktail
    • ►  August (2)
    • ►  July (1)
    • ►  June (3)
    • ►  May (2)
    • ►  April (1)
    • ►  March (1)
    • ►  February (3)
    • ►  January (3)
  • ►  2012 (14)
    • ►  November (1)
    • ►  October (2)
    • ►  September (2)
    • ►  August (3)
    • ►  July (1)
    • ►  June (2)
    • ►  April (3)
  • ►  2011 (15)
    • ►  December (1)
    • ►  September (1)
    • ►  June (1)
    • ►  April (3)
    • ►  March (1)
    • ►  February (5)
    • ►  January (3)
  • ►  2010 (14)
    • ►  December (3)
    • ►  November (1)
    • ►  October (6)
    • ►  September (2)
    • ►  August (1)
    • ►  March (1)
Powered by Blogger.

About Me

Unknown
View my complete profile