Fake Lawsuit Notification Attack

A few of days ago, we encountered an e-mail with a malicious RTF attachment. It was sent with a supposed lawsuit notification message. The e-mail didnā€™t mention any company by name and took a shotgun, rather than targeted, approach. Today, a security blogger forwarded us (and others) his version of the e-mail: At this point, it appears that the attachment has been replaced by hyperlink pointing to the Marcus Law Center. ...

March 26, 2010 Ā· 1 min Ā· 201 words Ā· Omid Farhang

Child Tax Credit is the New Phishing Bait

Who wouldnā€™t want some tax benefits in the current economic times? Donā€™t phishers and scammers know that all too well! In a new phishing scheme, We found that Child Tax Credit is being used as bait to lure parents to disclose their financial data. This attack specifically tries to convince users to make claims for credit and lower their tax burden by using their childrenā€™s education expenses. According to the Internal Revenue Service (IRS) website [PDF], taxpayers may be able to reduce their federal income tax by up to $1,000 for each qualifying child. Making use of this information, spam email discusses the expensive education of children and quickly advises recipients to use this expense to make claims for tax credits under the numerous tax benefits provided by the IRS. They make a further appeal that as a U.S. citizen or resident, recipients should apply for their tax returns. According to the email, users can get a tax refund of $75,000 for their childrenā€™s education. To apply for a refund, users need to complete a form attached to the email message. The fraudulent email has an HTML attachment named ā€œ#1924819299.pdf.htmā€. ...

March 26, 2010 Ā· 2 min Ā· 364 words Ā· Omid Farhang

Attacks on Indian Income Tax Department Continue

We previously reported a phishing attack on the Indian Income Tax Department. Phishing emails boasting of tax refunds were sent to users in an attempt to entice citizens to enter their credentials on a bogus website. Recently, new attacks have been observed in which the phishing website states that taxes can be paid online. As the fiscal year in India draws to an end, more people are rushing to pay taxes before the deadline. ...

March 23, 2010 Ā· 2 min Ā· 225 words Ā· Omid Farhang

Icelandic Volcano Erupts, Fake Antivirus Spews Forth

Yesterday there was a volcanic eruption in Iceland, near the Eyjafjallajoekull glacier, that has led the Icelandic authorities to declare a state of emergency in southern Iceland. People living nearby have been evacuated in case of glacial melt water flooding and the airspace near the now active volcano is effectively closed off. As you have probably already guessed, any event which commands a high level of public interest will be pounced on quickly by the makers of fake antivirus software in order to make a quick buck. This incident is no exception. ...

March 22, 2010 Ā· 3 min Ā· 554 words Ā· Omid Farhang

A Fishy Defacement

Generally speaking, most website defacements I see tend to look the same with political activist Y decrying political activist Z, or leet hax0rs posting up a mile-long shoutout list to their crew. This one is, er, a little different ā€“ a defacement of what appears to have been a site involved in fish logistics and / or preservation, fish2see(dot)dk. I can only imagine the horror on the face of the site admin who woke up this morning to be confronted by this: ...

March 22, 2010 Ā· 1 min Ā· 118 words Ā· Omid Farhang

Phishers cast their nets at Neopets Users

If you have children that play Neopets, you might want to warn them about this website or insert it into a blocklist of your choosing. The site is Neopoints(dot)tk, and promises lots of free Neopoints related items, with the help of a cute mascot called ā€œTuma the Draikā€. I think there was a Norwegian prog rock group from the 70s called that, but I could be wrong. ...

March 22, 2010 Ā· 1 min Ā· 200 words Ā· Omid Farhang

IMF money-making scam

I have seen a lot of these lately. This one currently doing the rounds tries to dupe the reader into thinking that the International Monetary Fund (IMF) wants to use their accounts to transfer money meant for charity. In the email. the IMF (supposedly) wants to transfer $10 Million into the readerā€™s account using NatWest Bank. The contact details within the Bank are given as follows: ...

March 22, 2010 Ā· 1 min Ā· 186 words Ā· Omid Farhang

Phishing increased 62 percent in '09

The DarkReading site is carrying a story about brand-protection firm MarkMonitorā€™s finding that phishing increased 62 percent in 2009 with 565,502 attacks in the year. MarkMonitor is based in San Francisco. Other conclusions in MarkMonitorā€™s 2009 BrandJacking Index report: The huge increase can probably be attributed to the use of botnets and the large amount of personal information that can be scraped from social network sources. 2009 saw the all-time high average of 600 phishing attacks per organization only 33 percent of victims were first-time targets. Social networks suffered 11,240 attacks ā€“ two percent of the yearā€™s total. The U.S. hosted 44.7 percent of phishing attacks, up from 36.5 in 2008. DarkReading story Here. ...

March 22, 2010 Ā· 1 min Ā· 114 words Ā· Omid Farhang

Index of /images: a hiding place for malware?

The underlying structure of a typical website is made up of different folders and sub-folders, much like the ones that are on your computer. A webmaster (is this term still used often lol?) transfers files back and forth using an FTP client in order to update the website. In most cases, specific folders are created for a specific reason. For instance the ā€˜pubā€™ folder is usually a public repository that allows anybody access to. ...

March 22, 2010 Ā· 4 min Ā· 795 words Ā· Omid Farhang

Please give me your credit card

I wonā€™t abuse it, I promiseā€¦. cross my heartā€¦ spit into the windā€¦ etc. Hi folks, Yesterday, I received this SPIM (Instant message spam) ā€¦ usnews3.com sounds kind of official, doesnā€™t it? and the page looks impressiveā€¦ There are lots of links on the page, but unfortunately, a mouse-over of each link reveals that they all go to the same placeā€¦ ...

March 22, 2010 Ā· 2 min Ā· 244 words Ā· Omid Farhang