| 

Do They Know itā€™s (not) Christmas Time at All?

  • Post author: Omid Farhang
  • Post published: February 21, 2010
  • Reading Time: 1 min
  • Word Count: 207 words

I saw something quite funny when checking out the spam feeds the other day. An attachment kept appearing, once in a while, with a name ofĀ Christmas Card.zip. It was making sporadic appearances in the feeds (and the number of spam email messages was quite low), but there were a couple of these odd messages at equally odd hours of the day: The email message itself was a run-of-the-mill electronic greeting card with an HTML body containing a nice Flash animationā€”the Flash animation actually comes from a legitimate source (123greetings.com). The email body contains a message asking the user to open the attachment to see who sent the email. Of course, opening the attachment yields a malicious file. The name of the file inside isĀ _**Christmas Card.htm[MANY SPACES].exeĀ **_and it is already detected by Symantec as W32.Ackantta.G@mm. ...

Continue Reading Do They Know itā€™s (not) Christmas Time at All?

The Facebook Team informs youā€¦

  • Post author: Omid Farhang
  • Post published: February 16, 2010
  • Reading Time: 2 min
  • Word Count: 250 words

In the last two days our lab has detected a flood of email messages that seem to have been sent by the Facebook team urging users to submit a new account agreement. Weā€™ve seen around 16,000 since yesterday. The subject of the message isĀ UPDATED ACCOUNT AGREEMENTĀ and the attached file is calledĀ AGREEMENT.ZIP. The message is like the following: Users are required to submit a new account agreement before a certain date. If not, their Facebook account will be restricted. The message also contains detailed instructions on how to do it. ...

Continue Reading The Facebook Team informs youā€¦

Zeus ā€“ Exploiting Spear Phishing to Spear Phish

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 1 min
  • Word Count: 129 words

The Zeus crimeware family has moved into new territory with its latest spam campaign ā€“ purporting to be a warning about targeted phishing attacks on ā€œ.govā€ and ā€œ.milā€ domains, by Zeus Trojans no less! In fact, one of the latest spam samples weā€™ve seen, duplicates the title and first three paragraphs of aĀ blog entry by well-known security expert Brian Krebs, which discusses a previous iteration of this Zeus attack. As seen below, the spam sample starts off with the same three lines of the blog post, before starting into the phony KB content and links that lead to Zeus malware. ...

Continue Reading Zeus ā€“ Exploiting Spear Phishing to Spear Phish

Interview with a Nigerian 419 scammer

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 3 min
  • Word Count: 486 words

Bruce Schneier, in his blog Schneier on SecurityĀ http://www.schneier.com/Ā drew attention to this great interview with an ex-Nigerian-419 scammer on theĀ Scam-Detective site. Itā€™s a fairly long piece and gives a pretty good view of the Nigerian scam industry run by organized crime, how it sucks in young people who have good computer and English skills and pays them a huge amount of money ($75,000 per year in this case) to scam victims they view as white, greedy and rich. ...

Continue Reading Interview with a Nigerian 419 scammer

A Perfect Valentineā€™s Day

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 3 min
  • Word Count: 535 words

Planning a romantic Valentineā€™s Day for your loved one? Is there is no end to all that you can do to add even more sparkle this dreamy day? Perhaps a bottle of wine, flowers, or a lovely gift to impress him/herā€”and if you arenā€™t with anyone, there are even dating services available that provide you with options to meet a date. As Dermot Harnett mentioned inĀ A Brilliant Proposal: Stay Away from Valentineā€™s Day Spam!, for spammers, Valentineā€™s Day is a great target. Weā€™ve observed several spam email message styles related to this upcoming event. Gift options, flower delivery, dating service, med spam to spice up your relationship, and much more. Here are some common header lines that Symantec has tracked relating to Valentineā€™s Day: ...

Continue Reading A Perfect Valentineā€™s Day

Spammers dangle iPad carrot

  • Post author: Omid Farhang
  • Post published: February 7, 2010
  • Reading Time: 1 min
  • Word Count: 82 words

New, shiny products always tend to catch peopleā€™s attention, and spammers are continually looking for ways to do exactly that. So itā€™s not surprising to see spam tempting people with the promise of a new iPad, and a FREE one at that: The image theyā€™ve used is very sketchy too, patched together from other existing Apple products and bearing little resemblance to the pictures released so far. However much you might want an iPad, donā€™t get lured in by spam like this. ...

Continue Reading Spammers dangle iPad carrot

Major U.S. crackdown on work-at-home fraud coming?

  • Post author: Omid Farhang
  • Post published: February 7, 2010
  • Reading Time: 2 min
  • Word Count: 252 words

The U.S. Federal Trade Commission today announced that next Tuesday they will hold a news conference to make public details of ā€œa law enforcement sweep cracking down on job and work-at-home fraud fueled by the economic downturn.ā€ The media advisory said that the news conference would feature the director of the FTCā€™s bureau of Consumer Protection David C. Vladeck, an assistant attorney general and the Ohio Attorney General. The advisory listed as ā€œalso attendingā€ representatives of the U.S. Postal Inspection Service, Monster.com and Microsoft. ...

Continue Reading Major U.S. crackdown on work-at-home fraud coming?

Job opportunity without a single name

  • Post author: Omid Farhang
  • Post published: February 7, 2010
  • Reading Time: 2 min
  • Word Count: 288 words

Today we received some job hiring emails that looked like this: It has been formatted nicely and appears to have come from a large job search website. The message reads as follows: Dear Job Seeker, Upon reviewing your resume on Careerbuilder.com we have decided to offer you a job opportunity with our company. The job position is for a Payment Manager/Payments Processor in your area with no obligation to relocate. ...

Continue Reading Job opportunity without a single name

Phishing scam steals carbon credits

  • Post author: Omid Farhang
  • Post published: February 5, 2010
  • Reading Time: 1 min
  • Word Count: 109 words

Wired magazine has run a story on a phishing scam in Europe, New Zealand and Japan that resulted in the loss of 250,000 carbon credit permits worth $4 million from six companies. The phishing emails spoofed the German Emissions Trading Authority and said that the victim companies needed to re-register their accounts with the authority. When victims entered their information on a fraudulent web page from the link in the phishing emails the scammers accessed their accounts, transferred emissions credits to accounts they controlled then sold them. The amount the scammers made hasnā€™t been disclosed. ...

Continue Reading Phishing scam steals carbon credits

It looks like a phish but isn't

  • Post author: Omid Farhang
  • Post published: February 5, 2010
  • Reading Time: 1 min
  • Word Count: 19 words

This is really bad for so many reasons. It certainly doesnā€™t help their security. And yes, itā€™s completely legitimate.

Continue Reading It looks like a phish but isn't