| 

Spam from the Advocate

  • Post author: Omid Farhang
  • Post published: October 25, 2010
  • Reading Time: 1 min
  • Word Count: 197 words

Currently cyber criminals try to make fast money by spamming out emails in masses in Germany which allegedly stem from an Advocate specialized in copyright. According to the spam mails, the user was downloading copyrighted material. An IP address is in the email to proof that. To not call the attorney to action, the recipient of the mail is offered to send 100 Euros via a payment system called Ukash. Don’t fall for that social engineering, don’t pay! ...

Continue Reading Spam from the Advocate

Google's Spam Report Extension

  • Post author: Omid Farhang
  • Post published: October 24, 2010
  • Reading Time: 1 min
  • Word Count: 123 words

If you want to improve Google’s results and report spammy web pages, there’s a Chrome extension for you.Google Webspam Report adds a link next to each Google search result and automatically fills the spam report form with information like the URL of the page and your query. You can also use the button from Chrome’s toolbar to report pages. The most interesting feature is the integration with Chrome’s browsing history that lets you select recently visited pages and recent Google searches. ...

Continue Reading Google's Spam Report Extension

Fake Twitter homepage kit serves up naked ladies and infection files

  • Post author: Omid Farhang
  • Post published: October 18, 2010
  • Reading Time: 2 min
  • Word Count: 279 words

You might be wondering why the frontpage of Twitter has a big “Edit” line running through it in the screenshot below: The answer, of course, is that this is not the real Twitter page at all. It’s part of an increasingly popular kit used for shenanigans: The scammer downloads the zip, edits the links in the .htm file and places something likely to catch the attention of an end-user underneath the “Edit” line. The fact that the fake content is sitting directly underneath the “New Twitter” promotional text is not a coincidence. ...

Continue Reading Fake Twitter homepage kit serves up naked ladies and infection files

Buggy Paypal phishing

  • Post author: Omid Farhang
  • Post published: October 12, 2010
  • Reading Time: 1 min
  • Word Count: 171 words

Usually I have to wonder how much inventiveness the spammers and Phishers show. But, from time to time, it is funny to see some really stupid Phishing attempts. I do hope that nobody is falling for these puny attempts to fake Paypal we found today. The email below is being sent with a German subject line and it is pretending to come from a German mail address, but the mail itself is written in English and it is allegedly pointing to paypal.com instead of paypal.de. ...

Continue Reading Buggy Paypal phishing

Online pharmacy spam campaign faking Twitter

  • Post author: Omid Farhang
  • Post published: October 12, 2010
  • Reading Time: 1 min
  • Word Count: 185 words

During the weekend our spamtraps received large amounts of emails pretending to come from Twitter. This time, the social engineering twist lies within the subject of the email: It is “You have 2 urgent messages from Twitter!”, creating psychological pressure by some kind of emergency within in the social surroundings of Twitter users. This way the spammers try to increase the rate of the users that are opening the email and click on the links. ...

Continue Reading Online pharmacy spam campaign faking Twitter

Twitter password phishing

  • Post author: Omid Farhang
  • Post published: October 7, 2010
  • Reading Time: 2 min
  • Word Count: 219 words

Our friend in the UK got this via a contact. It was from a Twitterer who obviously had his Twitter login stolen: (Twitter apparently is filtering this URL at this point.) The link led to a phishing page that used the deceptive tactic of showing an error message: “Wrong Username/Email and password combination.” You login, it steals your Twitter password, sends the above Tweet to all your contacts and continuing rounding up passwords. ...

Continue Reading Twitter password phishing

Facebook spammer fined $1 billion USD

  • Post author: Omid Farhang
  • Post published: October 7, 2010
  • Reading Time: 2 min
  • Word Count: 229 words

How does one say in French: “We’re gonna make an example out of you, boy” The Toronto Sun is reporting that convicted spammer Adam Guerbuez of Montreal has been ordered to pay $1 billion to Facebook by Quebec Superior Court. The court was upholding a U.S. Federal court fine that resulted from a wave of four million spam ads sent to Facebook users in 2008. Guerbuez did not contest the Sept. 28 Quebec Superior Court ruling. ...

Continue Reading Facebook spammer fined $1 billion USD

More Spam with JavaScript redirectors

  • Post author: Omid Farhang
  • Post published: September 23, 2010
  • Reading Time: 1 min
  • Word Count: 96 words

We received new spam emails which contain a JavaScript redirector in form of a HTML attachment. The emails we received have the subject “Consultation Appointment”. The decrypted JavaScript consists of new JavaScript code. This JavaScript redirector loads yet another JavaScript from the internet. The domain which is hosting the malicious .js is registered to someone from Malaga. Domain tools show that this person has registered about 2.400 other domains. ...

Continue Reading More Spam with JavaScript redirectors

New phishing-spam waves using Facebook as bait

  • Post author: Omid Farhang
  • Post published: September 17, 2010
  • Reading Time: 3 min
  • Word Count: 499 words

We have started to see again a large increase in the amount of emails pretending to come from Facebook. There are two types of emails which are being sent in large amounts currently. Both of them use classical types of social engineering techniques. The first type is using the old trick with “the photos”. The final target is a website where SMSes can be sent for “free” (note the quotes). I would like to emphasize again that there is nothing out there for free. Even if you don’t pay for it, those who offer the service (or whatever is given for “free”) do get something in exchange. It might be your telephone number, your email address or something similar which is worth a lot on the Internet. ...

Continue Reading New phishing-spam waves using Facebook as bait

This could save your LIFE!

  • Post author: Omid Farhang
  • Post published: August 29, 2010
  • Reading Time: 4 min
  • Word Count: 811 words

The following internet advice which may have a subject title such as above could just get you killed. Like any other middle aged, balding, over-weight chap my mother still worries about me. So when her friend sent this to her and many other people, she forwarded it to me first:- Just in case!!! Let’s say it’s 6.15pm and you’re going home (alone of course), after an unusually hard day on the job. ...

Continue Reading This could save your LIFE!