| 

Want to Make Easter Even More Magical? Click me!

  • Post author: Omid Farhang
  • Post published: April 3, 2010
  • Reading Time: 1 min
  • Word Count: 151 words

As Easter approaches, spam related to this upcoming holiday is expected. Spammers didnā€™t send malicious greetings like last yearā€”they sent out various product promotion ads instead. One particular coupon promotion page offers recipients a free coupon for digital TV service for Easter. A domain attack was observed from this spam attack, and the offer page changed to different product coupons on a daily basis. 1 2 _From: ā€œThe Easter Bunnyā€ <easterbunny removed> Subject: How to make this Easter even more magicalā€¦</easterbunny>@>_ ...

Continue Reading Want to Make Easter Even More Magical? Click me!

Ah yes. FBI agent Brad Martins with the ā€œglobal scam Fither in CA 93535ā€

  • Post author: Omid Farhang
  • Post published: March 31, 2010
  • Reading Time: 1 min
  • Word Count: 166 words

Good God! A 419 scam email from someone in grade school! From: FBI AGENT [mailto:[email protected]] Sent: Wednesday, March 31, 2010 7:34 AM Subject: FBI AGENT Hello honest peopleā€¦ā€¦ā€¦ We got your contact from our Microsoft data-base system. This is to inform you all that have lost money to Scammers in Africa, Europe and USA. We hear by inform you there is quick opportunity for you mostly on lottery. My name is FBI brad Martins I assure you am doing all I can to get your lost money back in 2 days . I know what scam means. I work with the global scam Fither in CA 93535.we have all the global scam computer to trace all Scammers Name and location. Reply back to us. We just caught a scammer now, and we found some money with him, we are returning it back to those involves. This mean your money will be refund back to you.Get back to the FBI through this email for immediate response [email protected] ...

Continue Reading Ah yes. FBI agent Brad Martins with the ā€œglobal scam Fither in CA 93535ā€

EXEs in word docs

  • Post author: Omid Farhang
  • Post published: March 30, 2010
  • Reading Time: 1 min
  • Word Count: 168 words

Today, our friends at Trend Micro blogged about a new attack vector using Microsoft Word documents. We saw this as well last week, and have written a detection for the dropped trojan. Itā€™s not just a ā€œlawsuitā€ thatā€™s being spammed, we also picked up another form of this attack in our honeypots over the weekend: When you open the Word document, you see a ā€œPDFā€, but itā€™s actually not. Itā€™s a JPG, which links to an executable. ...

Continue Reading EXEs in word docs

Fake Lawsuit Notification Attack

  • Post author: Omid Farhang
  • Post published: March 26, 2010
  • Reading Time: 1 min
  • Word Count: 201 words

A few of days ago, we encountered an e-mail with a malicious RTF attachment. It was sent with a supposed lawsuit notification message. The e-mail didnā€™t mention any company by name and took a shotgun, rather than targeted, approach. Today, a security blogger forwarded us (and others) his version of the e-mail: At this point, it appears that the attachment has been replaced by hyperlink pointing to the Marcus Law Center. ...

Continue Reading Fake Lawsuit Notification Attack

Child Tax Credit is the New Phishing Bait

  • Post author: Omid Farhang
  • Post published: March 26, 2010
  • Reading Time: 2 min
  • Word Count: 364 words

Who wouldnā€™t want some tax benefits in the current economic times? Donā€™t phishers and scammers know that all too well! In a new phishing scheme, We found that Child Tax Credit is being used as bait to lure parents to disclose their financial data. This attack specifically tries to convince users to make claims for credit and lower their tax burden by using their childrenā€™s education expenses. According to the Internal Revenue Service (IRS) website [PDF], taxpayers may be able to reduce their federal income tax by up to $1,000 for each qualifying child. Making use of this information, spam email discusses the expensive education of children and quickly advises recipients to use this expense to make claims for tax credits under the numerous tax benefits provided by the IRS. They make a further appeal that as a U.S. citizen or resident, recipients should apply for their tax returns. According to the email, users can get a tax refund of $75,000 for their childrenā€™s education. To apply for a refund, users need to complete a form attached to the email message. The fraudulent email has an HTML attachment named ā€œ#1924819299.pdf.htmā€. ...

Continue Reading Child Tax Credit is the New Phishing Bait

It takes only one &#8216;nice' person

  • Post author: Omid Farhang
  • Post published: March 25, 2010
  • Reading Time: 2 min
  • Word Count: 299 words

In the security industry we often focus heavily on new technologies and shiny new software, and forget that so much of what we see is dependent on the person behind the computer. Today, a co-worker of mine was sent an email from someone she doesnā€™t know, with the following text: ā€œIā€™m writing this with tears in my eyes,my fam and I came down here to Wales,United Kingdom for a short vacation unfortunately we were mugged at the park of the hotel where we stayed,all cash,credit card and cell were stolen off us but luckily for us we still have our passports with us. ...

Continue Reading It takes only one &#8216;nice' person

Merogo SMS worm

  • Post author: Omid Farhang
  • Post published: March 22, 2010
  • Reading Time: 1 min
  • Word Count: 204 words

Weā€™re investigating a series of SMS Worms, found in the wild in China. Known as Trojan:SymbOS/MerogoSMS, these worms try to spread on Symbian Series 60 3rd Edition devices. Symbian continues to be by far the most common smartphone operating system in the world. These worms spread by sending text messages to other phones. These text messages contain variable messages (in Chinese), and a link to a website. If the link is followed, user is prompted to install an application ā€“ infecting the phone and restarting the SMS spreading. ...

Continue Reading Merogo SMS worm

IMF money-making scam

  • Post author: Omid Farhang
  • Post published: March 22, 2010
  • Reading Time: 1 min
  • Word Count: 186 words

I have seen a lot of these lately. This one currently doing the rounds tries to dupe the reader into thinking that the International Monetary Fund (IMF) wants to use their accounts to transfer money meant for charity. In the email. the IMF (supposedly) wants to transfer $10 Million into the readerā€™s account using NatWest Bank. The contact details within the Bank are given as follows: Name: Mr. Donald Miller (Co-founder) Office Address: 11 El Shams Bldgs., 8th District Nasr City E-mail: Bernisecharityfoundationimf ā€˜atā€™ gmail.com Tel: (+44) 7031-939-750 Fax: (+44) 7011830323 ...

Continue Reading IMF money-making scam

Please give me your credit card

  • Post author: Omid Farhang
  • Post published: March 22, 2010
  • Reading Time: 2 min
  • Word Count: 244 words

I wonā€™t abuse it, I promiseā€¦. cross my heartā€¦ spit into the windā€¦ etc. Hi folks, Yesterday, I received this SPIM (Instant message spam) ā€¦ usnews3.com sounds kind of official, doesnā€™t it? and the page looks impressiveā€¦ There are lots of links on the page, but unfortunately, a mouse-over of each link reveals that they all go to the same placeā€¦ Thatā€™s not a good sign for a legitimate webpage. Moreover, a whois shows that it was registered just on 7th December 2009, and that the ownership is hidden behind a privacy protector service. ...

Continue Reading Please give me your credit card

Can spam get worse?

  • Post author: Omid Farhang
  • Post published: March 19, 2010
  • Reading Time: 1 min
  • Word Count: 168 words

Or is it at the saturation point? The SANS Institute (acronym = SysAdmin, Audit, Network, Security) web site carried a blog piece that gives a good snapshot of the horrible ongoing plague of spam email that IT folks all over the globe must deal with. The writer, Deborah Hale, said the ISP in the Midwest where she works received almost 20 million pieces of email for more than 9,000 accounts since the beginning of March. Only 713,222 (3.6 percent) were NOT spam. ...

Continue Reading Can spam get worse?