Phishing Alert: MySpace.com / AIM
- http://www.websensesecuritylabs.com/alerts…php?AlertID=504
June 01, 2006
"Websense® Security Labs™ has discovered a phishing attack that attempts to steal the account information of MySpace.com users. A hyperlink is first delivered to victims via AOL Instant Messenger. Users who follow this link are taken to a fraudulent website that spoofs the MySpace.com login page. This page captures their MySpace account information and then forwards the user to the actual MySpace.com website. The fraudulent site also sets a cookie on the victim's computer, which prevents the phishing attack from being displayed on any subsequent visits. The phishing site is located in California and was up at the time of this alert. Screenshot available with full alert.
For additional details and information on how to detect and prevent this type of attack:
* http://www.websensesecuritylabs.com/alerts…php?AlertID=504 …"
I can't belive I was so stupid. Heh.
I followed it did something, and blah. Seems that all of my friends did too?
Another note, it posts a bulliten "Who Is Steven". Just noticed that today, when a bulliten poppedup that I didn't do.
Danny
Phishing Alert: FDIC
- http://www.websense.com/securitylabs/alert…php?AlertID=518
June 12, 2006
"Websense® Security Labs™ has received reports of a new phishing attack that targets customers of FDIC insured institutions. Customers receive a spoofed email message, which claims that their account is in violation of the Patriot Act, and that FDIC insurance has been removed from their account until their identity can be verified. This message provides a link to a phishing website which prompts users to enter account information to verify their identity. This phishing site is hosted in Hungary and was up at the time of this alert.
Phishing email:
'In cooperation with the Department Of Homeland Security, Federal, State and Local Governments your account has been denied insurance from the Federal Deposit Insurance Corporation due to suspected violations of the Patriot Act'…"
Pay Pal Phish Phlaw?
- http://isc.sans.org/diary.php?storyid=1422
Last Updated: 2006-06-16 17:05:22 UTC
"We've recieved a report of a potential flaw in the PayPal website that is being used to steal credit card and other personal information from PayPal users. The scam works by tricking users into accessing a URL hosted on the genuine PayPal web site. The URL uses SSL to encrypt information transmitted to and from the site, and a valid 256-bit SSL certificate is presented to confirm that the site does indeed belong to PayPal.
When the victim visits the page, they are presented with a message that has been 'injected' onto the genuine PayPal site that says, "Your account is currently disabled because we think it has been accessed by a third party. You will now be redirected to Resolution Center." After a short pause, the victim is then redirected to an external server, (apparently somewhere in Korean IP space) which presents a very convincing fake PayPal Member log-In page. Logging in sends the PayPal username and password to the bad guys and causes another page asking for more information (social security number, credit card number …) to remove the limits on the access of their account. More to come as we confirm information."
Also:
- http://news.netcraft.com/archives/2006/06/…tity_theft.html
Jun 16, 2006
EDIT/ADD:
- http://news.com.com/2102-7349_3-6084974.ht…g=st.util.print
Jun 16 17:16:35 PDT 2006
"…By exploiting the flaw, attackers were able to redirect people from a PayPal Web page to an online trap located in South Korea, a representative for the service said. The page actually has a real PayPal URL, but hosts malicious code that presents a message warning members that their account had been compromised. It then redirects them to a "phishing" Web site. At the malicious, information-thieving Web site, people are asked for their PayPal login information, experts at Netcraft, an Internet monitoring company in England, said in an advisory. Subsequently, the scammers are urged to enter their Social Security number and credit card details, Netcraft said. "As soon as we became aware of this scheme, we changed some of the code on the PayPal Web site. So this scheme, or any scheme like it, can no longer be effective," Amanda Pires, a PayPal spokeswoman, said in an interview…"
Yahoo! user account phishing
- http://isc.sans.org/diary.php?storyid=1463
Last Updated: 2006-07-06 00:10:23 UTC
"…The web site, which you can see*… is actually hosted on Geocities. The URL will immediately alert any user that knows what he's looking for (and this is why we can not stress enough how important user awareness and education is).
As you can see*… the design is fairly good, and if you don't check the URL, you might be fooled into entering your credentials here. There are couple of issues here about which we wrote recently ( http://isc.sans.org/diary.php?storyid=1277 ). While we were looking at bank web sites in the original diary by Johannes, we have a similar problem here. Although the credentials are transferred over the network securely (using SSL), the front web page seems to be plain HTTP. A typical user doesn't know how to check what's happening once he clicks on the "Login" button, so it's very easy to launch phishing attacks like this on them. That's why you should always use SSL on the front web page at least (yes, there are other numerous attacks on this, but let's stick to this subject for this moment).
Back to the phishing web page. Once a user tries to log in, his credentials are sent to a CGI script on a remote site which then (probably) e-mails this to the attacker. The last interesting thing is related to obfuscation of the HTML. The attacker decided to use a product called HTML Protector. This tool basically just obfuscates HTML code using JavaScript but as a browser needs to be able to parse the HTML code, the unobfuscation function always has to be present, so with some spare time you can easily unobfuscate this."
Phishing Alert: Google Mail
- http://www.websense.com/securitylabs/alert…php?AlertID=545
July 10, 2006
"Websense® Security Labs™ has received reports that a variant of Google phishing attacks (discussed in a previous alert*) are increasing in sophistication. Users are shown a spoofed copy of the Gmail login page with a message claiming, "You WON $500.00!" The message states that this prize money will be delivered to an e-Gold, PayPal, StormPay, or MoneyBookers account of their choice. If users select an account, they are informed that this prize money is only available to "premium members" of "Gmail Games." The page states that "Gmail Games" membership requires an $8.60 registration fee, and then asks users to pay the registration fee or forfeit the $500 prize money. Users are directed to an actual payment site to deliver the registration fee. This phishing site is hosted in the United States and was up at the time of this alert.
> Sample Email Lure:
* *You won $500! Gmail congratulates you!* *
CONGRATULATIONS!
YOU WON $500!*
Gmail gives members random cash prizes. Today, your account is randomly selected as the one of 12 top winners accounts who will get cash prizes from us. Please click the link below and follow instructions on our web site. Your money will be paid directly to your e-gold, PayPal, StormPay or MoneyBookers account.
Click here to get your prize:
Phishing Alert: -Fraudulent- "Stop Fraud Now" Program
- http://www.websense.com/securitylabs/alert…php?AlertID=546
July 10, 2006
"Websense® Security Labs™ has received reports of a new phishing attack that targets customers of Bank of America and various other banks. Users receive a spoofed email message, which claims that a new security program called SFN (Stop Fraud Now) has been launched. The program claims to provide protection against cloning of credit cards and asks users to provide details, such as Social Security Number, card number, and ATM Personal Identification Number (PIN). The message provides a link to a phishing website that requests users enter their personal information and account details. The phishing site is hosted in Canada and was up at the time of this alert.
> Phishing email: Bank of America' in collaboration with ALL the banks around the world which offers services of transactions through the internet and not only and several institutions against frauds launched a revolutionary program called SFN (Stop Fraud Now)'.
By registering on SFN your card is protected 99.99%. You probably wonder why we say that the chances of suffering a loss are 0. The moment you register you will receive a code which contains an international unique code (IUC). This code arrives to the bank which your card was released from. This way your card can't be cloned without knowing this code. Only the issuer bank can reproduce your card in case you loose it or has been stolen. Also you have many options from your account. On-line assistance through chat or virtual phoning (skype) non-stop and also the possibility of blocking your account through the push of a button anytime you find anything suspicious about it. You can unblock it as easy after solving the issues. Another helpful option you can find it in the internet Online section. There you have two buttons On-line and Off-line which allows y! ou to keep your card off-line for transactions and to active it only when you wish to shop or make a transaction. We guarantee it's a 100% efficient and secure program and monitored 24 hours a day, 365 days a year.
Click here < LINK REMOVED > to see the list of banks which support SFN program | Click here < LINK REMOVED > to visit our website for more informations!
JOIN NOW FOR MORE PROTECTION!
Your card no longer can be cloned!
Your card is monitored non-stop for a period of 356 days preventing suspicious transactions on the internet but also from the bancomat!
You have free assistance from our team anytime you're unclear about our services!
Once you created your account you can set your card to on-line or off-line for internet transactions! This option offers you 100% ASSURANCE that ONLY YOU are able to use the card for online transactions!
The chances of being a victim of a material loss is 0.01% and in the case supposing our system didn't work at the efficiency we promised, we guarantee 100% that your money will be recovered!
This service is offered by Bank of America in association with European Central Bank and National Australian Bank The project is of federal nature and is protected by the Federal Bureau of Investigation (FBI) and the National White Collar Crime Center (NW3C).
It is 100% FREE !
For more information about this program visit our website
< URL REMOVED >
Bank of America
Electronic Banking Services
CA4-701-02-75
P.O. Box 37000
San Francisco, CA 94137 …"
(Phishing Screenshots available at the URL above.)
Recent Two factor authentication attacks
- http://isc.sans.org/diary.php?storyid=1478
Last Updated: 2006-07-12 23:04:15 UTC
"There has been recent report* of two factor authentication protected websites getting attacked by the man-in-the-middle type of setup where the victim enter information (include the token code) into a look-alike website, this look-alike website immediate uses those credential to login to the actual financial site. Obviously, upon success login by the user, the attacker can immediately execute the fraudalent transaction. While this might sound shocking to the financial industry since we haven't seen too many of these attacks, the theory of the attack and the risk have certainly been well understood within the security community**… Overall, two factor authentication will reduce the risk of attacks by raising the effort of the attacker to compromise the accounts, but it might not have the level of security enhancement that some people believed. In the man-in-the-middle attack, the flaw happens due to the lack of verification of the bank's website by the victim, the victim are simply tricked into yielding credentials to a web site without authentication. This is really outside of the protection zone of the extra authentication factor.
To futher extend this, two factor authentication also does NOT protect the end host security, a malware (such as keylogger, BHO) could be installed on the client's machine and effectively gather the credential and login on behalf of the victim instead of letting the victim login. This is a classic problem of "you are only as secure as the weakest link". Two factor authentication is good for secure authentication but does not take care of mutual authentication or endpoint security. From the financial organization perspective, maybe further investment into mutual authentication and ensuring client's computer being free of malware would be necessary to protect the client's online transactions."
IRS refund… (phish) http://isc.sans.org/diary.php?storyid=1500
Last Updated: 2006-07-20 17:06:54 UTC
"…A cute little Phish Mail that claims to come from the IRS (Internal Revenue Service) who are desperately trying to refund some money directly to your Visa card. All they need is your Social Security Number and the Visa card #. And, incidentially, IRS processing seems to be done in Romania (hxxp://ap[dot]ro) nowadays. Outsourcing, most likely ;o) …"
E-Gold Scams
- http://isc.sans.org/diary.php?storyid=1507
Last Updated: 2006-07-24 00:00:45 UTC
"Reader Ivan alerted us earlier today about an email scam that has surfaced in the past few days. Here's the text of the message he saw:
Subject: egold transaction
Message:
Good day,
Yesterday I was checking my egold account and was surprised at what I saw: I had almost 200 ounces of gold (USD 100,177.90). I never had so much money, (I only had USD177.90 in my account at he time of this transaction) I don't know how did they get there. I clicked on history and saw that money were transferred 2 hours ago, in the memo field I saw your email address: When I was trying to sort this out - money disappeared from my egold account. I lost my money and money that came from nowhere. I changed my password immediately and now I am trying to find out what has happened. Luckily I made a screenshot with the transaction history for you to see and tell me what is going on. I hope that you will let me know what has happened. I did not contact egold support yet. I hope that we will be able to sort this matter ASAP. Before I will contact them.
Regards,
Jannet Johnston
Not a bad job of building a scam. As you might expect, there was a file attachment that looks fairly innocent, "screen.zip" and likely would fool many unsuspecting victims. Opening the file we find an executable file inside the archive that is named "screen.jpeg (many spaces) .exe" that in turn has a filesize of 8,485 bytes. Most of you know what happens next…
Ivan did a bit more analysis and found that the .exe file drops a .dll component that is installed as a Browser Helper Object (BHO). The dropped component also downloads mailordermarijuana.ca/images/mod.gif (careful!!) The mod.gif file (11,570 bytes) is also a .exe dropper which in turn also installs another .dll in the infected system. The second .dll looks like a Trojan-Spyware stealing e-gold account information from the users of the infected system. Handler Lenny found a blog* that seems to indicate this scam started a few days ago…"
New Haxdoor variant via spoofed E-mail from ecost
- http://isc.sans.org/diary.php?storyid=1508
Last Updated: 2006-07-24 14:53:45 UTC
"We received several notifications of an email being spoofed from ecost. It is being used to "socially engineer" or trick people into installing a new version of Haxdoor. This virus was largely undetected by most of the commercial antivirus vendors yesterday. We have submitted samples to most of the commercial antivirus vendors. They are responding rapidly and in many cases they are able to detect it now…
—- Text from original message —–
Dear Sir/Madam,
Thank you for shopping with our internet shop. Your order, WC2905036, has been received. Summary of your order you can see in the attachment file.
This email is to confirm the receipt of your order. Please do not reply as this email was sent from our automated confirmation system.
Please Note: There is no need to re-send your request or call our customer service department for status or tracking number, this will only delay our response time to you. Rest assured, we are making every effort to process and ship your order within 1 to 2 business days. We appreciate your understanding and patience and do value your business.
Once your order has been processed and shipped a FEDEX Tracking number will be automatically emailed to the address provided.
Please Note: Tracking information will be available in FedEx's system only after 10pm EST Monday thru Friday. If you receive a tracking number on Sunday, you will be able to track it Monday evening after 10pm EST. All orders placed including 1-2 or 2-3 business day options are shipped within 48 hours providing the merchandise is in stock.
All FedEx Ground orders will take 7-10 business days to arrive. Some packages may require a signature upon delivery. These packages will not be left without a signature. For your convenience, we will email you a FedEx tracking number on all successfully processed and shipped orders. All Plasma TVs, DVD players, Scanners, Fax Machines, Receivers, Home Theater, and Printers are not returnable after box is opened.
To insure the best handling of your order please allow 24-48 business hours for the processing and the shipping of your order. Thank you for your cooperation.
We hope you enjoy your order! Thank you for shopping with us!
—– End text from message —–
(May be similar to: http://www.symantec.com/security_response/…-071214-4735-99
: "…Backdoor.Haxdoor.N is a Trojan horse program that opens a back door on the compromised computer and allows a remote attacker to have unauthorized access. It also steals passwords and drops a rootkit that will run in safe mode, making this threat difficult to remove…")
- http://isc.sans.org/diary.php?compare=1&storyid;=1508
Last Updated: 2006-07-25 16:22:24 UTC …(Version: 2)
"UPDATE: These are also being sent out spoofed from [removed] and [removed]…"
==========================================
Yet another:
Subject: Your order information WC2905036
Message: Dear Sir/Madam, Thank you for shopping with our internet shop. Your order, WC2905036,has been received. Summary of your order you can see in the attachment
file.
Attachment: wc2905036.exe …"
- http://www.darkreading.com/document.asp?do…;WT.svl=news1_1
8.1.2006
"…A phishing email is circulating that poses as a message from [removed] and offers prize money that a recipient would claim by linking to the "Microsoft Resolution Centre," a malware site that mimics Microsoft's but has malware that then installs a Trojan on the victim's PC. The phish was first spotted by SurfControl* in Sydney, Australia over the weekend. "The Trojan will open a backdoor on the PC, allowing a remote intruder to gain access and control over the computer," says Susan Larson, vice president, threat analysis and research at SurfControl, which contacted Microsoft about the phish…"
* http://www.surfcontrol.com/ViewHandler.asp…amp;mnuid=6.2.1
Phishing Alert: Data Stolen via ICMP/IE-BHO
- http://www.websense.com/securitylabs/alert…php?AlertID=570
August 07, 2006
"Websense® Security Labs™ has received a sample of a new phishing Trojan that delivers stolen information back to the attacker via ICMP packets. Upon infection of a victim's computer, the Trojan will install itself as an Internet Explorer Browser Helper Object (BHO). The BHO then waits for the user to post personal information to a monitored website. As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique. Typically, keyloggers of this type will send the stolen information back to the attacker via email or HTTP POST, which can appear suspicious. Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into the data section of an ICMP ping packet.
To network administrators and egress filters, this ICMP packet looks like legitimate traffic leaving the network. However, the ICMP packet actually contains encoded personal information entered by a user. The attackers presumably capture this packet at their remote server, where the packet is easily decoded to reveal the information entered by the user…"
Brasilian Right to Vote revoked by Phish!
- http://www.websense.com/securitylabs/alert…php?AlertID=576
August 16, 2006
"Websense® Security Labs™ has received reports of a new phishing attack that targets customers of the Brasilian Tribunal Superior Eleitoral. Users receive a spoofed email message claiming that their entry in the electoral roll has been cancelled. To learn the reason for the cancellation and be able to reinstate their right to vote at the upcoming elections, they will have to read the attached regulations. The link provided by the email leads to a download for a Trojan that installs malicious code on the user's computer. The URL leading to the malicious code is hosted in Korea and was up at the time of this Alert…"
AT&T hack exposes 19,000 identities
- http://www.sfgate.com/cgi-bin/article.cgi?…;type=printable
September 1, 2006
"…AT&T's press release this week made no mention of the phishing aspect of the scam. But the company's internal memo warns employees to be on the lookout for phony e-mail. "Impacted customers may receive an e-mail that appears to be from AT&T but is actually from the unauthorized person requesting additional personal information such as Social Security number, driver's license number, date of birth or other credit card information," it says. AT&T's Sharp said individual customers were warned of the phishing threat in e-mail this week from AT&T. "We don't know how many people received the phishing e-mails," he said. "We indicated (to customers) that there was an apparent phishing expedition going on that was linked to this incident and was not from AT&T"…"