Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Thursday, November 20, 2014

Fake Tech Support Scams

Fake Tech Support Scam

Although not all of the fake tech support callers misrepresent that they are calling on behalf of Microsoft, claiming to represent Microsoft or Windows is most commonly used in such calls.  Scammers also claim to represent other vendors such as Dell, McAfee and Norton.

Two operations working out of the state of Florida have conned tens of thousands of consumers out of more than $120 million through their deceptions.  The FTC and state of Florida obtained a federal court orders to shut down those two operations for deceptively marketing computer software and tech support services. The court orders have additionally placed a temporary freeze on the defendants’ assets and have placed the businesses under the control of a court-appointed receiver.

As welcome as the FTC action is, fake tech support scams have been harassing people since early in 2009 and this is not the end of it.  As I recommended over two years ago:
Should you receive an unsolicited telephone all from someone purporting to be from Microsoft (or any other vendor), the best advice is to just hang up! Microsoft does not make this type telephone call.
There are also people who try to keep these cybercriminals on the telephone in order to not only waste their time but also to keep them tied up so they are not calling someone else who may not realize the caller is a scammer.  Microsoft recently published an online form to Report a technical support scam.  By supplying as much of the information as possible requested on the form, you will be assisting both Microsoft and law enforcement agencies in stopping these cybercriminals.  

References:


Home
Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Sunday, July 29, 2012

Get a Second Opinion from Virus Total

It is not uncommon that an antivirus or anti-malware software program has a f/p (false/positive) detection in a scan. In the event a file that has been on your computer for some time suddenly turns up during a scan, the first recommendation is quarantine rather than remove. If it is a f/p, the file can be restored from quarantine but not easily replaced if deleted, particularly if it is a critical system file.

How can you determine if the detection is a f/p? There are various vendors that provide free on-line computer scans but, in this case, we are looking at one particular file. Among the many services Virus Total provides is the ability to navigate to a specific file on the PC and send it to VirusTotal. As you can see by this example, not every service was detecting this Zbot variant when it was submitted.

To scan an individual file at VirusTotal, just go to https://www.virustotal.com/. Navigate to the location of the file on your computer. After the file is uploaded, click the Scan it! button.

There is more to VirusTotal than scanning individual files. With so many malicious websites, there are occasions when you may want to check whether a site is safe before visiting. VirusTotal also includes the ability to scan URLs. In addition to the Malware Domain Blocklist being integrated in VirusTotal's URL scanning engine, it also includes hpHosts.

hpHosts is maintained by my friend and fellow Microsoft Consumer Security MVP, Steve Burn. The activities that result in domains being included by hpHosts are described at VirusTotal as follows:

  • "Domains being used for advert or tracking purposes.
  • Domains engaged in the distribution of malware (e.g. adware, spyware, trojans and viruses etc).
  • Sites engaged in or alleged to be engaged in the exploitation of browser and OS vulnerabilities as well as the exploitation of gray-matter.
  • Sites engaged in the selling or distribution of bogus or fraudulent applications.
  • Sites engaged in astroturfing otherwise known as grass roots marketing.
  • Persons caught spamming the hpHosts forums.
  • Sites engaged in browser hijacking or other forms of hijacking (OS services, bandwidth, DNS, etc.).
  • Sites engaged in the use of misleading marketing tactics.
  • Sites engaged in Phishing.
  • Sites engaged in the selling, distribution or provision of warez (including but not limited to keygens, serials etc), where such provisions do not contain malware."


The next time you are unsure of the safety of a website, go to VirusTotal and Scan it!



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Saturday, August 21, 2010

Devasting Results from E-mail Scam

Graham Cluley reported a devasting story about 67-year-old Al Circelli who committed suicide after losing $50,000 to West African romance scammers.

"Circelli's son Peter says he stumbled across evidence that his late father had wired considerable amounts of money to Ghana, and discovered email messages and photos on his father's laptop supposedly from a woman called Aisha, who wanted to come to the USA to begin a new life and promised to bring a small fortune with her

According to media reports, "Aisha" needed money to be sent to her in Ghana via Western Union to pay for expenses - and when Circelli ran out of his own money, he took out credit cards in his son's name and stopped making mortgage payments.

Peter Circelli says that his father commited suicide on the day that "Aisha" was due to arrive in the USA but, of course, she never showed up. Bizarrely, an email message has been found on the dead man's laptop from a Ghanaian intermediary in the money transactions claiming that "Aisha" had also killed herself."

Let this be a wake-up call to anyone who has gullible family members. Make certain that they understand about phishing scams. Natural disasters, elections, tax time, holidays all result in a spew of new scams. Be sure to educate your family.

In addition to the references below, additional tips and information on phishing are available in these Security Garden posts.


References:

, Phishing, Fraud



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Wednesday, March 10, 2010

Its Income Tax Time – Avoid Tax Fraud

IRS

The deadline for filing income tax returns in the U.S. is April 15. As that date approaches tax payers are anxiously searching references and online tax preparation services. Caution is advised because fraudsters and phishers thrive during this time of year.

The best authority for tax questions is the official IRS website, located at irs.gov. Just as Microsoft does not contact an individual directly about security updates, neither will the IRS use e-mail to communicate any personal information. (Telephone 1-800-829-1040 to determine if an IRS contact is legitimate.)

The same goes for unsolicited e-mails from a supposed tax-preparation company. Always expect that such e-mails are phishing attempts. To better understand phishing attempts, see How to recognize phishing e-mails or links.

Not everyone is in a position to afford the latest computer operating system. In the event you are still using Window XP, you will want to ensure that your computer is as secure as possible prior to using an online tax preparation service. A computer infected with a backdoor trojan or keylogger is an invitation to identity theft. To determine if your computer is infected, run a full-system scan with an up-to-date antivirus product such as Microsoft Security Essentials, the Windows Live OneCare safety scanner or ESET Online Scanner.

If you are filing your taxes online, it is important that you use as secure a browser as possible. I recommend either Internet Explorer 8 or Mozilla Firefox 3.6. Also make sure that the Web address begins with https.

Save and happy returns!

References:

, Phishing, Fraud


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, October 05, 2009

Windows Live Hotmail Phishing Scheme

Earlier today, Neowin reported that thousands of Windows Live Hotmail account details were publicly exposed:

“An anonymous user posted details of the accounts on October 1 at pastebin.com, a site commonly used by developers to share code snippets. The details have since been removed but Neowin has seen part of the list posted and can confirm the accounts are genuine and most appear to be based in Europe. The list details over 10,000 accounts starting from A through to B, suggesting there could be additional lists. Currently it appears only accounts used to access Microsoft's Windows Live Hotmail have been posted, this includes @hotmail.com, @msn.com and @live.com accounts.”

The Windows Live Team, Windows_Liveconfirmed that the logon account information of several thousand Windows Live Hotmail accounts were exposed on a third-party site. It is believed that this was due to a likely phishing scheme.

Edit to add Windows Live Team Update:

"As of 3pm PT: We want to provide a quick update, that as a result of our investigation we are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts.

If you believe your information was documented on the illegal list, please fill out the following form to reclaim access to your account."

If your account was compromised, please see “What to do if you think your account has been stolen”.

The Windows Live Team provided the following steps to take if you are a victim to this or any phishing scam:

Q: What should you do if you fall victim to a phishing scam? How should you respond? What steps should you take?

A: If you think that you may have responded to a phishing scam with personal or financial information or entered this information into a fake website, you should take four key steps: (1) report the incident to the proper authorities, (2) change the passwords on all your online accounts, (3) review your credit reports and your bank and credit card statements, and (4) make sure you are using the latest technologies to help protect yourself from future scams.

  1. For the first step:
    • If you have given out your credit card information, contact your credit company right away. The sooner a company knows your account may have been compromised, the easier it will be for them to help protect you.
    • Next, contact the company that you believe was forged. Remember to contact the organization directly, not through the e-mail message you received. Or call the organization's toll-free number and speak to a customer service representative. For Microsoft, call the PC Safety hotline at:
      1-866-PCSAFETY.
    • Then, report the incident to the proper authorities. Send an e-mail to spam@uce.gov to report it to the Federal Trade Commission and to reportphishing@antiphishing.org to report it to the Anti-Phishing Working Group.
  2. The second step is to change the passwords on all your online accounts. The reason for this is that a lot of people use the same password for multiple accounts. Start with passwords that are related to financial institutions or personal information. If you think someone has accessed your e-mail account, change your password immediately. If you’re using Hotmail, go to: http://account.live.com.
  3. The third step is to review your bank and credit card statements and your credit report monthly for unexplained charges, inquiries or activity that you didn’t initiate.
  4. Finally, make sure you use the latest products, such as anti-spam and anti-phishing capabilities in e-mail services, phishing filters in Web browsers and other services to help warn and protect you from online scams.”

As a precautionary step,it is advised that Windows Live Hotmail passwords be changed every 90 days. Instructions for changing your password as well as getting a refresh reminder are available in “Let Hotmail Remind You To Refresh Your Passwords Every 72 Days”.

With the end of the year Holidays approaching, phishing scams will be on the rise. Learn how to Create strong passwords, Protect your Windows Live ID and much more at the Microsoft Online Safety Fraud Prevention web page.

Clubhouse Tags: Security, Password, Windows Live, How-to, Hotmail, Clubhouse, Safety, Phishing, Information




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Trackback: http://windowslivewire.spaces.live.com/blog/cns!2F7EB29B42641D59!41528.trak

Tuesday, April 14, 2009

U.S. Tax Season and Phishing Scams

Yes, I waited until close to the last minute to file our tax returns. Figuring it out both ways, it worked out better for us by filing our return as married/separate.

If you are in the mad scramble to file your return on time, don't fall into any phishing scams. As US-Cert reported today:
"Phishing scams may appear as a tax refund, an offer to assist in filing for a refund, or contain details about fake e-file websites. These messages may appear to be from the IRS and directly ask users for personal information. These messages may also contain a link and instruct the user to follow the link to a website that requests personal information or contains malicious code.

US-CERT encourages users to take the following measures to protect themselves from this type of phishing scam:
Reference: US Tax Season and Phishing Scams



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, December 21, 2008

Beware of Malware Disguised as Holiday Greetings

The Microsoft Security Tips and Talk blog published this timely reminder to Beware of Malware Disguised as Holiday Greetings. It bears repeating here:

"The Microsoft Malware Protection Center (MMPC) recently noted the inevitable increase in holiday-themed viruses and worms.

There's not much new about this malware: You get an e-mail or instant message that promises a greeting, holiday image, or music.

If you click the message, your computer gets infected with the malware which can easily spread to all of your contacts.

Remember, take these five steps to help prevent any kind of malware:

  1. Use a firewall.
  2. Update your operating system.
  3. Use antivirus software and keep it updated.
  4. Use antispyware software and keep it updated.
  5. Approach links in e-mail, on social networking sites, or in IMs with caution.

To read more about holiday malware, see Merry Malware - You’d better watch out, you’d better think twice and O Come All Ye Malware or check out the entry in our virus encyclopedia."


Think before you click!



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Sunday, October 12, 2008

Fake Security Update E-mail

No matter how many times people are told that Microsoft does not send updates of any kind via e-mail, there are still people who fall for the well-crafted fake.

If you receive the following, do not open the attachment. Delete, delete, delete! It is not from Microsoft.

Subject: Security Update for OS Microsoft Windows

Dear Microsoft Customer,

Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium, Microsoft Windows XP, Microsoft Windows Vista.

Please notice, that present update applies to high-priority updates category. In order to help protect your computer against security threats and performance problems, we strongly recommend you to install this update.

Since public distribution of this Update through the official website http://www.microsoft.com would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all Microsoft Windows OS users.

As your computer is set to receive notifications when new updates are available, you have received this notice.

In order to start the update, please follow the step-by-step instruction:

1. Run the file, that you have received along with this message.
2. Carefully follow all the instructions you see on the screen.

If nothing changes after you have run the file, probably in the settings of your OS you have an indication to run all the updates at a background routine. In that case, at this point the upgrade of your OS will be finished.

We apologize for any inconvenience this back order may be causing you.




Thank you,



Steve Lipner
Director of Security Assurance
Microsoft Corp.











Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, October 04, 2008

Cyber Security Awareness Tip of the Day: October 4

Along with the current financial news regarding bailouts, financial institution failures and bank mergers comes the inevitable increase in phishing. Attachments contain malware and links are tricks to obtain your personal information.

October 4 Tip of the Day

Don't be a victim. Learn to recognize the difference between a legitimate e-mail and a phish. Take the SonicWALL Phishing and Spam IQ Quiz. Be sure to check the explanations for any you get wrong at the end of the quiz.

As you can see, I practice what I preach. My results:

You got 10 out of 10 correct.
100%











Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, September 29, 2008

Cyber Security Awareness Month


October is National Cyber Security Awareness Month. The purpose of Cyber Security Awareness is to call attention to the importance of protecting the online information of you and your family. As StaySafeOnline describes the goal:
"The goal of National Cyber Security Awareness Month is to educate everyday Internet users on how to "Protect Yourself Before You Connect Yourself", by taking simple and effective steps."
Therein begs the question: How can I protect myself before I connect?

In the Microsoft reference below, there are
four suggested steps, the first three being to use a firewall, antivirus software, and antispyware software. The remaining recommendation by Microsoft is to turn on automatic updating.

Ensuring those steps are in place will provide your computer with the basic protection that is needed and are, of course, absolutely necessary. Is that sufficient? What else do you need to do? I like the way fellow Microsoft MVP, Harry Waldron explained that Security requires both technical defenses and user awareness:
"Home and corporate users cannot be expected to become security experts. Conversely if someone totally ignores the many dangerous security exposures, they will most likely experience technical issues with their PC or they could even become a victum of fraud. Instead, users should be taught the basic principles of risk avoidance and where to go to for help."
In recognition of Cyber Security Awareness Month, following is a collection of articles I have compiled that will provide both information as well as places to go for help so you can Protect Yourself Before You Connect Yourself.

Child Safety

As parents, grandparents and other family members, keeping our children safe online is paramount. The documents below contain information to sources providing guidance
for protecting the privacy and personal safety of our children. General Security

General security sites, including government as well as sites providing virus warnings and security advisories.

Phishing

As Harry Waldron indicated in the article linked above:
"Many attacks user social and technical engineering approaches that can deceive even highly experienced users. For example, malware authors use embed actual HTML from the real websites or simulate Windows dialog boxes"
The social engineering techniques used by malware authors are particularly clever when it comes to phishing. Learn how to recognize a phish and protect yourself from potential identity theft.
Secure Your Wireless Network

As families add additional computers to the home environment, wireless networks are becoming very common. Don't let your wireless network be a source of data or identity theft. Be sure it is propery secured.



Cyber Security Awareness References:



Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, September 05, 2008

Recognize the 5 Most Common Types of E-mail Scams

The Windows Live Hotmail team recently published a fantastic article providing not only examples but explanations on recognizing E-mail scams. A couple of the examples are Microsoft-specific, using a Hotmail and a "Microsoft Promotions" example. Apply the learnings in the examples provided and you may not only save getting your computer infected, but prevent identity theft as well.

Even if you are cautious and recognize scams, perhaps your "Great Aunt Emma" is gullible or too trusting. Take the time to share this information with that gullible aunt, trusting uncle or kindly neighbor who "only uses the internet to check her E-mail".

Windows Live Hotmail: Learn how to recognize the 5 most common types of E-mail Scams




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Friday, June 06, 2008

Phish: 2008 Economic Stimulus Refund!

The following is NOT from the Internal Revenue Service. It is a cleverly created phish. Rest assured anyone who provides their bank information at the link in the email (removed in this copy) will soon find their bank account emptied.

Don't you just love the note at the end.

From: Internal Revenue Service
To: Undisclosed Recipients
Subject: 2008 Economic Stimulus Refund!





Over 130 million Americans will receive refunds as part of President Bush program to jumpstart economy. Our records indicate that you are qualified to receive the 2008 Economic Stimulus Refund. The fastest and easiest way to receive your refund is by direct deposit to your checking/savings account. Please follow the link and fill out the form and submit before June 10th, 2008

Submitting your form on June 10th,2008 or later means that your refund will be delayed due to the volume of requests we anticipate for the Economic Stimulus Refund.

To access Economic Stimulus Refund, please click here.

Note
: If you received this message in your SPAM/BULK folder, that is because of the large amount of e-mails we are sending out or because of the restrictions implemented by your ISP,




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, May 03, 2008

Protect Yourself or a Friend from Phishing & Fraud

I have published quite a few posts on phishing since starting this blog. If you are a regular reader, you may have seen some of the previous posts and think to yourself, ok, nothing new here. Wait, please. Before you move on to another website, please
Think about your favorite aunt or the nice gentleman who lives next door. Has anyone explained to them about phishing? Perhaps not.
or consider
Are you the "family computer fixer"? You know who you are -- the person in the family that all the cousins, nieces and nephews call when they are having a problem with their computer. Do they understand phishing? Perhaps not.
Don't take a chance that your family or friends might fall for a phish and suffer possible financial loss and/or identity theft. Explain to them how serious the problem has become as well as how clever the phishers are these days.

Microsoft published a series of articles, individually linked below, on how to protect yourself from phishing and fraud. Use the information there to educate your family and friends and to refresh your own knowledge. If you volunteer at a community center or youth group consider making a presentation on phishing. You could show the FTC videos on phishing on YouTube at http://www.youtube.com/ftcvideos

How to help avoid phishing scams

How to recognize a phishing scam
Use technology to protect yourself from phishing and fraud




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, April 07, 2008

Phishing is not your Phriend

This video of CastleCops Founder Paul Laudanski's lecture recorded in Ford Theater on October 18, 2007, was just made available. In the video, Paul provides a bit of information on himself and Robin as well as Castle Cops and discusses Phishing Methods, Detection, and Data Tracking. The lecture was presented at the invitation of Case Western Reserve University. Sit back and enjoy Paul's excellent presentation:



From YouTube


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, November 12, 2007

Holiday Online Shopping Safety Tips

We (finally) had our first notable frost yesterday morning. I couldn't resist snapping a picture of one of the dwarf barberry bushes. The frost and cold reminded me that it will soon be Thanksgiving in the U.S., which tends to mark the start of the Holiday shopping season.

I was reminded further when I received an E-mail from Amazon.com announcing "Free Shipping on the Season's Best Toys". Highlighted was a section on "Black Friday Deals". Black Friday in the U.S. is the day after Thanksgiving and the biggest shopping day of the season. That is followed closely by "Cyber Monday" when people return to work following the long weekend and take advantage of their company's high-speed internet connection or shop from work because they do not have a connection at home. (I suppose there are still homes without an internet connection.)

With this blog post in mind, I bookmarked the article, "Best Practices for Online Shopping" that Microsoft MVP Harry Waldron reproduced in August from Net World. You can find a link to that article as well as some additional safety tips in the references at the end of this post.

It seems that Nellie2 and I are on the same wave-length (again) as she also recalled Harry Waldron's post from last year on Cyber Monday. In fact, as I looked back to last year, I see that I had also quoted Harry's post when I wrote "First Black Friday, Then Cyber Monday".

Don't be a victim. If you are planning on doing on-line shopping for Holiday gifts, stick to the sites you know to be safe and check out the tips in the linked references below.

References:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, July 09, 2007

Beware of "Customer Support Robot"

Just like the phony e-card from a friend, neighbor, spouse, or other unidentified source, the emails from "Customer Support Robot" are also packed with trouble. This time, however, the creators of the Storm Worm (Nuwar) have disguised the infected path with a URL link that when moused over yields the IP Address.

The subject may vary from "Spyware Alert!", "Trojan Detected!", "Virus Detected!", etc. Regardless of the subject, don't be fooled. Instead, click the delete key.

The link from the sample below was removed and changed to red:

"Dear Customer,

Our robot has detected an abnormal activity from your IP adress
on sending e-mails. Probably it is connected with the last epidemic
of a worm which does not have official patches at the moment.

We recommend you to install this patch to remove worm files
and stop email sending, otherwise your account will be blocked.

Customer Support Robot"


References:




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Saturday, June 30, 2007

You have NOT received a postcard from a friend!

Indeed, that postcard is not from a friend, family member or partner! Instead, it is a Storm variant. The variations I received, along with the order confirmations for "val1um" and the opportunity to order "repl1ca Cart1er r0lex w4tches", the past couple days include:
  • You've received a postcard from a family member!
  • You've received a greeting card from a friend!
  • You've received an ecard from a partner!
See the report from SANS.




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, June 18, 2007

Q&A With Security MVP Experts 21June07

Do you have questions about security your computer? Online safety? Malware? Phishing? If that is the case, join the Microsoft Security MVPs in a question and answer chat in the Microsoft TechNet Chat Room on Thursday, June 21, 2007.

We invite you to attend an Q&A with the Microsoft Security MVPs. In this chat the MVP experts will answer your questions regarding online safety issues such as phishing, spyware, rootkits as well as server related topics. If you have questions on how to protect your PC, please bring them to this informative chat.

When: Thursday June 21st
Time: 4 pm PST (7pm EST)
Where: TechNet Chat Room www.microsoft.com/technet/community/chats/chatroom.aspx
No password required
References:



Remember - "A day without laughter is a day wasted."

May the wind sing to you and the sun rise in your heart...





Wednesday, May 23, 2007

Extremely dangerous Better Business Bureau spam with malware

Reported by SunbeltBLOG as seen in the wild is highly "personalized" spam that appears to be from the “Better Business Bureau”. The RTF (rich text format) document is loaded with malware and when opened, it downloads:

1. More malware

2. TightVNC

3. WinRAR

As reported by Sunbelt researchers, this thing is designed to steal data and results from Virus Total yield very thin coverage. You've been warned!

SunbeltBLOG Report


Friday, May 04, 2007

No Charge for Windows Genuine Advantage

I learned from fellow MVP, Donna Buenaventura, that Symantec has identified as Trojan.Kardphisher. The Trojan is installed when the PC is restarted. A window appears that has been designed to look like the Windows Genuine Advantage (WGA) Activation Form.

There are two options presented on the form -- activate now or later. According to Symantec, it isn't possible to run Task Manager or any other applications. Choosing no results in immediate shutdown of the computer. Selecting yes presents an activation window, but not quite what is provided by Microsoft.

The trojan window requests credit card information.
Microsoft does NOT request credit card information for WGA Activation. Do not be tricked into providing credit card information. Instead, update your antivirus software and run a full system scan. If you need assistance, visit one of the ASAP Member Sites.