Journalist Brian Krebs and few other reporters are to be featured in an upcoming documentary co-financed by BBC Storyville where viewer will be able to witness hands-on forensics that uncover the perpetrators and follow film makers as they film cases and investigations in real time.
However, this project will only be funded if at least $20 000 is pledged by Saturday, June 2, 2012. For more information and to support the project please click here.
- Basic online safety tips
- |
- Free malware removal tools from Emsisoft
- |
- Speed up and secure your Web browser
- |
- Anti-malware for Windows server 2003 / 2008
- |
- How to spot scam
- |
- How a banking trojan can steal your data and money
- |
- Fake antivirus and the dark side of online money making
- |
- Bot description and removal
- |
- Free bot detectors and anti malware tools from Trend Micro
- |
- Ways a Win or Mac system can get infected
- |
|
Click here for a fast 1 min diagnostic scan!
Emsisoft Malaware is a free cloud based ultra fast online anti-malware scanner. |
Online safety, anti malware policy and pc security essentials. Free spyware adware malware removal tools and advice |
Showing posts with label internet fraud. Show all posts
Showing posts with label internet fraud. Show all posts
Tuesday, 24 April 2012
Monday, 26 March 2012
Sunday, 4 March 2012
Rogues and the dark side of online money making
Scareware
Have you got the anti-virus software that shows you a list of threats and won't go away until you buy a registration for it? Does it look more like a virus than legitimate anti-virus? If that sounds about right then you most likely are dealing with rogue anti-malware threat. The following video by rynesandbergfan23 shows a demonstration of what the rogue anti-malware (or anti-virus for that matter) is and what it's capable of. The example of rogue anti-malware used in the video is called XP Anti Spyware. The attempt to get rid of the rogue software is made by the help of Malwarebytes Anti-Malware which, on this occasion, proves to be unsuccessful:Here are some names of rogue security software: Antivirus PC 2009, PCSuperCharger, DrAntispy, AntiMalware Pro, AntiSpywareMaster. (Extensive list of names can be seen here.) Some common patterns can be singled out:
- there is no name of the developer / publisher mentioned;
- the software name includes 'super', 'pro', 'master' and probably other hyperbolic terms.
Method of removal
Rogue software should be treated as malware therefore its removal is carried out by using anti-malware software provided by genuine and established publisher. For suggested free malware and rogue software removal tools click here. I'd suggest to follow the computer cleaning method outlined by me here. All the more because the method suggested can be used without the computer being connected to the Internet.If you want to report a website hosting malware/scareware/spyware
Help to make the Internet a better place and report malicious URLs by going to Badwarebusters.org. Thank you.The dark side of cyber business
More information on what part of the Internet the rogue anti-virus software (scareware) belongs to, you can find in the extensive summary by Dmitry Samosseiko, a data security researcher at data protection company SophosLabs Canada. The aforementioned research deals with the dark side of the Internet:- spam and other online promotional tactics that are more or less of criminal nature;
- adult and casino sites of obscure origin;
- scareware;
- fake pharmacy products;
- Black Hat SEO.
The author of this blog strongly recommends against both: abuse of information and participation in criminal activities.
Download and test these products for free for 30 days:
|
|
Labels:
antimalware,
antivirus,
cleaning,
computer,
data security research,
fake pharmacy products,
fake software,
freeware,
infection,
internet fraud,
MalwareBytes,
online marketing,
scan,
scareware,
seo,
spam,
spyware
Monday, 13 February 2012
What is an online scam?
Before we proceed to recognizing the common phishing and scam patterns, let me tell you
Where to report phishing emails and websites?
Go to antiphishing.org website by clicking here, and follow instructions.
How to spot scam and phishing attempts?
In the picture above is a very simple example of what to look out for when you receive an email from a hot blonde with naughty videos online:
1. Spelling. I mean, waht series individuall or organizattion or website would send an email like that?
2. Do you know who is Micah Rafe and a website named cucougars.com?
3. What kind of a link is that anyway?
Speaking of links. Before clicking on any of them, at least hover your mouse cursor over each of them as to see where the link is supposed to take you. The address can usually be seen at the bottom left of the browser screen (and even then it might redirect the browser to another destination). The linked text can say Click Here, or it can look similar to one in the picture above, but in reality, can take you to a malicious website that is set up with an intent to collect personal or financial data (pharming), or to infect your machine with malware.
Even if the link looks legitimate at first sight (starting with www.paypal.com, for example), double-check that you read the link right (in other words, it's not www.paypalcom.com). Here's an excerpt from an article at scamdex.com website regarding links and DNS system:
Very simple and useful tips regarding to spotting the scam and phishing messages are provided in the following video (authors come up with an interesting fact that mobile users are receiving 3 times more scam messages than those using computers):
- Just because the domain name of a website mentions kitties and fluffy bunnies, it doesn't mean that it's not a porn site.
- A mis-spelled bank domain name is probably a spoof website, trying to get you to enter your bank access details for a scammer.
- The DNS system makes no decisions of any kind about the content of or suitability of or legality of websites - it is just a tool.
- When your kids use google or any other search engine to search for stuff, the results returned may expose them to violent and/or sexual images which would horrify you.
While we are at the subject of scamming, ladies, check out the Valentine's Day article on online dating scams by Ann Brenoff at Huffingtonpost.com website.
An extensive list and information on known scam patterns can be found at Consumer Fraud Reporting website.
An extensive list and information on known scam patterns can be found at Consumer Fraud Reporting website.
Phishing and Identity theft
The essence of an Identity theft attempt looks like following:
Dear Sir,
I have 2 million dollars. I will give you 1,525 million dollars because I trust you. Please provide
Your Name:
Your Data of birth:
Your address:
In reality you would probably get more elaborate email message like this:
As you can tell straight away, should you decide to reply to the sender of the message, eventually you would be asked for your personal and financial details because, how would you otherwise be able to "help to relocate" the sender's "funds"..? My advice: don't reply to the message, blacklist the email address the message was sent from, and delete it.In reality you would probably get more elaborate email message like this:
For your confidence,
Please consider to help me relocate this $2.5mUSD for establishing an industry in your country.
This fund was deposited in our bank by Mrs. Nina Wang from Hong Kong who died of cancer on April 3rd 2007 without a heir.
A routine notification was sent to her forwarding E-mail address but without responses.
She did not declare her next of kin in the bank
official papers including her real home contacts.
This money has been floating and if I do not remit it out urgently it will be confiscated by the government as unclaimed fund.
You will be compensated with 40% for your collaboration to receive this fund.
Click here [link withdrawn]
I will give you all vital information and clarification so that you will contact my bank for the release of the money into your account as next of kin to the deceased depositor.
As one of the bank directors, I will play a role to make sure that the fund will be released to you.
Mr.Abdul .F. Umar
In order to be aware of the seriousness of keeping your personal data safe, a list of methods (from Wikipedia) of obtaining data on other people will (hopefully) give you the idea of how much effort some people are ready to invest in obtaining data on other people:
- Rummaging through rubbish for personal information (dumpster diving)
- Retrieving personal data from redundant IT equipment and storage media including PCs, servers, PDAs, mobile phones, USB memory sticks and hard drives that have been disposed of carelessly at public dump sites, given away or sold on without having been properly sanitized
- Using public records about individual citizens, published in official registers such as electoral rolls
- Stealing bank or credit cards, identification cards, passports, authentication tokens ... typically by pickpocketing, housebreaking or mail theft
- Skimming information from bank or credit cards using compromised or hand-held card readers, and creating clone cards
- Using 'contactless' credit card readers to acquire data wirelessly from RFID-enabled passports
- Observing users typing their login credentials, credit/calling card numbers etc. into IT equipment located in public places (shoulder surfing)
- Stealing personal information from computers using malware, particularly Trojan horse keystroke logging programs or other forms of spyware
- Hacking computer networks, systems and databases to obtain personal data, often in large quantities
- Exploiting breaches that result in the publication or more limited disclosure of personal information such as names, addresses, Social Security number or credit card numbers
- Advertising bogus job offers in order to accumulate resumes and applications typically disclosing applicants' names, home and email addresses, telephone numbers and sometimes their banking details
- Exploiting insider access and abusing the rights of privileged IT users to access personal data on their employers' systems
- Infiltrating organizations that store and process large amounts or particularly valuable personal information
- Impersonating trusted organizations in emails, SMS text messages, phone calls or other forms of communication in order to dupe victims into disclosing their personal information or login credentials, typically on a fake corporate website or data collection form (phishing)
- Brute-force attacking weak passwords and using inspired guesswork to compromise weak password reset questions
- Obtaining castings of fingers for falsifying fingerprint identification.
- Browsing social networking websites for personal details published by users, often using this information to appear more credible in subsequent social engineering activities
- Diverting victims' email or post in order to obtain personal information and credentials such as credit cards, billing and bank/credit card statements, or to delay the discovery of new accounts and credit agreements opened by the identity thieves in the victims' names
- Using false pretenses to trick individuals, customer service representatives and help desk workers into disclosing personal information and login details or changing user passwords/access rights (pretexting)
- Stealing cheques (checks) to acquire banking information, including account numbers and bank routing numbers
- Guessing Social Security numbers by using information found on Internet social networks such as Facebook and MySpace
- Low security/privacy protection on photos that are easily clickable and downloaded on social networking sites.
- Befriending strangers on social networks and taking advantage of their trust until private information are given.
If you think that someone would write you an email wanting to pay you million dollars from the bank in Hong Kong or Africa, or that they are eagerly willing to pay you a jackpot that you have supposedly won in a lottery you have never taken a part in, better delete the email message and watch how some people have managed to scam the scammers (note: don't try this at home, might get you in trouble):
Download and test these products for free for 30 days:
|
|
Friday, 10 February 2012
How a banking trojan can steal your data and money
A quick look at Zbot
There are many ways hackers can try to steal personal data from computers. We will take a look at what is known as Zeus to give you the idea of how your banking information can be stolen, so that you know what to be aware of, and how to avoid of becoming a victim.There is an in-depth analysis of ZeuS Banking trojan to be found at SecureWorks website by authors Kevin Stevens and Don Jackson, Security Researchers from SecureWorks Counter Threat Unit SM (CTU). While it is suggested that you read the whole article, I will post some excerpts here:
ZeuS is a well-known banking Trojan horse program, also known as crimeware. This trojan steals data from infected computers via web browsers and protected storage. Once infected, the computer sends the stolen data to a bot command and control (C&C) server, where the data is stored. ZeuS has evolved over time and includes a full arsenal of information stealing capabilities:
- Steals data submitted in HTTP forms
- Steals account credentials stored in the Windows Protected Storage
- Steals client-side X.509 public key infrastructure (PKI) certificates
- Steals FTP and POP account credentials
- Steals/deletes HTTP and Flash cookies
- Modifies the HTML pages of target websites for information stealing purposes
- Redirects victims from target web pages to attacker controlled ones
- Takes screenshots and scrapes HTML from target sites
- Searches for and uploads files from the infected computer
- Modifies the local hosts file (%systemroot%\system32\drivers\etc\hosts)
- Downloads and executes arbitrary programs
- Deletes crucial registry keys, rendering the computer unable to boot into Windows
How to detect the ZeuS Banking Trojan on your computer
Computers infected with this version of ZeuS will have the following files and folders installed. The location depends on whether the victim has Administrator rights. The files will most likely have the HIDDEN attribute set to hide them from casual inspection.
With Administrator rights:
%systemroot%\system32\sdra64.exe (malware)%systemroot%\system32\lowsec%systemroot%\system32\lowsec\user.ds (encrypted stolen data file) %systemroot%\system32\lowsec\user.ds.lll (temporary file for stolen data) %systemroot%\system32\lowsec\local.ds (encrypted configuration file)
Without Administrator rights:
%appdata%\sdra64.exe%appdata%\lowsec%appdata%\lowsec\user.ds%appdata%\lowsec\user.ds.lll%appdata%\lowsec\local.ds
ZeuS also makes registry changes to ensure that it starts up with Administrator privileges:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinlogonFrom:"Userinit" = "C:\WINDOWS\system32\userinit.exe"To:"Userinit" = "C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe"
Without Administrator rights:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunAdd:"Userinit" = "C:\Documents and Settings\<user>\Application Data\sdra64.exe"
The sdra64.exe program uses process injection to hide its presence in the list of running processes. Upon startup, it will inject code into winlogon.exe (if Administrator rights available) or explorer.exe (for non-Administrators) and exit. The injected code infects other processes to perform its data theft capabilities.
How your system can get infected
There is a list of ways your system can get infected to be found in one of my other posts here. Things you really should watch out for, and avoid, are emails supposedly sent from your bank where you are asked to follow a certain link in order to update your security details, or to download a file attached to the e-mail message. Here are few samples of such e-mail messages:
Dear Customer,We detected irregular activity on your
Internet banking account.
For your protection, you must verify this
activity before you can continue using your
account.
Please download the document attached to this
email to review your account activity.
We will review the activity on your account
with you and upon verification, we will remove any restrictions placed on
your account.
If you choose to ignore our request, you leave us no choice
but to temporary suspend your account.
We ask that you allow at least 72 hours for the case to be
investigated and we strongly recommend to verify your
account in that time.
© Copyright Barclays Bank Holdings plc 2012 - All rights reserved
and
Dear Valued Customer,
Your account is suspended due to the number of incorrect login attempts.
For your protection, we've suspended your account .
To reactivate your account please download the document attached to this
e-mail and review your account activity.
If not completed until February 09, we will be forced to close your account .
Note: If you received these e-mail in your BULK/SPAM section please
add to your address book [e-mail address withdrawn]
Thank you,
Customer Support Service.
Copyright © NatWest Bank Plc. Limited. All rights reserved.
On both occasions senders obviously have made an opportunistic attempt to get me into downloading their malicious HTML files attached to messages without knowing that I'm not a customer of either of aforementioned banks.
So, what would have happened if I'd downloaded the attached file? I would most likely have infected my machine with a trojan bot spyware that would be capable of sending data from my computer to a remote server on the Internet, controlled by a cyber criminal, and basically making my machine a part of a botnet.
Or, if there would have been a link to follow, then, by clicking it, I would most likely have ended up on some bogus website designed by a cyber criminal for malicious purposes such as pharming (URL redirections with purpose of information stealing) or spreading malware infections. Example of a phishing message:
Dear Valued Customer,
our security filter noticed a malicious activity in your online account.
We were able to trace it to an unknown link thereby, placing
your online banking on suspension till this is resolved.
We implore you to go over your account details so
as to continue with your online transactions.
Click here to resolve the problem. [Link withdrawn]
Thank you for helping us to render you a maximum protection.
Security Department.
Alliance-leicester online banking.
So, what would have happened if I'd downloaded the attached file? I would most likely have infected my machine with a trojan bot spyware that would be capable of sending data from my computer to a remote server on the Internet, controlled by a cyber criminal, and basically making my machine a part of a botnet.
Or, if there would have been a link to follow, then, by clicking it, I would most likely have ended up on some bogus website designed by a cyber criminal for malicious purposes such as pharming (URL redirections with purpose of information stealing) or spreading malware infections. Example of a phishing message:
Dear Valued Customer,
our security filter noticed a malicious activity in your online account.
We were able to trace it to an unknown link thereby, placing
your online banking on suspension till this is resolved.
We implore you to go over your account details so
as to continue with your online transactions.
Click here to resolve the problem. [Link withdrawn]
Thank you for helping us to render you a maximum protection.
Security Department.
Alliance-leicester online banking.
Things to keep in mind
Regardless of the content of the message, remember: banks will not ask you for any security details or security updates via e-mail. Don't just click on links in emails you receive from someone. Make sure the sender is trusted and genuine, and the link does not look dodgy. (The same applies to Instant Messenger chats.) If you receive a suspicious email supposedly sent from your bank, and you are asked to proceed with giving away any of your personal or financial details, or to download an attachment, don't. Instead, forward the email message to the bank. Almost on all occasions you can find e-mail address for forwarding phishing emails to at the bank's official website. For more detailed information on types of scams related to Online banking, and to get a genuine advice, please visit Bank Safe Online, a website developed by UK Payments Administration Ltd.
|
|
Labels:
botnet,
browser,
computer,
data security research,
email scam,
HTML hijacking,
infection,
internet fraud,
malware,
Online banking,
pc,
phishing,
spam,
spoofing,
stealing,
torrent,
trojan,
Zeus
Subscribe to:
Posts (Atom)
