Showing posts with label Phishing Scams. Show all posts
Showing posts with label Phishing Scams. Show all posts

Wednesday, April 27, 2016

Disneyland 4 Free Tickets: Facebook Scam

Scam Score: 100 (Severe Risk)

Background
Recently I found this being shared on Facebook. It appeared quickly as an obvious scam but I followed the link to see more evidence of the scam.

You can see quickly that the coupon was composited in a hurry and without much thought to design. The most important parts to Disney is going to be their logo, which is obviously skewed in this picture. This picture also happens to be click-bait as it does not appear on the landing page.

http://www.disneyland.com-present.com


The landing page greeting the clicker displays all the common elements of a scam. A poorly designed web site, which Disney would never put their name on. A tickets remaining countdown (which randomly resets to one of several different numbers on refresh) to encourage quick action by the user, but is nothing more than some JavaScript.

While the site appears to be on behalf of Disney, there is no listed responsible party of who would handle the prizes.

The button for redeeming your exclusive gift card is set to alert that you have not completed step 2.

Looking at the source of the page is appears that the developers were German.

The URL (http://www.disneyland.com-present.com) is meant to be deceiving as well. The root of the domain is actually com-present.com which is obviously not owned by Disney and has private registration.




Monday, November 24, 2014

Email: Center Security (noreply@facebookalert.com) Scam


Scam Score: 85 (Severe Risk)

Background: While reviewing emails in my inbox, I came across an email that was intended to look like Facebook warning me that a charge had been made on my account for 22.34 USD.

The link provided for me to login to "Facebook" actually resolves to http://74.7.88.163/aboutes.php which is obviously not Facebook. This server also appears to be hosting the websites: websiteincomesuccess.com, www.leidschdagblad.nl, and www.tweetprocesor.com which are obviously not owned by Facebook and seem sketchy themselves.

This email fails our tests by first, not identifying me personally. If anyone knows my name, it is Facebook (or at least the name I provide them). Second, the grammar and punctuation in the email are not professional. Third, the email is supposed to be from Facebook but the message ends with a reference to PayPal Security. PayPal and Facebook are not the same company. Purchases notifications from PayPal will never be from a Facebook email.







Thursday, November 7, 2013

Circumnews.com Scam (sontores.com or inqueritopro.com)

Overview
Today I learned of a web site called circumnews.com (server [46.28.65.179] also hosts sontores.com or inqueritopro.com which appear to be Russian and Portuguese versions of the same kind of thing). This site claims to pay you between $2 - $5 USD per article you read. There is no verification system to ensure users read the articles other than a (weak) bot protection system. They say that you must reach a minimum of $100 in order to get paid out and they will pay to a PayPal or Payza account. They claim that the site owners pay them and then they pay you 70% of what they make. Once you request your money, payments are supposed to be paid within 14 days. This has not been verified to actually happen.

A Potential Threat!
Personally, I have serious doubts about this kind of web site. Well it does not appear to be asking for more than your name (first and last), email, and your PayPal account, I speculate this is a system that provides them with a list of real PayPal (ecommerce)  accounts, emails, and possible passwords for those accounts if you use the same password for those accounts as you signed up with. In addition, providing your PayPal or Payza account information could put you at risk.

In addition, they also track referrals. This could provide them with a way to spam your email account as pretending to be someone you know since they know names and who referred who. They can also send you phishing emails pretending to be PayPal or Payza trying to get you to reveal additional important account information.

They also track IP addresses which can reveal more about you and the services you use (your general location, your Internet Service Provider).

Reasons for my distrust:
Don't provide company contact information
Servers hosted in Germany (or Ukraine)
Do not account for US tax requirements and regulations
Poor grammar used through out the site
Russian language used on the site
Fishy revenue model
The thought that Russians are going to pay you money to read English articles

Saturday, July 27, 2013

Tariff DNS Scam Email - DreamHost Phishing Scam

Recently, I received an email that was supposed to have come from my hosting company. It said I needed to confirm a request for changing of a tariff plan. Although, the wording was awful and it was very non-specific as to the recipient. The email I got was as follows:

Dear DreamHost client,

In your account has been created request for changing of a tariff plan. 
It is necessary confirmation of this request. 
You can do it in the section (Change tariff) Virtual Offices :

https://dreamhost.com/login.aspx?ts=domain.org?
19abc7f04ff-c0ac4315-99bf3-55dcbd7ec5c44AECA3E759B1992CFA6Ad4

Sincerely,

DreamHost hosting Team.


Someone who is rushing may not read the contents of this email and just click link. This clever scammer set up a catch-all subdomain so that the link would even appear to be directing to dreamhost. The link would take you here:

http://panel.dreamhost.com.login.2qjesez0l6dlilz4tuz67gzzz1bkwp4lyg3apxo1jrzimfx27l9wbbgbuaf72m.vqp9gqp87c8za6gayfc0fvryrbzkczg4r4u5f95me64v9q1ddk99x4qcoo85e.eyt0b3of65cvtd5c6shn2baq8xslyuj4yckz72tgwok4n5npixapz02xr3viztc.kidea.com/login.php?domain=domain.org

At first glance, this appears to go to http://panel.dreamhost.com, but notice that it is really all part of a complex sub-domain meant to confuse the recipient. The root domain is actually: kidea.com

Looking at the whois record for this domain we can find out the following information.

This domain is hosted by tucows.com and resolves with domain servers to bluehost.com by a company with the following registration record:

XOL Holding
Beirut
Beirut, Beirut xxxxx
LB

The technical contact information for this domain is:
Nassar Center
5th Floor
Charles El-Helou Avenue, Rmeil
Beirut,  20727508
LB

This happens to be the ISP end point, a company in Lebanon called Terra Net. This company has chosen to not disclose more information about the scammers.

So looking at the main website for kidea.com, we find out some interesting information. One, that they used a company called art-promotion to build and design their site. This company happens to also be in Lebanon, so I looked up their whois and found that they were also hosted on bluehost.com and contact information.

Saab, Jean web@artpromotion-lb.com
Art Promotion
Nahr el Mot
Beirut, -
Lebanon
+961.3737247

So I went to look closer at kidea.com and found that this might be a cover site (or some poor site that got hacked). The poor design and lack of ecommerce functionality is what seem to indicate that there was more than what meets the eye.You can't checkout with any of the items they sell. It's difficult to think that isn't part of the scam.

Regardless of who this phishing scam came from, be sure to take the time to read your emails before you go clicking links and signing in.




Friday, August 7, 2009

Gone Phishing (How to catch a phishing scam)

No, I didn't misspell the word fishing. Phishing is a terms defined by Wikipedia as:
In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.
Electronic communication most commonly referred to as email. Phishers will generally pose as an important institution of some sort. For example, banks and credit unions, online merchant (PayPal), federal resources, etc. In my own experience I have received emails from banks I didn't even have accounts with.

So how you identify if a predator is phishing for your information? Here are some signs you can look for.
  1. Your information is at risk! - If an email is telling you you need to log in and verify your information because someone else has posed as you is a good sign. Especially when they provide you with a link where you can go to log in. All important institutions your a client of has several ways of getting a hold of you and in return being able to identify themselves. If something as important as someone threatening to steal your identity is really at risk, the institution will likely call you and explain the situation and your options. They will never send something as casual as an email. If you are still unsure, take the extra effort to pick up the phone and look up the number (not given in the email) and call them. Someone on the other end of that phone is going to be able to assist you or direct your call.
  2. Click here to update your account information. - As a general rule, never click links in an email your unsure about. If you need to update personal information, etc. You should open a new browser window and manually enter the correct URL in the URL address bar. This ensures that you will be where you should be and that you can securely log in and handle any disputes as well as update your information. Many times the links provided in emails will look like this www.bankname.com, but is a hyperlink. This means that even though it says your banks name on the link, that isn't necessarily where it will take you. If you mouse over the link, you might even be able to see where the link would otherwise take you. More often then not, these links reference a page that looks like your bank's (or other business's) website. The links on this page will refer you back to the actual bank's website, so they look legit but in your URL bar, you will notice it is not the right URL for your bank. The URL will be pointing to a server in some other country and therefore will probably be composed of random words, letters, and numbers.
These are two big ways to determine a phishing scam and to be able to avoid it. More signs will come soon. If you have any other suggestions, please post them in comments below, thanks.

 
Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | Bluehost Review