Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Friday, June 20, 2025

Steam Phishing: popular as ever

A month or so ago a friend of mine received the following message on Steam from someone in their Friends list (they were already friends):

Figure 1 - 'this is for you'           


 

 

 

 

 

The two links are different and refer to a Gift Card on Steam's community platform. As you might have noticed, the domain is not related to Steam at all, but rather is an attempt at phishing.

 The URLs are:

stermcormmunity[.]com/gift-card/
steamcoummuniity[.]com/gift-card/

The differences are subtle enough that you may just miss it. When you click on the link, you are redirected to a 'Summer Gift Marathon'.

Figure 2 - Fake Steam website


Once you log in to the fake Steam website, your credentials are stolen and will be used to spread more phishing, likely steal your inventory items and so on.

Other phishing sites related to this campaign are:

steam-pubgvn[.]top
steamauthconnection[.]store
steamcommnunity[.]com
steamcommunitay[.]com
steamcommunitfy[.]com
steamcommunitihy[.]icu
steamcommunitiny[.]com
steamcommunitweya[.]art
steamcommunl1ty[.]com
steamcommunllity[.]com
steamcommunty[.]ru
steamcommununity[.]cam
steamcommunutiy[.]com
steamcomnunityty[.]com
steamcomnunlity[.]com
steamcomnuty[.]com
steamcomrnnunlty[.]com
steamcomun1ty[.]com
steamcomuniry[.]com
steamconmunify[.]com
steamconnection[.]store
steamcornmunlty[.]ru
steamcornrnunlty[.]ru
steamlinks-short[.]com
stearncommunjty[.]com
stearncommunnity[.]com
stearncomnunity[.]com
stearncornnunity[.]com
steeamcommunitty[.]com
unevwsteeamcommunitty[.]com 

New ones do pop up from time to time, so stay vigilant. 

Tips  

Only log in on the legitimate Steam community website, this being https://steamcommunity.com/. An extra tip is to bookmark the legitimate site, so even if you do get a message like this, you can go straight to your bookmark and search what you need from there.
 
If someone new tries to add you as a Friend and immediately sends a message like the above, alarm bells should start ringing.
 
If someone already on your Friends list suddenly sends a random message with an even more random link out of the blue, cue the alarm bells again. 
 
If you want to check the website out in a safe manner, then you can use URLscan.io, which will give you a verdict of the website as well as an image preview. In addition, you can use VirusTotal to review a website's reputation.
 
Note that an 'all clean' does not necessarily mean it is. Caution above all! 
 
Follow Steam's Account Security Recommendations to stay safe.

 

 

Monday, March 4, 2019

Analysing a massive Office 365 phishing campaign


Last week, a friend of mine reached out with a query: a contact in his address book had sent him a suspicious email. As it turns out, it was. In this blog post, we'll have a quick look at an Office 365 phishing campaign, which turned out to be massive. This type of phishing has been on the rise for a while now (at least since 2017), and it's important to point out, as seemingly attacks are only increasing.


Analysis

As mentioned earlier, Office 365 (O365) phishing isn't new, but it is definitely prevalent. A high-level overview of a typical attack is as follows:

Figure 1 - High-level overview of typical O365 phishing
















A typical flow of such an attack may be as follows:


  1. An attacker sends an O365 spearphishing email, likely from a spoofed or fake email address;
  2. The user is enticed to click on the link, or open the attachment which includes a link;
  3. The user will then unknowingly enter their credentials on the fake O365 page;
  4. Credentials get sent back to the attacker;
  5. Attacker will access the now compromised user's mailbox; and,
  6. The cycle repeats: the attacker will send spearphish emails to all of the compromised user's contacts - with this difference, it's coming from a legitimate sender.
This is exactly what happened to a friend of mine: he got sent an email from a legitimate email address, which was a contact in his address book - only the sender never intentionally sent this email! 

Let's have a look at the infection chain.

The initial email

The initial email sent looked as follows:

Figure 2 - "P.AYMENT COPY"












Clicking on the "OPEN" button would redirect you to a legitimate but compromised Sharepoint (part of O365) webpage. Seeing as a legitimate business has been compromised, I won't post the link here. Its web administrators have been notified.


Figure 3 - "Access OneDrive"













The PDF document

Next step is hosting a PDF named "INVOICE.PDF", which entices the user to access OneDrive to view the shared file. If the user were to click on "OPEN PDF HERE":


Figure 4 - "Login with Office 365"















URI: https://happymachineit[.]info/Michael/b4fb042ba2b3b35053943467ac22a370/OFE1.htm

The final landing or phishing page


Finally, clicking on "Login with Office 365" will redirect the user to the final phishing page, which will look as follows:

Figure 5 - Final landing page
















The final landing page is as follows:
https://happymachineit[.]info/Michael/b4fb042ba2b3b35053943467ac22a370/7hsfabvj2b0b9rguzbzw910d.php

When entering credentials, they will be sent off to the attacker, and the cycle from Figure 1 will repeat itself. Note that other scenarios are possible, for example:
  1. The attacker may try to (re-)sell credentials that have been gathered so far on criminal forums
  2. The attacker may send more targeted spearphishes to potentially interesting victims
  3. The attacker may attempt to access other services or accounts using the same user/password combination
In short, there's countless other possibilities.

The phishing infrastructure

Avid readers will have noticed the phishing website uses a valid SSL certificate, which has the following details:


  • Subject DN: CN=happymachineit.info
  • Issuer DN: C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority
  • Serial: 169382499542171049850152621295591104087
The SSL cert was issued by Comodo in January. Details can be found on Censys.io.

An additional email address is connected with "happymachine": fudtoolshop@gmail.com

The phishing website encountered here, https://happymachineit[.]info, is hosted on the following IP: 178.159.36[.]107

Pivoting on that IP brings us to the following SSL certificate details:

emailAddress=ssl@server.localhost.com, CN=server.localhost.com

This means the certificate is a local and self-signed one. In other words, if you are accessing a secure website, and you see "server.localhost.com" as the SSL certificate, do NOT trust it. This is sometimes from an automatic setup from the hosting provider.

As a side-note, a search for the Common Name (CN) mentioned above with Censys currently yields 473 (unexpired certs) results: https://censys.io/certificates?q=%28server.localhost.com%29+AND+tags.raw%3A+%22unexpired%22&

Performing a search with RiskIQ's PassiveTotal as well as VirusTotal, and after filtering results, we obtain a whopping total of 875 unique Office 365 phishing sites, hosted on that IP alone! It appears this campaign has been active since December 2018.

Searching a bit further, it appears the whole ASN (which is a collection of IP prefixes controlled by a single entity, typically an ISP), AS48666 is in fact riddled with Office 365 as well as other phishing sites. Using URLscan.io we can quickly gauge the ASN is hosting multiple phishing sites for Office 365 as well as Adobe:

Figure 6 - AS48666 hosting badness










General Info:

  • Geo: Russian Federation (RU) — 
  • AS: AS48666 - AS-MAROSNET Moscow, Russia, RU 
  • Registrar: RIPENCC

As shown in this blog post, one IP address can host tons of phishing instances, while the ASN controls multiple IPs. Bonus bad IP: 178.159.36[.]120. 


Detection

For the phishing websites itself, any network traffic that resolves to the IP above.

I've noticed there are countless similar PDFs from this same campaign. Due to the way these are created (likely in bulk), a simple Yara rule can be developed as follows:











The Yara rule can be found on Pastebin here or on Github Gist here.

Note: in specific instances, this rule may false-positive - so use at your own will.

The following MITRE ATT&CK techniques are relevant:



Disinfection

There isn't much to disinfect, since there's no actual malware involved.

However, if you have been affected by this phishing campaign, do the following immediately:

  • Contact your network and/or system administrator or managed services provider if you have one and wait for their response - if not;
  • Note down the phishing page/URL, then close any open phishing pages - in fact, close the whole browser;
  • Perform an antivirus scan with your installed product, and a scan with another application, for example Malwarebytes (better be safe than sorry);
  • Change your O365 password immediately;
  • Change passwords on other websites where you used the same combination;
  • Reach out to the people in your address book you were compromised and they are not to open your email(s) or at least not any attachments or links from your email(s);
  • Verify your "Sent" emails folder (or "Outbox") for any suspicious activity. If there are no Sent emails - the attacker may have deleted them, or you may have a full compromise on your hands.;
  • Verify any (newly) created rules in your mail application (in this case O365), for example, verify there are no new forwarding rules or perhaps rules that delete new incoming emails - forwarding rules and deletion rules are sometimes set up by an attacker to gather more information or as an attempt to remain hidden; and,
  • File a complaint with your CERT, local police station, or whichever authority would handle such cases. If you are unsure how to do so, have a look here for assistance.


Prevention

  • Block the IP (or whole subnet 178.159.36[.]0/24) mentioned in this report in your firewall or proxy or other appliance;
  • Use strong and preferably unique passwords (use a password manager);
  • Set up 2FA for accounts or, preferably, MFA (multi-factor authentication);
  • Enable, deploy or implement anti-spam and anti-phishing protection;
  • Enable, deploy, or implement a URL phishing filter;
  • Trust, but verify: "did this contact really need to send me a "Payment Copy"? - if needed, verify via a phone call - not via email;
  • Be generally cautious with links and attachments. Do not click on links or open attachments from unknown senders;
  • If possible, use Firefox with NoScript enabled; and,
  • If you're in an organisation: create or organise user awareness training.

Conclusion

Phishing has been around for a long time - Office 365 phishing, on the other hand, has been around since, well, Office 365 was created. Every time a new service is created, you can imagine that phishing emails targeting that service will follow - maybe one month later, perhaps a year later - but they will.

Always try to be vigilant and follow the prevention tips mentioned above to stay safe.

As a side-note, the real Office 365 page is: https://outlook.office365.com/owa

You may find more information in the Resources section below.

Resources

Blaze's Security Blog - Cybercrime Report Template
Decent Security - Easily Report Phishing and Malware
Microsoft - Anti-phishing protection in Office 365
Microsoft - Microsoft publishes guidance to boost public sector cloud security
Microsoft - Set up multi-factor authentication
Microsoft - Set up Office 365 ATP anti-phishing and anti-phishing policies

Indicators


Sunday, November 16, 2014

Malware spreading via Steam chat

If you're only interested in how to remove this malware from your machine or other tips and prevention advise, click here. In case you have questions, issues or doubts, feel free to leave a comment and I'll be happy to help or answer any questions you may have. (you may have to click 'Load more...' or 'Loading...' to view all comments)


Today I was brought to the attention of a Tumblr post - apparently there's malware doing the rounds making use of Steam chat, (adding Steam friends and) spamming Steam users.

Example message:
"karpathos" sending a bit.ly link (Image source)






















Onyx is right, the link's indeed phishy and uses bit.ly (a URL shortener) to trick users into clicking it. Remember the worm that spread via Skype and Messenger last year? (reference here and here) This is a similar campaign.



Setup

Someone adds you on Steam, you accept and immediately a chat pops up as similar to above.

Alternatively someone from your friends list already got infected and is now sending the same message to all his/her friends.

The bit.ly link actually refers to a page on Google Drive, which immediately downloads a file called IMG_211102014_17274511.scr, which is in fact a Screensaver file - an executable.
The file is shared by someone named "qwrth gqhe". Looks legit.

Note that normally, the Google Drive Viewer application will be shown and this will allow you to download the .scr file. In this case, the string "&confirm=no_antivirus" is added to the link, which means the file will pop-up immediately asking what to do: Run or Save.
(and in some cases download automatically)

At time of writing, the file is actually still being hosted by Google Drive. I have reported it however.

Afterwards, you're presented with the screensaver file which has the following icon:
Image of IMG_211102014_17274511.scr file














Opening the file will result in installing malware on your system, which will steal your Steam credentials.



Technical details

IMG_211102014_17274511.scr

Original Filename: wrrrrrrrrrrrr.exe

Type: PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly
SHA1: 7d0575a883fed7a460b49821c7d81897ae515d43
VirusTotal: link


Connects to:
185.36.100.181


Server in Czech Republic. VirusTotal reference










Downloads and executes:
temp.exe

Type: PE32 executable for MS Windows (GUI) Intel 80386 32-bit Mono/.Net assembly

SHA1: cd9b3bf5c8d70e833b5c580c9b2fc1f3e5e4341e
VirusTotal: link




Interesting information in the debug path, note the "steamstealer" string.











Remediation

What if you clicked the link and executed the file? Follow these steps:


  • Exit Steam immediately
  • Open up Task Manager (CTRL + SHIFT + ESC) and find a process called temp.exewrrrrrrrrrrrr.exevv.exe or a process with a random name, for example 340943.exe or a process similar to the file you executed
  • Launch a scan with your installed antivirus
  • Launch a scan with another, online antivirus or install & scan with Malwarebytes
  • When the malware has been disinfected or deleted, change your Steam password - if you use the same password for other sites, change those as well
  • De-authorize any unknown machines, read how to do that here:
    Family Library Sharing User Guide
  • Verify none of your Steam items are missing - if so, it is advised to reinstall Steam as well.
    Note: move the Steamapps folder (default on C:\Program Files\Steam\Steamapps) outside of the Steam directory to prevent your games from being deleted
  • Contact Steam/Valve in order to get your items back:
    Send a ticket to Steam support




Prevention
  • Be wary when someone new or with Level 0 adds you on Steam and immediately starts sending links
  • In fact, don't click on links someone unknown sends to you
  • If you receive a link which is a URL shortener (bit.ly or goo.gl for example), you can use GetLinkInfo to see the real URL
  • If you did click the link, don't open or execute anything else - just close the webpage (if any) or cancel the download
  • By default, file extensions are not shown. Enable 'Show file extensions' to see the real file type. Read how to do that here
  • Install WOT - WOT is a community-based tool and is therefore very useful for those fake screenshot websites, whereas other users can warn you about the validity.
  • Follow the tips by Steam itself to further protect your account:
    Account Security Recommendations
  • If you trade a lot or want to check if a Steam account has a bad reputation, you can use SteamRep:
    https://steamrep.com/
  • SteamRep has also set up a Safe Trading Practices guide.
  • Consider setting up the Steam Guard Mobile Authenticator (2FA).
  • There's a useful guide in preventing scams on this Reddit link as well.
  • Install an antivirus (which one doesn't matter, as long as you have one) and keep it up-to-date and running.
  • Enable the Windows Firewall, or use the one that comes with the antivirus software, if relevant.
  • For sysadmins/network administrators, I have created an IOC on AlienVault OTX with all known (to me at least) SteamStealer IPs.




    Conclusion 


    Never click on unknown links, especially when a URL shortener service like bit.ly is used. (others are for example t.co, goog.gl, tinyurl, etc.)
    Don't be fooled by known icons or "legit" file descriptions, this can easily be altered.

    Even if you clicked the link and you're not suspicious, you should be when a file is downloaded and it's (in this case) a screensaver file.

    For checking what is really behind a short URL, you can use:

    For checking whether a file is malicious or not:

    Follow the prevention tips above to stay safe and protect yourself from the SteamStealer malware.


    Wednesday, November 14, 2012

    Diablo account phishing


    Do you love the smell of phishing in the morning? I surely don't. In today's post we will be reviewing a phishing attempt for Diablo or Diablo III.

    The following mail ended up in my mailbox:

    You need to login as soon as possible to avoid account closing

    There are other, less fancy examples:

    Same trick as in the previous example. You need to "verify" your account


    Subjects of the mail can vary, but these are the most common:
    - Blizzard Notification About Diablo III Account
    - Diablo III Account-Notice
    - Diablo III Account - login validation‏
    - You must verify your identity as the registered account .World of  Warcraft - Diablo III account (s).

    The introduction in the email reads:

    Greetings!   It has come to our attention that you are trying to sell your personal Diablo III account(s). As you may not be aware of, this conflicts with the EULA and Terms of Agreement. If this proves to be true, your account can and will be disabled.  It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership.


    Let's move on to the actual link in the phishing mail. When clicked you'll land on the following page:

    An exact copy of the real login page at Battle.net















    Below you can find the list of URLs I've gathered in the past days, do not visit any of them as they may harm your computer (or even worse, your Diablo account ;-) ).

    hxxp://battle.net.noreply-login.com
    hxxp://cn15mcc.com
    hxxp://eu.diablo.net.account.oy-login.in
    hxxp://eu.diablo.net.account.ts-login.in
    hxxp://eu.diablo.net.ca.zx-login.in
    hxxp://eu.diablo.net.jiagedi.info
    hxxp://eu.diablo.net.tianzhou58.info
    hxxp://us.battle.com.wwowus.com
    hxxp://us.battle.net.aacc.cn.com
    hxxp://us.battle.net.cacc.cn.com
    hxxp://us.battle.net.ccus.asia
    hxxp://us.battle.net.ddeu.asia
    hxxp://us.battle.net.eacc.cn.com
    hxxp://us.battle.net.en.oo-rs.com
    hxxp://us.battle.net.en.qq-rs.com
    hxxp://us.battle.net.en.uu-rs.com
    hxxp://us.battle.net.facc.cn.com
    hxxp://us.battle.net.ffus.asia
    hxxp://us.battle.net.gacc.cn.com
    hxxp://us.battle.net.ggwow.asia
    hxxp://us.battle.net.hhwow.asia
    hxxp://us.battle.net.iacc.cn.com
    hxxp://us.battle.net.iieu.asia
    hxxp://us.battle.net.jacc.cn.com
    hxxp://us.battle.net.kacc.cn.com
    hxxp://us.battle.net.lacc.cn.com
    hxxp://us.battle.net.lacc.cn.com
    hxxp://us.battle.net.llus.asia
    hxxp://us.battle.net.login.en.ddus.asia
    hxxp://us.battle.net.login.en.yykiki.com
    hxxp://us.battle.net.login.en.zkiki.com
    hxxp://us.battle.net.ok.jjweb.asia
    hxxp://us.battle.net.ok.kk-rs.com
    hxxp://us.battle.net.ok.qw-rs.com
    hxxp://us.battle.net.ok.uuweb.asia
    hxxp://us.battle.net.ok.yywow.asia
    hxxp://us.battle.net.pacc.cn.com
    hxxp://us.battle.net.ppwow.asia
    hxxp://us.battle.net.qacc.cn.com
    hxxp://us.battle.net.racc.cn.com
    hxxp://us.battle.net.rreu.asia
    hxxp://us.battle.net.tacc.cn.com
    hxxp://us.battle.net.uacc.cn.com
    hxxp://us.battle.net.uuwow.asia
    hxxp://us.battle.net.w.llweb.asia
    hxxp://us.battle.net.wacc.cn.com
    hxxp://us.battle.net.w-u.asia
    hxxp://us.battle.net.xacc.cn.com
    hxxp://us.battle.net.yacc.cn.com
    hxxp://us.battle.net.zacc.cn.com
    hxxp://us.battle.net-bizzard-d3-com.account-com.net
    hxxp://us.diablo.net.en.rk-login.in




    Most of the domains seem to be set up by the same person, someone named "Jin Yu":
    Registrant Contact:
       Jin Yu
       Yu Jin jinyu2000@yahoo.cn
       +86.324242434233 fax: +86.324242434233
       ShengLiLu
       Shangraoshi Jiangxi 610041
       CN

    Other email addresses associated with Jin Yu:
    329409115@qq.com
    service@511web.com


    Almost all of the IP addresses are originating from China. The hosting companies are as follows, and seem to not care (or know) that malware and phishing pages are set up:

    Beijing Weishichuangjie Technical Development Co. - IPvoid Result
    DEEPAK MEHTA FIE - IPvoid Result
    New World Telecom Ltd., Hong Kong - IPvoid Result
    XIN XIN LING - IPvoid Result


    Thanks to IPvoid you can easily see other sites hosted there, seems there is more of the same. (read: more malware & phishing pages are hosted)




    Conclusion

    Stay away from phishing mails like the ones pointed out in this post. There are several variants, some more graphical than others, but in the end they serve the same purpose:
    Trying to steal your login credentials!

    I'm sure that even when you open the mail, alarm bells should be going off if you simply check the URL, it's pointing to another address than the usual login page.

    To be clear, the real webpage to login for your Battle.net account is:
    https://battle.net/login/en/

    If you're ever in doubt, visit the website directly and do not click on any links in emails from unknown senders. Use add-ons like WoT and/or NoScript to stay protected against these types of threats.
    You can also use the URL scanning services at VirusTotal or URLvoid to double-check a URL.



    Friday, August 10, 2012

    A word on XDocCrypt/Dorifel/Quervar

    I'm sure everyone has heard by now about the so called XDocCrypt/Dorifel/Quervar malware.

    It has mostly damaged machines in The Netherlands, but reports have come in from other countries (including the United States) as well. I myself have seen this infection on 08/08/2012, my initial thought was: ransomware. However, there isn't any message displayed, so it's either a failed ransomware attempt or the malware simply wants to annoy users.

    This virus infects Office files, reverses the extension and adds “.scr” behind it (this is also known as the RTLO unicode hole, which makes it easy to hide the original file extensions. - I remember a blogpost from not too long, about this hole targeting users of the Arabic language, let me know if you find it - ). Renaming does not solve the issue, you cannot open the documents.



    Office files affected by the malware


    As is depicted in the figure above, Word and Excel files have their extension reversed, so now the files appear to be .scr files, which is the format for a Screensaver. The .jpg file is not affected in any way.

    The files are encrypted with RC4, which is a very common encryption algorithm in the cryptography. SurfRight has developed a tool to decrypt (and recover) your files:
    Dorifel decrypter



    The malware has probably been downloaded by the Citadel or Zeus (aka Zbot) malware.


    Zeus sample:

    remyf.exe
    Result: 12/42
    MD5: 30e7785cb9eafcea34fe930631fbba07
    VirusTotal Report
    Anubis Report



    Let's take a look at a few Dorifel samples:

    Acquisit.exe
    Result: 15/42
    MD5: d913394b8011b317f6d916507ffb7f2f
    VirusTotal Report
    Anubis Report


    gis-woz4_v8.exe
    Result: 12/42
    MD5: a311cd6f67cb112cba78a27b87320fc3
    VirusTotal Report
    Anubis Report


    DGRAYP.exe
    Result: 24/42
    MD5: f05f4f5be8431f746e59fe409a0b9bb1
    VirusTotal Report
    Anubis Report


    Y6TK9B.exe
    Result: 11/42
    MD5: c1fa3618d7b54ab6a7a25857d7b30b3c
    VirusTotal Report
    Anubis Report



    The malware tries to connect to one of the following IP addresses:
    184.82.162.163 - IPvoid result
    184.22.103.202 - IPvoid result


    Where it will attempt to download the following file:

    a.exe
    Result: 13/42
    MD5: 493887a87cd95b004f9ffbbaaecd1ac6
    VirusTotal Report
    Anubis Report



    I haven't taken an in-depth look at it, but besides encrypting your Office files, I have seen the malware will kill itself when you open up Task Manager. Not sure what the point is there. It also doesn't seem to start up again automatically.

    It does create an .lnk file to the dropped malware and puts that as an autorun entry, so it will start every time the machine starts.



    Conclusion

    The infection vector (how it spreads) is via phishing or spam email, so as usual:

    - Don't open attachments from unknown senders - ever.
    - Some antivirus already detected Dorifel generically, so update your antivirus.

    - If you're in a corporate network, use a strong spamfilter. It will prevent a lot of troubles if correctly configured.
    - Educate your users: raise the general awareness. Not even a spamfilter stops 100% of all the spam, there's always a chance something slips through.




    Thanks to @erikremmelzwaal from Medusoft for most of the samples.

    External sources:

    Wednesday, April 11, 2012

    Hacked Hotmail accounts... and the consequences

    It's a trend I'm seeing more and more, even with some of my relatives:

    Their Hotmail account is getting hacked, and from then on is being used by scammers or malware authors to spread their malicious intent.

    In almost all cases, you'll receive an email with (No Subject), and the only content is a link pointing to some website. But wait: it seems that all those websites have (probably an outdated version of) Wordpress installed.

    When you click the link, you will be redirected to either a scam/phishing page or scareware/rogueware.

    Either way, you'll first get the following message:


    Message you receive when clicking on the link

    So let's take a closer look at the 2 scenarios you get on your plate:

    Scenario #1 - scam


    Scam page

    In scenario number one, you'll be presented with an awesome News page, where you can read several testimonials of how great working from home is.

    It also has some fascinating news stories on how to make lots of money by simply being at your comfortable home. This includes reactions on the articles - of course this is all fake.

    If you click on any of the links on this website, you'll be ultimately redirected to - hxxp://internetprofitpacket.com

    Administrative Contact:
    WhoisGuard
    WhoisGuard Protected
    +1.6613102107
    Fax: +1.6613102107
    11400 W. Olympic Blvd. Suite 200
    Los Angeles, CA 90064
    US


    UrlQuery Result:
    Suspicious
    http://urlquery.net/report.php?id=40849

    URLvoid Result:
    1/25 (4.00%)
    http://www.urlvoid.com/scan/internetprofitpacket.com/


    Ultimately you land on the following page:


    Landing page where you'll need to pay

    After paying a small price, you'll get lifetime access to the Internet Profit Package ! What honor !

    Obviously, you'll get scammed and your credit card details might get stolen.


    Scenario #2 - scareware

    Likewise as in scenario #1, you'll get the nice message that you got here thanks to your friend.


    Seems like you're infected ... right ?

    You'll then be presented with a pop-up indicating critical process activity has been found and a scan will be launched... (I think we all know this one by now) :


    Fake Explorer window indicating numerous infections

    If you click on any button, a file will be downloaded with the name of setup.exe.

    In this case, the file was downloaded from:
    hxxp://fail-safetylow.info/bb61f9bcec711d56/29/setup.exe

    This site and several other rogueware pages are hosted on the IP:
    64.120.207.107


    Several other rogueware sites are hosted on this IP


    We'll now see some more details about the downloaded file:

    setup.exe
    Result: 5/40
    MD5: 8b0c16a50c0bca1eb0b45bd411eb30e5
    VirusTotal Report
    ThreatExpert Report
    Anubis Report

    This file drops another executable:

    Protector-hfpt.exe
    Result: 5/42
    MD5: f04cb906356f19a1dbf68c62f162c4e7
    VirusTotal Report
    Anubis Report


    The payload is a rogueware called "Windows Antibreaking System" :


    Windows Antibreaking System setup screen



    Windows Antibreaking System main screen


    Prevention

    - Most important of all: use a strong password ! You can verify your current password, or create a new one to check its strength on the following website: http://www.passwordmeter.com

    - Second important rule:
    don't use the same password for each and every website !

    - Be wary when receiving such a mail, even if it's from someone you know.

    - Use browser extentions to verify the integrity of an image or URL. Useful add-ons are for example WOT or NoScript.

    - Keep your Antivirus and browser, as well as your browser add-ons up-to-date.

    - If it is too late and a 'scan' is already starting, immediately close your browser by bringing up Task Manager (CTRL + ALT + DEL) and killing your browser's process:
    • a) For Google Chrome: chrome.exe or chrome.exe *32
    • b) For Mozilla Firefox: firefox.exe or firefox.exe *32
    • c) For Microsoft's Internet Explorer: iexplore or iexplore.exe *32


    Desinfection

    If the harm is already done and you are getting warnings, messages or pop-ups stating you are infected and you need to take 'immediate action' to clean your computer, follow the guide below at BleepingComputer's to rid yourself of this malware:

    BleepingComputer's Virus Removal


    Also, if you know the sender personally, notify him/her that they've been hacked and they need to change their password. If you don't know the sender, immediately remove the email.

    In Hotmail, you even have a useful option if you know the sender. Open the email, select Mark as and click on My friend's been hacked!


    Help your friend by stating (s)he's been hacked


    If you happen to have a Wordpress website, be sure to update it regularly as well as any Wordpress plugins you may have installed. This website will aid you in the matter: Hardening WordPress



    Conclusion

    Don't fall for either of these, in both cases you'll lose a lot of money !

    Follow the above prevention tips to decrease the chance of your computer becoming infected.

    Tuesday, April 10, 2012

    Free Riot codes scam



    Below you can find a list of confirmed phishing and scam websites. In the conclusion (end of this post or click) you'll be able to find some prevention tips and what to do if your account has been hacked.



    Facebook. A social networking place. For some a dream come true, for others a true nightmare. Guess in which category phishers, scammers and malware authors reside?

    In today's post we will be highlighting a scam specifically focusing on players of the game League of Legends, an action real-time strategy game developed and published by Riot Games.

    The scam page on Facebook in question is:
    hxxp://www.facebook.com/pages/Free-Riot-codes/141669939249958

    Currently, it already has over 41,000 likes:


    More and more people are liking the page, thus might be getting scammed



    On Youtube as well as on Google+ and Twitter it is -for now- pretty calm. Only a few video's and tweets promoting this scam:


    On Twitter, Google+ and Youtube they are also promoting their website, but not as heavily as on Facebook


    Example websites where you can get "free" riot points  or "free" riot codes are
    (ALL FAKE!):

    hxxp://bilgewaterchests.com      
    hxxp://blogs.gamenov.us/lol
    hxxp://cheatsjungle.com/league-of-legends-promotional-code-generator-2
    hxxp://cheatsjungle.com/league-of-legends-riot-points-generator
    hxxp://christmas.riotpromotions.com
    hxxp://clasentropsorp.somee.com
    hxxp://easycheat.org
    hxxp://elohell.org
    hxxp://free20skins.jimdo.com
    hxxp://free-mystery-skins-2015.esy.es
    hxxp://free-riot-points-codes.org
    hxxp://free-riotcodes.info
    hxxp://free-riotpointscodes.com
    hxxp://free3600rp.byethost22.com
    hxxp://freehackgames.org/league-of-legends-riot-points-generator-3-2-version              
    hxxp://freeleaguecodes.com    
    hxxp://freeleaguecodes.congoloid.net
    hxxp://freeleaguecodes.net    
    hxxp://freeleagueoflegendsriotpoints.com
    hxxp://freeleagueoflegendsriotpointcodes.com    
    hxxp://freeleagueoflegendskins.co.uk    
    hxxp://freelol-skins.blogspot.ba    
    hxxp://freelolcodes.com      
    hxxp://freelolriotcodes.com   
    hxxp://freelolriotcodes.info
    hxxp://freelolriotcodes.netii.net  
    hxxp://freelolriotpointz.blogspot.com      
    hxxp://freelolrpcodez.weebly.com 
    hxxp://freelolskins.com   
    hxxp://freepoitnsforyou.com 
    hxxp://freeriot4free.com
    hxxp://freeriotcodes.com            
    hxxp://freeriotcodes.filegame.net              
    hxxp://freeriotcodes.info  
    hxxp://freeriotcodes.org           
    hxxp://freeriotcodes.weebly.com              
    hxxp://freeriotcodesgift.com 
    hxxp://freeriotpoints32.blogspot.com
    hxxp://freeriotpoints.me
    hxxp://freerpgenerator.com
    hxxp://freeriotpointcodes.net
    hxxp://freerpriotpoints.wordpress.com
    hxxp://freeriotpointsgeneration.com     
    hxxp://freeriotpointderiot.yolasite.com
    hxxp://freeriotpointscheat.blogspot.com
    hxxp://freeriotpointsclub.com  
    hxxp://freeriotpointscode.com
    hxxp://freeriotpointscodes.com
    hxxp://freeriotpointsgenerators.blogspot.com   
    hxxp://freeriotpointsleagueoflegends.blogspot.com
    hxxp://freeriotpointslol.com        
    hxxp://freeriotpointsnow.com              
    hxxp://freeriotpointss.com 
    hxxp://freerpcodegenerator.com            
    hxxp://freerpcodes.com              
    hxxp://freerpcodes.tk  
    hxxp://freerpleagueoflegends.yzi.me        
    hxxp://freerppoint.com    
    hxxp://gameskeys.info/riot-points-generator   
    hxxp://getfreeriotcodes.blogspot.com              
    hxxp://getfreeriotcodes.com              
    hxxp://getfreeriotpoints.com 
    hxxp://getfreeriotpoints.org 
    hxxp://getfreeriotpointsfast.com
    hxxp://getfreerppoints.blogspot.com
    hxxp://getfrenocturneskin.webs.com          
    hxxp://getriotcodes.com      
    hxxp://getriotpoints.info       
    hxxp://getriotpointscodes.com   
    hxxp://getriotpointsforfree.com
    hxxp://getriotpointsfree.com
    hxxp://getyourfreeriotpointcodes.blogspot.com
    hxxp://giftsofsnowdown.com
    hxxp://give-aways.net
    hxxp://www.godshack.tk
    hxxp://gogamecheats.com/league-of-legends-free-riot-points 
    hxxp://hackerzzs.blogspot.com              
    hxxp://hackscheatsgamesprograms.blogspot.com
    hxxp://hacksplanet.net/league-of-legends-hack-2014
    hxxp://howtogetfreeriotpoints.com
    hxxp://lcs.riotpromotions.com
    hxxp://leageuoflegends.com
    hxxp://league-gamers.com
    hxxp://leaguecodes.net
    hxxp://leaguecodes.org
    hxxp://leaguegift.com
    hxxp://leagueofcheat.com
    hxxp://leagueoflegends.byethost33.com
    hxxp://leaguesoflegends.nazuka.net
    hxxp://leagueoflegends2012hack.blogspot.com    
    hxxp://leagueoflegendsrpandipgenerator.blogspot.com
    hxxp://leagueoflegendsrphack.com 
    hxxp://leagueoflegendvotevelkoz.ye.vc  
    hxxp://leaguereward.net
    hxxp://leaguerewards.net         
    hxxp://leaguerp.com  
    hxxp://leaguerp.net
    hxxp://leaguerpgifts.com       
    hxxp://leagueoflegendseuw.esy.es
    hxxp://leagueoflegendsgenerator.wordpress.com
    hxxp://leagueoflegendsgiveaway.com
    hxxp://leagueoflegendsrpcodegenerator.blogspot.com   
    hxxp://leagueoflegendsrpcodegenerator.weebly.com
    hxxp://leagueoflegendssupporte.esy.es
    hxxp://leagueflegendvoteasestribunall.gaming.lc
    hxxp://live.rpgiveaway.com  
    hxxp://lol.freepoitnsforyou.com         
    hxxp://lolhacktool.blogspot.com 
    hxxp://lolfreeriotpoints.blogspot.com
    hxxp://lolfreerp.com             
    hxxp://lolmultihack2012.blogspot.com
    hxxp://lolpromobundles.blogspot.com             
    hxxp://lolriotpointcodes.blogspot.com              
    hxxp://lolrpgenerator.webs.com   
    hxxp://lolrpgifts.com
    hxxp://lolrpgiveaways.weebly.com    
    hxxp://lolrpoints.com
    hxxp://lordhacks.com/league-of-legends-hack
    hxxp://lordhacks.com/league-of-legends-promotional-code-generator
    hxxp://my-riotpoints.xyz
    hxxp://naleagueoflegends.ga
    hxxp://oisn.mypressonline.com/league
    hxxp://rafflesforprizes.com
    hxxp://riot.ws
    hxxp://riot-codes.com
    hxxp://riot-point.com
    hxxp://riot-points-free.info
    hxxp://riot-points.free-cards.info   
    hxxp://riot.edgehacking.com              
    hxxp://riot.freecodesgiveaway.com   
    hxxp://riot.generator4points.com          
    hxxp://riotcodegenerator.com 
    hxxp://riotcodesgenerator.com            
    hxxp://riotcodes.hacksfiles.com              
    hxxp://riotcodes.net              
    hxxp://riotcodesforfree.org              
    hxxp://riotcodesfree.com              
    hxxp://riotcodesfree.net
    hxxp://riotgames.qualtrics.com
    hxxp://riotgenerator.com
    hxxp://riotgiveaway.net
    hxxp://riotpoint.eu
    hxxp://riotpointcodes.org
    hxxp://riotpointgenerator.com
    hxxp://riotpointsgenerator.net
    hxxp://riotpointshack.eu
    hxxp://riotpoints.4free-games.net
    hxxp://riotpoints.alqbyte.com
    hxxp://riotpoints.cu.cc  
    hxxp://riotpoints.net
    hxxp://riotpointsadderforfree.blogspot.com
    hxxp://riotpointscampaign.com 
    hxxp://riotpointscheat.blogspot.com      
    hxxp://riotpointscodes.info 
    hxxp://riotpointscodes.net
    hxxp://riotpointscodes.org
    hxxp://riotpointsgeneratorfree.blogspot.com           
    hxxp://riotpointsfree.com  
    hxxp://riotpointsgenerator.co
    hxxp://riotpointsgenerator.org  
    hxxp://riotpointshop.com    
    hxxp://riotpointsrewards.weebly.com      
    hxxp://riotpoints-free.com
    hxxp://riotpromotions.com
    hxxp://riotsgiftcard.com
    hxxp://rpcode.me
    hxxp://rpcodes.info
    hxxp://rpcodesnow.com
    hxxp://rpfree.com
    hxxp://rprewards.com
    hxxp://rp-free.blogspot.com              
    hxxp://rpgiveaway.com
    hxxp://rpointsgenerator.com  
    hxxp://rppointsfree.com   
    hxxp://smashingsports.co/download/riot-points-generator
    hxxp://thefreeriotpoints.com  
    hxxp://thefreerp.yolasite.com
    hxxp://unlimitedhacks.com/league-of-legends-riot-points-generator 
    hxxp://unlockcodehome.com/riot-unlockcodes.php      
    hxxp://videogamehacks.net/riot-points-generator
    hxxp://www.vix-group.com/lol
    hxxp://xpandhacks.net/league-of-legends-riot-points-generator
    hxxp://xpandhacks.com/league-of-legends-riot-points-generator-2                

    You can +1 it, share it on Facebook, Tweet it ... Share the scam with everyone you like ;-) .

    The first link in bold is the one discussed in this blog post. All you have to do to get your Riot Points for free is to follow these 3 easy steps:

    Step 1 - Share it on Facebook
    Step 2 - Post the following message once on your wall and 5 times on a Different Game Page on Facebook:
    WOW! I just got my League of Legends Riot Code for free! So excited! Thanks hxxp://freeriotcodes.com !
    Step 3 - Click "Like and Confirm"

    Step 2 in the process - posting on Facebook. In this specific scam, it is not being posted automatically to your wall, you actually have to share it yourself


    That's it, 3 simple steps and then you'll be able to download your Riot Points or codes free of charge!

    ... But wait, there's a timer on the page indicating you'll have to wait before the next giveaway:



    Somehow, I got lucky and, through one of the other websites, I was able to visit the download page and acquire my points!

    However, ultimately I have to complete a survey to finally download my Riot points. I am getting redirected to several other scams and so on. You can win a smartphone, the new iPad, an iPhone, trendy boots, a Macbook ....

    In some cases only your phone number is sufficient, in others you'll have to fill in complete information like your full address, email address ...

    Some examples of dubious file sharing websites, which are also showing a popup with some Javascript behind it (another survey scam):
    hxxp://cleanfiles.net
    hxxp://fileharmony.com
    hxxp://fileice.net
    hxxp://fileme.us
    hxxp://fileml.com
    hxxp://filenix.com
    hxxp://filesquick.net
    hxxp://jlyse.net
    hxxp://matrixmega.com
    hxxp://needforfile.net
    hxxp://oceanfiles.me
    hxxp://redirectlock.com
    hxxp://sharecash.org
    hxxp://sharkyfiles.com 
    hxxp://skippyfile.com 
    hxxp://speedyfiles.net
    hxxp://tinyfileshost.com
    hxxp://topfiles.me
    hxxp://videlocked.pw


    There's also a Pastebin link with all the above scam/phishing sites for League of Legends here: League of Legends scam & phishing URLs



    Conclusion