<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; fraud</title>
	<atom:link href="http://blog.novirusthanks.org/tag/fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Massive phishing scam emails against Maybank Malaysia</title>
		<link>http://blog.novirusthanks.org/2010/01/massive-phishing-scam-emails-against-maybank-malaysia/</link>
		<comments>http://blog.novirusthanks.org/2010/01/massive-phishing-scam-emails-against-maybank-malaysia/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 01:54:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[maybank]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=2229</guid>
		<description><![CDATA[We have recently counted more than 50 scam emails that contain very dangerous links used for phishing attacks against the Maybank of Malaysia. &#160; &#160; Below there are some examples of subjects used in the scam emails: Subject: Important Update Subject: Security Check Subject: Update your profile Subject: Urgent Notice Subject: Profile update Subject: Security [...]]]></description>
			<content:encoded><![CDATA[<p>We have recently counted more than 50 scam emails that contain very dangerous links used for phishing attacks against the Maybank of Malaysia.</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/maybank-phishing.jpg" alt="Maybank phishing emails" title="Maybank phishing emails" width="530" /></p>
<p>&nbsp;</p>
<p>Below there are some examples of subjects used in the scam emails:</p>
<blockquote><p>
Subject:  	Important Update<br />
Subject:  	Security Check<br />
Subject:  	Update your profile<br />
Subject:  	Urgent Notice<br />
Subject:  	Profile update<br />
Subject:  	Security Warning<br />
Subject:  	Update your Account<br />
Subject:  	Update your Password
</p></blockquote>
<p>While I was checking the headers of the emails, I noticed that most of the IP addresses of the senders come from Chinese (.CN) domains:</p>
<blockquote><p>
mail.bnu.edu.cn (mail.bnu.edu.cn [219.142.99.2])<br />
58.185.112.164 (HELO user) (58.185.112.164) by 219.142.99.2<br />
mailqd.cmr.com.cn (unknown [211.100.42.132])<br />
User ([212.62.45.71]) by mailqd.cmr.com.cn<br />
mail0.shift.edu.cn (unknown [61.152.219.51])<br />
User ([58.185.112.164]) by mail0.shift.edu.cn<br />
mail.smu.ac.kr (smu.ac.kr [203.237.168.13])<br />
User ([58.185.112.164]) (authenticated (0 bits)) by mail.smu.ac.kr<br />
idrgroup-nx0i3d.idrgroup.local (servera210.opencom.com [121.78.88.210])<br />
User ([58.185.112.164]) by idrgroup-nx0i3d.idrgroup.local<br />
mail.fudan.edu.cn (unknown [61.129.42.10])<br />
User ([212.62.45.71]) by mail.fudan.edu.cn
</p></blockquote>
<p>Some of the malicious links used for phishing attacks are the following:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">hxxp://zoahaza.isfreeweb.com/tt/style/setup/image/m2u.htm
hxxp://www.dobongn.kr/gnuboard4/bbs/m2u.htm
hxxp://central-groove.co.uk/images/M_images/www.maybank2u.com.my/m2u.htm
hxxp://zoahaza.isfreeweb.com/tt/components/m2u.htm
hxxp://womabkr.com.tw/Ch/img/main.htm</pre></td></tr></table></div>

<p>Not all the links are still active and fortunately there are also links that are detected and blocked by Mozilla Firefox but keep in mind that there are always links that are not blocked or that are not detected by any antispam filter!</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/maybank-phishing2.jpg" alt="Reported web forgery" title="Reported web forgery" /></p>
<p>&nbsp;</p>
<p>Remember always to NOT insert sensitive data in unknown websites and to never click in links contained in unknown emails. When you receive this kind of emails, example from your Bank, and you are requested to insert sensitive data make sure to give a call to your bank before insert any kind of data in the suspicious website.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2010/01/massive-phishing-scam-emails-against-maybank-malaysia/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam Campaigns go for RTF Documents</title>
		<link>http://blog.novirusthanks.org/2009/05/spam-campaigns-goes-for-rtf-documents/</link>
		<comments>http://blog.novirusthanks.org/2009/05/spam-campaigns-goes-for-rtf-documents/#comments</comments>
		<pubDate>Sat, 30 May 2009 21:21:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[rtf spam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/2009/05/spam-campaigns-goes-for-rtf-documents/</guid>
		<description><![CDATA[A new spam strategy is in the wild. We spoke on a recent article that spammers were using a new trick to bypass anti-spam filters by adding the text on an image and send the image attached as file. Now it seems they changed from image to RTF document: The attached file contains a redirect [...]]]></description>
			<content:encoded><![CDATA[<p>A new spam strategy is in the wild. We spoke on a <a href="http://novirusthanks.org/blog/2009/04/new-spam-strategy-in-the-wild/" target="_blank">recent article</a> that spammers were using a new trick to bypass anti-spam filters by adding the text on an image and send the image attached as file. Now it seems they changed from image to RTF document:</p>
<p><img src="http://img2.imageshack.us/img2/8503/screenhunter01may302310.gif" alt="New Spam Strategy Screenshot" title="New Spam Strategy Screenshot" /></p>
<p>The attached file contains a redirect to a malicious link:</p>
<p><img src="http://img411.imageshack.us/img411/8717/spamnew.gif" alt="Malicious Link Screenshot" title="Malicious Link Screenshot" /></p>
<p>Malicious link details:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
6
7
8
9
10
11
12
13
14
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">Domain: 9-000.com
Ip Address: 203.93.208.86
&nbsp;
Administrative Contact:
Name : NIUJINGYI
Organization : NIUJINGYI
Address : CHANGFENGLU51
City : jiujiangshi
Province/State : jiangxisheng
Country : china
Postal Code : 332113
Phone Number : 86-0792-56051418
Fax : 86-0792-56051418
Email : NIUJINGYI@126.COM</pre></td></tr></table></div>

<p>Other malicious domains:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">4-999.net
7-999.com
4-555.net</pre></td></tr></table></div>

<p>We have noticed around 150 spam emails of this type on 48 hours and most senders seem to be ADSL users&#8230; is possible the spam campaign was started by a botnet.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/05/spam-campaigns-goes-for-rtf-documents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New spam strategy in the wild</title>
		<link>http://blog.novirusthanks.org/2009/04/new-spam-strategy-in-the-wild/</link>
		<comments>http://blog.novirusthanks.org/2009/04/new-spam-strategy-in-the-wild/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 18:46:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[fraud]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=1441</guid>
		<description><![CDATA[Recently we noticed a big archive of spam messages related to selling various pharmacy products. But something was different from the old spam messages&#8230; no http links were present in the message. &#160; The surprise was attached in .gif or .jpg or .png format: &#160;]]></description>
			<content:encoded><![CDATA[<p>Recently we noticed a big archive of spam messages related to selling various pharmacy products. But something was different from the old spam messages&#8230; no http links were present in the message.</p>
<p>&nbsp;</p>
<p>The surprise was attached in .gif or .jpg or .png format:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/new-spam-strategy-00.gif" alt="Spam Images Screenshot"  title="="Spam Images Screenshot"/></p>
<p>&nbsp;</p>
<p>The attached image has inside all the info related to various pharmacy products and the malicious http url:</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/new-spam-strategy-01.gif" alt="Spam Image Screenshot" title="Spam Image Screenshot" /></p>
<p>&nbsp;</p>
<p>Spammers are using this strategy to bypass common anti spam filters and to avoid to be placed in the &#8220;spam folder&#8221; of the email clients.</p>
<p>&nbsp;</p>
<p>Other spam messages were full of links that redirected to yahoo groups with random names:</p>
<blockquote><p>
groups.yahoo.com/group/zygikyromaxit49/message/1<br />
groups.yahoo.com/group/vigecydavypov17/message/1<br />
groups.yahoo.com/group/gefyfewozimax24/message/1
</p></blockquote>
<p>All the above links redirected again to other suspicious domains:</p>
<blockquote><p>
proudtasty.com<br />
advocacywife.com
</p></blockquote>
<p>Pay always attenction when opening unknown, and even known, emails.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/04/new-spam-strategy-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Massive phishing scam emails against Poste Italiane</title>
		<link>http://blog.novirusthanks.org/2009/03/massive-poste-italiane-phishing-emails/</link>
		<comments>http://blog.novirusthanks.org/2009/03/massive-poste-italiane-phishing-emails/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 22:32:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=1358</guid>
		<description><![CDATA[We recently received a lot of phishing emails used by attackers to steal Poste Italiane accounts by redirecting victims to a malicious website that looks as the Poste Italiane homepage. Despite this, the user who will insert its details will be victim of a phishing attack and is highly suggested to change its username and [...]]]></description>
			<content:encoded><![CDATA[<p>We recently received a lot of phishing emails used by attackers to steal Poste Italiane accounts by redirecting victims to a malicious website that looks as the Poste Italiane homepage. Despite this, the user who will insert its details will be victim of a phishing attack and is highly suggested to change its username and password of its account.</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/mass-phishing-emails.gif" alt="Screenshot of the phishing email" title="Screenshot of the phishing email" width="530" /></p>
<p>&nbsp;</p>
<p>Malicious links used for phishing attacks:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">hxxp://217.24.231.33/login.html
hxxp://79.39.132.165/poste/index.htm</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/03/massive-poste-italiane-phishing-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Promemoria eBay per oggetto non pagato numero</title>
		<link>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/</link>
		<comments>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/#comments</comments>
		<pubDate>Thu, 29 Jan 2009 22:59:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[ebay spam]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=818</guid>
		<description><![CDATA[We received again new false eBay emails that redirects the user to visit a webpage that is used to steals the user&#8217;s eBay account with a false webpage, similar to the original eBay homepage, that save the logi account typed by the user and send the sensitive data to the attacker. &#160; Message Promemoria eBay [...]]]></description>
			<content:encoded><![CDATA[<p>We received again new false eBay emails that redirects the user to visit a webpage that is used to steals the user&#8217;s eBay account with a false webpage, similar to the original eBay homepage, that save the logi account typed by the user and send the sensitive data to the attacker.</p>
<p>&nbsp;</p>
<p><u>Message</u></p>
<blockquote><p>
Promemoria eBay per oggetto non pagato numero 3104678753291</p>
<p>Gentile member,<br />
alenf ha segnalato di non avere ancora ricevuto il pagamento per il seguente<br />
oggetto: numero 3104678753291</p>
<p>Al momento non viene intrapresa alcuna azione nei confronti del tuo account.<br />
Tuttavia, ti ricordiamo che quando fai un&#8217;offerta o acquisti un oggetto su eBay,<br />
prendi un impegno vincolante con il venditore. Se la situazione non verr? risolta<br />
entro 7 giorni dalla ricezione di questo promemoria, riceverai un ammonimento per<br />
oggetto non pagato&#8230;
</p></blockquote>
<p><u>Header</u></p>
<blockquote><p>
<strong>Received</strong>: from hsenc.co.kr (unknown [211.215.20.40])<br />
<strong>Received</strong>: from User (80.229.253.105)<br />
by hsenc.co.kr (211.215.20.40) with [Nmail V3.6]<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 3104678753291<br />
<strong>Date</strong>: Thu, 29 Jan 2009 15:25:31 -0000
</p></blockquote>
<blockquote><p>
<strong>Received</strong>: from 419revolution.org (unknown [211.106.23.71])<br />
<strong>Received</strong>: from User ([])<br />
by 419revolution.org (Merak 6.1.0)<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 292567831524<br />
<strong>Date</strong>: Mon, 28 Jan 2009 14:38:18 -0000
</p></blockquote>
<blockquote><p><strong>Received</strong>: from mail.quike.com.cn (unknown [202.75.222.151])<br />
<strong>Received</strong>: from User ([80.229.253.105])<br />
by 211.155.233.151 with ESMTP<br />
<strong>Subject</strong>: Hai ricevuto un ammonimento per Oggetto non pagato 260300220759<br />
<strong>Date</strong>: Mon, 28 Jan 2009 14:38:18 -0000
</p></blockquote>
<blockquote><p>
<strong>Received</strong>: from topinfo.com.cn (unknown [211.157.2.61])<br />
<strong>Received</strong>: from User [80.229.253.105] by topinfo.com.cn<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 299010852347<br />
<strong>Date</strong>: Mon, 17 Nov 2008 10:51:59 -0000
</p></blockquote>
<p>Make sure to not fall in this scam, check always the address of the site before write sensitive data in web forms and analyze always the header of the emails.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What to do in case of a suspected email or phishing ?</title>
		<link>http://blog.novirusthanks.org/2008/10/what-to-do-in-case-of-a-suspected-email-or-phishing/</link>
		<comments>http://blog.novirusthanks.org/2008/10/what-to-do-in-case-of-a-suspected-email-or-phishing/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 15:48:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[what to do]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=75</guid>
		<description><![CDATA[Some basic info on what to do in case of a suspected email or phishing: &#160; Use always maximum attenction when reading the email Never click on http links or images Never download attachments Analyze the header of the email Check the email of the sender on google to see if you find bad info [...]]]></description>
			<content:encoded><![CDATA[<p>Some basic info on what to do in case of a suspected email or phishing:</p>
<p>&nbsp;</p>
<ul>
<li>Use always maximum attenction when reading the email</li>
<li>Never click on http links or images</li>
<li>Never download attachments</li>
<li>Analyze the header of the email</li>
<li>Check the email of the sender on google to see if you find bad info</li>
<li>Check the info of the sender&#8217;s site on google</li>
<li>Report the email to your local authorities</li>
<li>Report the email to <a href="http://www.phishtank.com/" target="_blank" rel="nofollow">PhishTank</a></li>
<li>Delete the email</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/10/what-to-do-in-case-of-a-suspected-email-or-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

