Tuesday, 6 December 2011

New Facebook scam

A new Facebook scam is spreading today, 6th of December. The interesting thing is that I have seen it posted in Dutch as well.

The method used is the same as in previous Facebook scams, see for example my earlier post:
New Facebook scam

Here is the post in question (in Dutch):


Classical scam post to lure users into clicking the link.

Here's what it reads:
WOW! Mijn profiel is ALLEEN VANDAAG AL 12 keer bekeken.. en ik kan zien dat er behoorlijk wat stalkers bijzitten LOL! Kijk zelf wie jou allemaal in de gaten houdt op #removed#

In English:

WOW! My profile has been seen 12 time ALREADY ONLY TODAY .. and I can see that quite a few stalkers are included LOL! See for yourself who's keeping an eye on yoy on #removed#



The link has been shortened by the bit.ly URL shortening service. While this service is not malicious on itself, it can also be used by persons with malicious intent, whether it would be hackers, malware authors, ... Or in this case scammers.

Let's review some stats for the bit.ly link first:


98 clicks on this link in the last hour



Top countries, including: France, Germany, The Netherlands



Facebook.com is the most referring site


At the moment of writing, there have been over 1,000 clicks on the link so far. I have already reported it to bit.ly and it should be taken down soon.

UPDATE: bit.ly has already issued a warning for when you click on the link. (12/07/2011)


Now let us analyse where the bit.ly link is taking us. The link can redirect you to different websites, but they will all (so far) redirect you to a page similar to this one (depending on your location):


Who is viewing your Facebook profile ?


You probably don't remember my post from February this year, but the concept is the same: you can supposedly view who's been "stalking", or viewing, your profile. This to attract users on clicking the link. Who doesn't want to see this, right ? Here is my post from early this year:
Facebook rogue applications still lurking around

You can presented with a screen like this (I have several, but I will only post one as example):

Are you the "lucky" winner ?

As stated previously, the concept is the same. Before you can see who's been viewing your profile, you need to fill in a short service to continue.

You may have won a prize, you may have won an iPad, you may have won free ringtones, you may have won a free iPhone application, etc, etc, etc, .... This is of course all a lie.
Remember: if it looks too good to be true, it probably is !

You have to fill in your email address and/or phone number to continue as well. At the end you will end up losing a lot of money, leaving your email address in the open and maybe worse.

Remember: if you click the link while logged in to Facebook, it will also post it on your own wall.



Conclusion

Conclusion is pretty straightforward: do not click on any of the links ! If in doubt, send your friend on Facebook (or if someone sent you the link) via PM if he or she knows what this is about.

To remove this from your or your friend's wall, click on the X on the message, and choose to "Report/Mark as spam" or "Remove Post".

You can also use a linkscanner to verify the integrity of a link on either http://www.urlvoid.com or https://www.virustotal.com/

To get some information on a bit.ly (or other URL shortener serivce) link, you can use any of the following websites:
- http://www.getlinkinfo.com/
- http://longurl.org/
- http://www.longurlplease.com/ (includes Firefox extension)

To report a malicious bit.ly link use:
http://bitly.com/a/report_spam

For any other question, do not hesitate to post a comment !

Friday, 2 September 2011

Increase in malicious spam



Rodel Mendrez from M86 Security labs has made an excellent post on a Massive Rise in Malicious Spam:

http://labs.m86security.com/2011/08/massive-rise-in-malicious-spam/





As he notes in his conclusion, "It seems spammers have returned from a holiday break and are enthusiastically back to work."





So I decided to check out if I had received some spam as well. Jackpot ;-) !






UPS notification























































Re: End of July Statement Required









Your credit card has been blocked











ACH Transfer Review







Most of the files are displaying a Word or PDF icon to trick

the user in opening the file:







Some examples of attachments, with their respective

VirusTotal results:



Invoice_08.17.2011_Collcod.exe

MD5: cf0397bb622e4ed9dfdeb07fcbfa9687

VirusTotal Report



MasterCard_invoce_ID73284783275943.doc.exe

MD5: 0b7eba77dd4bcea3c670c4a664e98778

VirusTotal Report



UPS_Document.exe

MD5: 17f9148b130a94ab1f50030ebbf2415a

VirusTotal Report



form-62091.exe

MD5: e18d8cb2a4264a3c559d7967b3c6ab99

VirusTotal Report



When opening either of these files, you can end up with a rogue.

One example rogueware I got was "System Repair":



System Repair rogueware



The dropped file that is launching the rogueware:



pusk3.exe

MD5: 27077c2058983bb76bd09cdad69f7bde

Result: 36/44 (81.8%)

VirusTotal
Report

ThreatExpert
Report

Anubis Report







Conclusion

Conclusion is pretty simple: Do not open any attachments from unknown senders.

If you happen to be infected with System Repair, you can for example use the guide on Bleepingcomputer:

http://www.bleepingcomputer.com/virus-removal/remove-system-repair


Tuesday, 12 July 2011

Guide to Earn Money from Forex Trading in Urdu

Forex trading in urdu,Forex news in urdu,Forex Market Trading,
 
 Trading Forex is a well-known business, moreover people have been trading currencies for decades already.

 

Tuesday, 5 July 2011

earn money ity.im Own Blog

What is a ITY.IM.
We are a free URL shortening service with cutting edge features!
Get paid to share your links on the internet! (WATCH VIDEO)
Upload images and get a short url for them! (MORE)
Add custom content such as banner exchanges to your destination pages! (MORE)
Get paid to promote ity.im and refer friends! (MORE)
Win weekly cash prizes! (MORE)
Own a website or blog? Monetize your website with ity.im! (MORE)
Have a phpBB,Vbulliten forum Monetize it! (WATCH VIDEO)
Have a wordpress blog? Monetize it!
An API is available for custom integration into your websites! (MORE)

  • Click Hare This Bunner And Join 


Get paid to promote ITY.IM ANYWHERE!
Earn up to $0.40CPM for US traffic for sending visitors to your paid to promote link!
On top of that, when someone signs up under your account you will earn:





ADDITIONAL REFERRAL BONUSES:
When you have a total of 10 referrals you will earn a bonus of $2.00
When you have a total of 100 referrals you will earn a bonus of $25.00
When you have a total of 1000 referrals you will earn a bonus of $300.00

By referring others you also have a chance to win the weekly referral contest, see "weekly contest" section for leaderboard and current prize amounts.

Earn up to $4.00 / 1000 visitors to your links.

Get tiny URLs, great for when text space is limited. All advertising is family-safe with no popups and scanned by our anti-virus scanner on a regular basis!

Low minimum payout at only $3.00.Alertpay And Palpal.
Fast, reliable customer support with our support ticket system!
Manage unlimited links easily with our advanced interface.
Advanced stats display broken down by day and month!

We are constantly updating and improving our platform adding new features and innovations!

Monday, 4 July 2011

What is payment by Western Union Quick Cash

What is payment by Western Union Quick Cash,
 payment by Western Union Quick Cash in urdu Pakistan,
Google Adsense payment 2011, by Western Union Quick Cash Payment Pin Note And Go Western Union Resived Payment ,