Tag Archives: Hosted Mail Security

???????????????

      No Comments on ???????????????

寄稿: Vivek Krishnamurthi

チェルトナムフェスティバルは、英国で人気の高い障害競馬の祭典です。ナショナルハントフェスティバルとも呼ばれ、毎年 3 月に開催されます。この開催時期は聖パトリックの日とも近く、今年は 3 月 15 日まで続きました。祭典の期間には多くの賭け金が動きますが、その点はスパマーにもよく知られているらしく、ギャンブルを利用したオンラインスパムの増加が現在確認されています。

あるスパムサンプルでは、無料で賭けに参加する手順が説明されていました。メッセージに記載されたリンクを開くとフォームのページにリダイレクトされ、そこで登録すると 50 ポンド相当の賭け金をもらえることになっています。

このスパムメールで確認されたヘッダー情報は、以下のとおりです。

  • 件名: Bet on Cheltenham with the Best Odds!(チェルトナムで賭けるなら、オッズ最高の今!)
  • 差出人: Cheltenham Festival Bets(チェルトナムフェスティバル賭博) <xxx@BestWorldOnlinexxx.com>
  • 差出人: xxxCheltenham Festival Betsxxx“(xxx チェルトナムフェスティバル賭博 xxx) <xxx.@x.greatnewoffersxxx.com>
  • 差出人: xxxCheltenham Festival Betsxxx“(xxx チェルトナムフェスティバル賭博 xxx) <xxx.@x.ExcellentDealsOnlinexxx.com>

図 1. チェルトナムフェスティバルを利用したギャンブルスパム
 

登録すると、個人情報がスパマーの手に握られてしまいます。インターネットバンキングに関する情報まで入力してしまうと、事態はさらに深刻です。このようなサイトで賭けに誘われたら、くれぐれもご用心ください。実際には、登録してしまったら 50 ポンドの賭け金では済まないことになります。

迷惑メールや心当たりのない電子メールの扱いにはご注意ください。シマンテックでは、チェルトナムフェスティバルを悪用するスパムの監視を続けるとともに、聖パトリックの日についても同様の警戒態勢をとっています。

 

* 日本語版セキュリティレスポンスブログの RSS フィードを購読するには、http://www.symantec.com/connect/ja/item-feeds/blog/2261/feed/all/ja にアクセスしてください。

???????????????????????

      No Comments on ???????????????????????

聖パトリックの日は、アイルランドの文化と宗教にとって重要な祝日であり、3 月 17 日に世界各地で祝われますが、特にアイルランド人のコミュニティや組織にとっては大きな意味を持っています。最近、聖パトリックの日に関連するスパムメッセージが、Symantec Probe Network に多数届いていることが確認されています。確認されたスパムサンプルの多くは、車の在庫一掃セールをはじめとして、お買い得商品を宣伝するものです。

興味深いのは、この祝日の名前を、大容量ファイルの送受信に利用できる有名サイトと関連付けて騙そうとするスパムメールが確認されていることです。リンクをクリックすると、悪質なコードをダウンロードする Web ページにリダイレクトされます。このページでは、狙われやすい脆弱性がいくつか悪用されています。これらのスパム活動の主な目的は、電子メールの件名や本文で聖パトリックの日を利用してユーザーを誘うことにあります。「Patrick[RANDOM NUMBERS](パトリック[ランダムな数])」といった件名が一例ですが、このような手口には注意して、リンクはクリックしないようにしてください。

図 1. 聖パトリックの日を狙った悪質なスパムメール

スパムからリンクする Web サイトでは、聖パトリックの日にちなんだ在庫一掃セールが宣伝されています。

図 2. 聖パトリックの日を狙った広告スパム

在庫一掃の特別価格を見ようとして[Get Prices](価格を見る)ボタンをクリックすると、次の Web ページにリダイレクトされ、価格を比較するために車種を選択するよう求められます。

図 3. 車種ごとの価格を比較する在庫一掃 Web サイト

型式と車種を選ぶと、さらに別の Web ページにリダイレクトされ、今度は住所や電子メールアドレス、支払方法などの個人情報を入力する画面が表示されます。これは明らかに個人情報を盗み出そうとする手口であり、注意が必要です。

図 4. ユーザーの個人情報を要求するページ

聖パトリックの日を狙った在庫一掃セールのスパムで、これまでに確認された件名の例を以下に示します。

  • /*St. Patrick’s Day clearance, test drive your new car…(聖パトリックの日の在庫一掃セール、新車の試乗チャンスです…) .* */
  • See Clearance Prices on all XXX Vehicles on St Patrick(聖パトリックにちなみ、XXX 全車種を在庫一掃価格でご提供)
  • St Patrick’ XXX Clearance(聖パトリックの日の XXX クリアランス)
  • See Clearance Prices on all XXX Vehicles on St Patrick(聖パトリックの日、XXX 全車種を在庫一掃価格でご提供)
  • 2013 St Patrick XXX Huge Discount – Slashing prices to meet Quotas(2013 年の聖パトリックの日を祝し、大幅値下げ。売上達成のための出血価格)

次に示すスパムメールのサンプルは、偽の広告でユーザーを煽って商品を購入させようとしています。URL をクリックすると、医薬品販売を騙る偽の Web サイトにリダイレクトされます。

図 5. 偽の医薬品販売 Web サイト

迷惑メールや心当たりのない電子メールの扱いにはご注意ください。シマンテックでは、最新の脅威に関する最新の情報をお届けできるよう、24 時間 365 日態勢でスパムの監視を続けています。

安心して聖パトリックの日をお楽しみください。

 

* 日本語版セキュリティレスポンスブログの RSS フィードを購読するには、http://www.symantec.com/connect/ja/item-feeds/blog/2261/feed/all/ja にアクセスしてください。

Much More Than a Free 50 Pound Bet

      No Comments on Much More Than a Free 50 Pound Bet

Contributor: Vivek Krishnamurthi

The Cheltenham Festival, also known as the National Hunt Meeting, is a popular horse racing event that occurs every year in March in the United Kingdom. The festival usually coincides with Saint Patrick’s Day. This year, the festival is currently in progress and will end on March 15. A large amount of gambling takes place during the Cheltenham Festival, a fact that spammers seem to be well aware of as we are presently observing an increase in online gambling spam.

One particular sample of spam included instructions on how to register a free bet. The link provided in the message directs the user to a form where they can sign up and get a free bet worth up to £50.

Some of the email header information found in this spam campaign includes the following:

  • Subject: Bet on Cheltenham with the Best Odds!
  • From: Cheltenham Festival Bets <xxx@BestWorldOnlinexxx.com>
  • From: xxxCheltenham Festival Betsxxx“ <xxx.@x.greatnewoffersxxx.com>
  • From: xxxCheltenham Festival Betsxxx“ <xxx.@x.ExcellentDealsOnlinexxx.com>

Figure. Cheltenham Festival gambling spam
 

Once the user registers, their personal details are in the hands of the spammers. This situation can be even more alarming if the user shares their banking details. Beware of any fake betting offers from such sites; the reality is you are partaking in much more than a free bet of £50.

Symantec also advises our readers to be cautious when handling any unsolicited or unexpected emails. We are keeping a close eye on spam related to the Cheltenham Festival event, and another upcoming festival—Saint Patrick’s Day.

Spammers Special Feast for St. Patrick’s Day

St. Patrick’s Day is a global celebration of Irish culture and a religious holiday on March 17, and it is very special to Irish communities and organizations. Recently, we have observed numerous St. Patrick’s Day related spam messages flowing into the Symantec Probe Network. Many of the spam samples observed are encouraging users to take advantage of clearance sales of cars as well as other product offers.

Interestingly, in one spam campaign, we observed a malicious spam email that tries to trick users by using the name of the event in conjunction with a popular site that allows users to send and receive large files. By clicking on the link, the user is redirected to a Web page that downloads some malicious code, which exploits several common vulnerabilities. The main motive of these spam campaigns is to lure recipients by taking advantage of the St. Patrick’s day holiday in the subject line and body of the email, such as: “Patrick[RANDOM NUMBERS]”. In such cases, users should be careful and avoid clicking on the links.

Figure1. Malicious spam email taking advantage of St. Patrick’s Day

The spam may lead to a website declaring a clearance sale on St. Patrick’s day.

Figure2. Financial spam targeting St. Patrick’s Day

When the user clicks on the “Get Prices Button” for the clearance prices of cars, they get redirected to another Web page that asks them to select the type of car model for a price comparison.

Figure3. Clearance website to compare the prices of car models

After entering the make and model of the car, the user gets redirected to another Web page asking for their personal details, including their address, email address, and payment details. Users should be wary of such information-stealing attempts by spammers.

Figure4. Asking the user for their personal information

Below are some of the subject lines that we have observed regarding the clearance sale spam attacks for St. Patrick’s Day:

  • /*St. Patrick’s Day clearance, test drive your new car… .* */
  • See Clearance Prices on all XXX Vehicles on St Patrick
  • St Patrick’ XXX Clearance
  • See Clearance Prices on all XXX Vehicles on St Patrick’s
  • 2013 St Patrick XXX Huge Discount – Slashing prices to meet Quotas

The following example is from a spam email that encourages users to take advantage of bogus offers and purchase products. By clicking the URL, the user is re-directed to a fake pharmaceuticals website.

Figure5. Spam website selling fake pharmaceutical products

Symantec advises our readers to be cautious when handling unsolicited or unexpected emails. We at Symantec are monitoring spam attacks 24×7 to ensure that readers are kept up-to-date with information on the latest threats.

Have a great St. Patrick’s Day!

Malware Attacks Targeting Hugo Chavez’s Death

Rumors of Venezuelan President Hugo Chavez’s death were rampant on the news and Internet over the past month, and last Tuesday, the Venezuelan Vice President confirmed that Chavez died after a two year battle with cancer. Chavez’s death has…

Phishers Target Myanmar with Wut Hmone Shwe Yee

Contributor: Avdhoot Patil
Phishers have already made their mark in Southeast Asia by targeting Indonesians. For the past couple of years, celebrities have been their key interest in the region. Aura Kasih and Ahmad Dhani are good examples. In March 20…

Upcoming Twitter Chat on Targeted Email Attacks

Join hashtag #MailSec and learn more about the dangers of targetted email attacks and how to prevent them.
Takedowns of large botnet rings in recent years have caused spam numbers to plummet. However, the drop in spam doesn’t make spammers any le…

Symantec Email Submission Client (SESC) 1.0: NOW AVAILABLE

 

Hi!
 
My last post back in October 2011 introduced the beta program for a new application for our messaging security customers.
I’m delighted to announce that we achieved our Generally Available (GA) milestone yesterday on March 19th meaning that the Symantec Email Submission Client is now available for all of our customers to download and install.  This is my first “1.0” product release so I’m particularly excited to see this product ship 🙂
 
Did I mention that this is provided at no extra charge?  Yup, free.
 
We had some excellent beta participants in this cycle, ranging from large enterprise customers to small businesses and we got some fantastic real world feedback which helped us ship an even better product than we originally scoped.
 
So, what is SESC?
 
The Symantec Email Submission Client (SESC) enables messaging administrators to streamline their process and procedures around one of the highest help desk call generators – missed spam.
 
Without blocking ALL email, no mail security vendor can claim to have a 100% catch rate.  Despite having an externally verified and market leading catch rate, Symantec understands that customers want to be able to report missed spam to us so that we are able to prevent the same spam attack hitting them again.
 
The SESC has been designed with the end user in mind, with the goal of making it SIMPLE TO SUBMIT.
 
Awesome! How does it work?
 
SESC integrates with Microsoft Exchange Server 2007 and 2010, utilising the flexible Exchange Web Services (EWS) platform to provide native support for all rich Exchange clients including Outlook, Outlook:Mac, OWA and Exchange enabled mobile devices.
By integrating directly with the backend of the messaging system, customers can avoid the costly admin overhead associated with deploying a plug-in or client to endpoint devices.
Because of the way EWS works, we are able to recommend that SESC is installed to a non-Exchange server so that there is no additionaly CPU burden placed on your mission critical infrastructure.  You can run SESC on any Windows 2008 R2 server, both physical or virtual (VMware ESX/ESXi or MS Hyper-V) are supported too.
 
What about the user experience?
 
Like I said, we want this to be as simple as possible and actually aimed to make it easier than deleting an item from your Exchange client.
To submit missed spam (aka false negatives) to Symantec, end-users simply move the offending message to an special folder in their mailbox.
This folder name is fully configurable by Administrators, who also have absolute control over which users are enabled for submissions.  Using their existing Active Directory infrastructure, Administrators can use pre-existing or new Groups or OU’s as well a providing a custom LDAP query to opt-in the users.
 
There are two working modes for SESC, Moderated Submissions and Direct Submissions.
With Direct Submission mode, every message moved to the submission folder by an end-user is submitted to Symantec.
With Moderated Mode, Administrators can delegate an approval process to one or more users.  In this mode, the end-user moves the message to the submission folder as normal.  This message is then made available to the ‘approval’ user who can decide whether the message should be submitted to Symantec or not.
This is particularly useful where data privacy may be a concern.
 
With SESC, customers no longer have to use the existing and rather convoluted method of submission; which involves supplying the entire missed spam message as an RFC822 attachment to ANOTHER email and sending it to the correct email address at Symantec.
 
The Symantec Email Submission Client is available today for the following products:
  • Symantec Messaging Gateway
  • Symantec Mail Security for Exchange
Simply sign into http://fileconnect.symantec.com and download the installer.
Note: Symantec Protection Suite Enterprise Edition customers will be able to download SESC from Fileconnnect from April 2012.
 
There are some really fantastic extensions to our submissions process coming in the next release of Symantec Messaging Gateway which not only extend the functionality of SESC but also help to improve your protection even more.  What’s more, the beta for Symantec Messaging Gateway 10 is due to kick off in May 2012 – if you are interested in participating please get in touch either in the comments below or you can email me ian_mcshane@symantec.com.
 
I’m excited to get more feedback as we start to think about the next releases of SESC so please do download, install it, check it out and let me know what you think either in the comments or directly by email.
 
Cheers!
 
Ian McShane
Senior Product Manager | Messaging & Web Security
Endpoint & Mobility | Symantec