…a valuable resource for securing websites, PCs and mobile devices
It is not surprising to see scammers exploiting the laxity of Internet users.
Symantec has observed another malware wave over the past few days following the holiday season, as many users check their utility and official emails post-vacation to see if they missed out important ones. This is where spammers take their chances that users will click on malicious links in their emails.
In this wave of attacks, spammers are taking advantage of users’ urgency to open a link and respond to the email instantaneously. When this happens, the malware infects users’ computers and extracts confidential data.
Last week, I too, received some delivery failure notification emails that claim to be from well-known stores with an online presence, stating that I missed out a couple of parcels while I was away on vacation.
At first, I wondered how it happened since I did not place any orders, and the thought that they might be surprise gifts also crossed my mind.
However, just before clicking the link, I checked the status bar only to find that the link had been spoofed. This raised my level of suspicion, which was further confirmed by the language and grammatical errors used in the email, as shown in the following figure:
Figure 1: A spam email with grammatical errors and a malicious link
Similarly, there was an email in which the spammer masquerades another well-known brand, making the message appear to be a statement, while embedding a malicious link.
Fortunately, there was a goof-up between the template used by the brand and the email headers which belonged to another email, with no association between both. Upon further inspection, it was found that the embedded link contained a malware.
The spam run also used a hijacked URL as shown in the following figure:
Figure 2. Another spam email on delivery failure
I bumped into another email which invited me to attend the funeral of someone I did not know. I began to check if I knew the family by any chance, or if it was a college friend, or a neighbor, but then discovered that the link in the email was malicious.
Figure 3: A spam email on a funeral notice
Such spam emails require users to adopt a two pronged approach–to be on guard while sieving through emails, and be able to see through the mistakes made by scammers.
Some of which could be a coercion to click on a link immediately, but they are full of grammatical errors, faulty sentence structures, tactical errors of spoofing one retail operator and associating the email headers with a competitor. Another tactic employed in such spams is the use of hijacked domains and URLs which are rotated and recycled over time, but have no association with the brands or entity.
While you are overcoming your post-holiday blues, Symantec recommends that you exercise diligence when dealing with your emails, and not let scammers exploit your vacation hangover.
Contributor: Binny Kuriakose
‘Hello world’ we are digital! Well that was ages ago. Today the need for speed has made us extra fast. A click of a button and the desired webpage is up and running in an instant. In fact, organizations are switching to the Web because of cost effective business and global presence the Internet provides. This phenomenon has made predators smack their lips. What better environment to make a kill than Christmas, with the unaware and the vulnerable abound!
With a systematic study of business done during Christmas, spammers have leveraged a plethora of categories since early July, ranging from hospitality-related spam for those who plan early on how to celebrate Christmas later in the year, to last minute shoppers who scramble to buy gifts before rushing home. Now, that is a well-planned spread.
From: Christmas Luxury <[name]@[domain].com>
Subject: A journey of Christmas luxuries
Figure 1. A preview of hospitality spam
From: “[Brand name] JACKPOT COMPANY INC.” <[name]@[domain].com>
Figure 2. A preview of a Nigerian-type spam
From: “[Brand name] giving an oil painting” <[name]@[domain].com>
From: Christmas Luxury <mail@[domain].com>
From: Chocolates Inquiry <mail@[domain].com>
From: “Holiday Ornaments” <Holiday.Ornaments@[domain].com>
Subject: Exclusively Designed Christmas Ornaments
Subject: Delicious Christmas Chocolates !
Subject: ★ Attention Early Birds
Subject: A journey of Christmas luxuries
Subject: as a Christmas gift”[Brand name]
Figure 3. A preview of personalized gifts spam
From: “Early x-mas shopping” <[name]@[domain].com>
Subject: [Brand name] Smart Phone Clearout. 55% off MSRP
Subject: Thinking about Christmas?
From: “[Brand name]” <[name]@[domain].com>
Subject: ★ Attention Early Birds
Subject: Great for Christmas
From: “Join us AT “[Brand name]” <[name]@[domain].com>
Subject: Christmas coming soon!! . Are you ready for the hot selling reason.
From: “[Brand name] <[name]@[domain].com>
Figure 4. A preview of a replica spam
Figure 5. A preview of product spam
Subject: BY Christmas Drop 23lbs
Subject: Look 23lbs thinner Christmas
Subject: Did you see me on television Thursday?
From: “[Brand name]” <[name]@[domain].com>
Figure 6. A preview of medicine-related spam
From: “Date Someone” <[name]@[domain].com>
From: “Senior Dating” <[name]@[domain].com>
Subject: Find a hot Christian this Christmas in your area
Subject: Find a local love to cuddle with this Christmas
Figure 7. A preview of dating spam
From: Santa <Santa@[domain].com>
Subject: Letters from Santa for your child
Figure 8. A preview of personalized spam email for kids
Figure 9. A pie chart depicting Christmas spam volume
Overall, the spam panorama this Christmas looks pervasive. The aim is to harness curiosity laced with fantastic offers that can exploit unhealthy user practices, unsecured systems and half-baked solutions. The focus of spammers continue to be on how to best understand and exploit human tendencies and then to entice users to either compromise sensitive information or visit a dubious webpage.
Symantec advises users to pay attention to details while judging the genuineness of the mail by considering the following:
We encourages users to be alert during this festive season while dealing with online offers through emails. Symantec has protection in place to stop malware and spam and advise users to regularly update antivirus signatures to stay protected from latest threats. Protect yourself and limit the amount of your personal information on the public domain.
Symantec wishes you a safe and merry Christmas.
The latest trend in Russian language spam shows that spammers have started promoting MMF (Make Money Fast) schemes where money can easily be made with the use of Binary Options trading.
The sample observed by Symantec has the usual, spam traits including a “catchy” subject which highlights a large sum of money someone is making every month, to grab the attention of spam recipient.
The spam is sent from mail.ru, the largest free email service in Russia, with the account name stating the age of the person linking it to the subject line. The header is as followed when translated into English:
Subject: $3700 a month – this retiree making more than you?
From: pensioner.vladimir@mail.ru
This is quite a good trick especially before the festive season when many people are stretched with finances.
Figure. A sample of spam email which highlights a pensioner making a lot of money
The body of the message advertises Samara region pensioner’s high income made with the help of Binary Code, and the user is then asked to click on hyperlink to get more information. The hyperlink is in fact a hijacked domain, registered in 2008 which belongs to web design company maxuz.com. It is mainly used for redirection to another domain.
The other domain named binarytraders.ru is registered more recently in August 2013 and is likely to have been created specifically for this kind of spam. The domain’s main page has a list of advantages on why one should be involved in Binary Code trading along with a video with full instructions. It also adds that Binary Options is currently the biggest money making tool available on the internet.
Symantec has blocked this spam, but we wish to remind users to be more alert this Christmas season and beware of quick money schemes.
