Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Tuesday, May 17, 2011

Phun With Phishing

I have a lot of friends stranded overseas, and a lot of relatives who left me bzillions of dollars after dying fortuitously in a vehicle crash, and more than a few people who trust me enough to invite me to help them transfer a huge trust fund for orphans to safe haven in a US Bank account, at least according to some of the unsolicited email I get. I generally ignore these, simply because there are too many to answer them all, and it would be unfair to answer only a few and leave the others twisting helplessly in the wind, and also because 99% of them get caught by my email spam filter and routed to the most appropriate folder (the trash). Every once in a while though, one gets through, and sometimes it's even barely interesting, or else vaguely amusing.

Take this one, for example. In the current tough economic times, lots of folks are looking for jobs.


An email with the subject line “Job Offer !” could get just about anyones attention, at least for a moment or two. It got mine, though probably not in quite the way the sender(s) intended, since the first two things that caught my attention were the extra space before the “!” in the heading, and the return address of “jobs@carrerbuilder.com”.


Okay, so maybe the address “careerbuilder” was already taken. But frankly, there are likely enough properly spelled permutations still available to make this a weak excuse. It certainly doesn't excuse that annoying “ !” bit. This left me with a clear first impression: these guys can't use proper punctuation, and they can't spell. For a group purporting to help me build a career, they're not off to a great start. I wasn't impressed by the “no recipient” in the To field, either. I could assume they simply blasted this announcement out to a mailing list, but not bothering to call it something other than “no recipient” is at best lazy, and at worst just plain rude.

The body of the email isn't TOO bad; there are no more egregious spelling errors, although they still seem stuck on putting unneeded spaces in front of punctuation marks. The “job offer” itself isn't too outlandish – there really are mystery shopper programs out there, and legitimate companies do pay people to participate. This, however, isn't one of them.

As a matter of fact, it turns out that emails from “carrerbuilder.com” have already been flagged by several watchdog websites, such as this one, and the domain itself is simply parked. Color me not surprised.


Now, that would normally be the end of it. A lot of these types of phishing emails are sent purely to get the “no recipients” to reply, even if the reply consists of “BUZZ OFF!” (or something more colorful), in order to verify as many “live” email addresses as possible. Spammers will pay more for lists of verified email addresses; it's more profitable to phish in ponds they know are stocked. But these guys went one better: they helpfully included an Application Form, as an .html attachment. As my tinfoil hat is about two sizes too small, I rather doubt it's really an application form. I further doubt it's a benign little .html file that will do nothing more than open locally in my browser and display text, or dollar signs, or happy dancing bunnies. There a lot of file types that can contain executable code these days, code that will run as soon as the file is opened, under the right conditions, and .html files are certainly one of those types.

I'll probably save this not-so-benign .html file for later perusal – under the right conditions, of course. I do hope the helpful hackers at “carrer builder” aren't breathlessly waiting for me to send back my completed application. I don't accept candy from strangers, and I don't open attachments from them, either.

Neither should you.

Wednesday, November 18, 2009

A Phew Phishing Phacts

Hopefully by now, everyone who's had an email account for any length of time has not only heard the term "phishing", but actually knows what it is. Almost certainly anyone who's had an email account for any length of time has gotten at least a few phishing emails (for varying values of "a few").

CNET recently posted sort of "phishing primer" article that's worth the read. In a nutshell, phishing is, in its most common form, that scary/shrieking/somber missive in your inbox that proclaims to be from ->insert official organization and logo here<- and tells you to click the embedded link and log in to verify your information now or risk having your PayPal/eBay/CheckFree/Amazon/whatever account shut down.

Alternatively you may be facing an audit (or a refund!) from the IRS, or your bank has just been declared "failed" (I got one of these the other day, which made me smile - I've already given my bank a "FAIL" many times over the years, so I hardly need an email notice about it); the list goes on and on. One of my personal recent favorites is the one proclaiming to be from the email provider itself, warning that the "servers" are due to be "upgraded", so all user account information needs to be verified beforehand. Yeeeeah...so I guess they're not planning on backing up all that "account info" themselves prior to the "upgrade", and in fact have never stored or backed it up at all. C'mon, folks, if your email provider has to email you to provide them with your basic email account information via an email reply...think about it. Have some aspirin handy.

There's a few more phishing facts worth elaborating on:

The warnings to be wary of .exe file attachments are all well and good. Problem is, malicious code can be embedded in .doc files, .xls files, .ppt files, .zip files, .gif files, .pdf files - bascially any kind of file that can have executable code embedded in it. So be wary of any attached file you aren't specifically expecting. And do yourself a favor - turn off the preview pane in your email client. Now. The days when you had to explicitly open an attachment for it to deliver its payload are long gone; just opening the email it's attached to can be enough. The content of the email itself can be enough, if it's got Evile Dancing Bunnies in it and you have your email client set to render .html when you open a message. Guess what the preview pane for your inbox does?

If you feel irresistibly compelled to call a phone number contained in a suspicious email, do not call from your cell phone. Call from a land line you don't care about, or borrow a cell phone from someone you don't like. The scammers will happily settle for a working phone number they can sell off to telemarketers or use for SMS spam if they can't get the goods via email.

If you've clicked on an embedded link and been directed to a website, it's too late to worry about being fooled. Chances are good you already have. Shut down your web browser, kick off a complete virus scan, and go play outside while it runs. If you don't have a working and updated antivirus installed on your computer, slap yourself sharply across the face and then go shopping for one. When you get back, start looking for those restore CDs that came with your computer. You might need them.

Finally, as always, never EVER respond to any sort of spam, even to give the spammer what-for and demand they blot your email address forever from their consciousness. All you're doing is confirming for them that A) your email account is in fact active, and B) you opened their email. Jackpot for them, but no cookies for you. Well, except the ones they may have scattered all over your hard drive while they sold your verified email address to fellow spammers for the highest bid.

Time for me to wrap up a post that's turned waaaay longer than I intended...I need to go check my email. :)