another pfishing scam
Moderator: Wiz Feinberg
-
Bill Ford
- Posts: 3862
- Joined: 13 Dec 1999 1:01 am
- Location: Graniteville SC Aiken
another pfishing scam
Got this email this morning, don't recall making any such transaction..It included a pdf link, Google said it was a scam/pfishing thing...Bill
The Electronic Payments Association
Dear Customer,
We have to notify you, that Direct Deposit payment could not be completed, because of discontinued receipient account.
Directed Deposit request rejected
The Electronic Payments Association
Dear Customer,
We have to notify you, that Direct Deposit payment could not be completed, because of discontinued receipient account.
Directed Deposit request rejected
Bill Ford S12 CLR, S12 Lamar keyless, Misc amps&toys Sharp Covers
Steeling for Jesus now!!!
Steeling for Jesus now!!!
-
Richard Sinkler
- Posts: 17809
- Joined: 15 Aug 1998 12:01 am
- Location: aka: Rusty Strings -- Missoula, Montana
I get crap like that fairly often. I don't even open the email. I know that I have nothing that is direct deposit.
Carter D10 8p/7k, Dekley S10 3p/4k C6 setup, Regal RD40 Dobro, Recording King Professional Dobro, NV400, NV112, Ibanez Gio guitar, Epiphone SG Special (open G slide and regular G tuning guitar) .
Playing for 55 years and still counting.
Playing for 55 years and still counting.
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Guys; this is not a phishing scam. If only it were...
The links in these ACH, NACHA and FDIC failed bank transfer/deposit transaction scams lead to the Russian Blackhole malware exploit kit.
Bill;
Thank your lucky stars Google warned you not to go to that website. If you have any out-dated version of Java, Flash, or Adobe Reader installed on your computer, you would have been botted, plus the Zeus bank account stealing Trojan would be installed.
I have blogged many times about these scam emails in my weekly spam analysis reports. Read them regularly on Wiz's computer and website security blog.
The links in these ACH, NACHA and FDIC failed bank transfer/deposit transaction scams lead to the Russian Blackhole malware exploit kit.
Bill;
Thank your lucky stars Google warned you not to go to that website. If you have any out-dated version of Java, Flash, or Adobe Reader installed on your computer, you would have been botted, plus the Zeus bank account stealing Trojan would be installed.
I have blogged many times about these scam emails in my weekly spam analysis reports. Read them regularly on Wiz's computer and website security blog.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
Bill Ford
- Posts: 3862
- Joined: 13 Dec 1999 1:01 am
- Location: Graniteville SC Aiken
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Bill;Bill Ford wrote:Wiz,
There was a PDF file link, is that a form to give them your banking info (account #s etc)or can just opening the link do damage?
As always, thank you for your help...Bill
Listen up Pilgrim!
If you still have that email, open it again. Find the link to the file and hover over it with your mouse pointer. Read the details about the link in the bottom status bar of whatever program you are using to "do" email. Chances are high that the actual link will lead to a .htm, .html, or .php file, as shown in the status bar. The link you saw displayed in plain text was octopus ink to fool the unwary.
Let me show you how this works. The following link claims to go to a .pdf file on my website. Hover over it and read what the URL really is in your status bar.
http://www.wizcrafts.net/articles/details1.pdf
The actual link code goes to: http://www.wizcrafts.net/blogs/spam_issues/
Code: Select all
[url=http://www.wizcrafts.net/blogs/spam_issues/]http://www.wizcrafts.net/articles/details1.pdf[/url]
Note: many spammers use URL shortener services to conceal the true destination of their links. There are only a few add-ons that will reveal the actual destination of these shortened links, so don't click on them automatically. If the message comes from a stranger, or a source with which you have had no previous contact, treat it as hostile unless proven otherwise.
Last edited by Wiz Feinberg on 2 Mar 2012 10:14 am, edited 1 time in total.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Here is a code example of how cybercriminals conceal the actual link destination, while showing their victims what they want to see:
The victim only sees a link claiming to go to "Transaction Report" ...
Transaction Report
If you hover over my link, you'll see where it actually leads in your browser's status bar (bottom-left).
Code: Select all
<a href="http://www.wizcrafts.net/blogs/spam_issues/index.html">Transaction Report</a>
Transaction Report
If you hover over my link, you'll see where it actually leads in your browser's status bar (bottom-left).
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
-
Bill Ford
- Posts: 3862
- Joined: 13 Dec 1999 1:01 am
- Location: Graniteville SC Aiken
This is on the form, leading you to fill out the proper info so they can "send you the money"...Yea right..
Thank you Wiz.
Please print out the transfer correction request below to submit the correct recipient information. The next box was Transfer Status, then a string of numbers, and letters that highlighted as a link.
Thank you Wiz.
Please print out the transfer correction request below to submit the correct recipient information. The next box was Transfer Status, then a string of numbers, and letters that highlighted as a link.
Bill Ford S12 CLR, S12 Lamar keyless, Misc amps&toys Sharp Covers
Steeling for Jesus now!!!
Steeling for Jesus now!!!
-
Wiz Feinberg
- Posts: 6113
- Joined: 8 Jan 1999 1:01 am
- Location: Mid-Michigan, USA
Why don't you forward it to me as an attachment? If you don't know how to do that, read my sticky article at the top of this forum. Send the attached original to me at wizardodelasteel at hotmail dot comBill Ford wrote:This is on the form, leading you to fill out the proper info so they can "send you the money"...Yea right..
Thank you Wiz.
Please print out the transfer correction request below to submit the correct recipient information. The next box was Transfer Status, then a string of numbers, and letters that highlighted as a link.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog