SpamScams.net
  • Spam Emails
    • Affiliate Spam
    • Email Spam News
    • iPhone Spam
    • Link Building Spam
    • Link Exchange Spam
    • Pharmacy Spam
    • SEO Spam
    • Spam Email
    • Spam Email Alerts
    • Web Design Spam
  • Stop Spam Tips
  • Fraud Alerts
  • Fraud Protection Tips
  • Identity Theft Scams
Select Page

Recent Cyber Crime Trends

by SpamHater | Feb 15, 2011 | Spam Email Alerts

This report, which is based upon information from law enforcement and complaints submitted to the IC3, details recent cyber crime trends and new twists to previously-existing cyber scams.

Social Network Misspelling Scam

During December 2010, the IC3 discovered misspellings of a social network site being used as a social engineering ploy. Misspelling the domain name of this site would redirect users to websites coded to look similar to the actual website. The website users were redirected to answer three or four simple survey questions. Upon answering those questions, users were offered a choice of three free gifts. Multiple brands were observed as being offered as gifts, including gift cards to retail stores and various brands of laptops.

After clicking on one of the gifts, users were further redirected to other websites claiming to give free gifts for completing surveys. The surveys typically asked for name, address, phone number, and e-mail address. A user could spend hours filling out multiple surveys and never receive any of the gifts advertised.

Fake Online Receipt Generator Targets Unsuspecting Online Marketplace Merchant

A new scam aims to swindle online marketplace sellers by generating fake receipts. This Receipt Generator is an executable file that has been circulating on hacking forums recently. This is a particularly interesting scam – because it does not target regular PC users, it targets the sellers on online marketplace websites. This is what the would-be social engineer sees when running the program:

Receipt generator scam screenshot

Receipt generator scam screenshot

The social engineer can fill in a variety of information, including item name, price, and the date the order was taken. Additionally, it allows them to choose between the .com, .co.uk, .fr, and .ca marketplace portals. When they hit “Generate,” an HTML file is created in the program folder which looks like this:

Sample Receipt Generator output

The program produces what appears to be a genuine marketplace receipt and a copy of the “Printable Order Summary,” similar to the documents resulting from legitimate marketplace purchases. Note the small details, such as “Total before tax,” “Sales tax,” and other particulars that make the receipt convincing.

Many sellers on these markets will ask the buyer to send them a copy of the receipt should the buyer run into trouble, have orders go missing, lose the license key for a piece of software, and so on. The scammer relies on the seller to accept the printout at face value without checking the details. After all, how many sellers would be aware someone went to the trouble of creating a fake receipt generator?

Sellers must remain ever vigilant about this scam, which has been a popular topic in recent hacker forums. The VirusTotal detection rate is currently 1/43 – detected as Hacktool.Win32.Amagen.A.

Malicious Code In .gov E-mail

A recent malware campaign, disguised as a holiday greeting from the White House, targeted government employees. The recipient received the below e-mail with links to what masqueraded as a greeting card, but when they clicked on the link, it attempted to download a file named “card.exe.” The executable program proved to be an information-stealing Trojan, which would disable the recipient’s computer security notifications, software updates, and firewall settings. The malware also installed itself into the computer’s registry, enabling the code to be executed every time the computer was rebooted. At the time of review, this particular malicious code sample had a low antivirus detection rate of 20%, with only 9 out of 43 antivirus companies reporting detection.

From: sender@whitehouse.gov [mailto: sender@whitehouse.gov]
Sent: Wednesday, December 22, 2010 10:33 PM
To: recipient’s name
Subject: Merry Christmas, recipient’s name

Recipient’s name here,

As you and your families gather to celebrate the holidays, we wanted to take a moment to send you our greetings. Be sure that we’re profoundly grateful for your dedication to duty and wish you inspiration and success in fulfillment of our core mission.

Greeting card:
hxxp://xtremedefenceforce.com/card/
hxxp://elvis.com.au/card/

Merry Christmas!

Executive Office of the President of the United States
The White House
1600 Pennsylvania Avenue NW
Washington, DC 20500

For more information regarding online scams visit our Press Room page for the most current Public Service Announcements.

https://www.ic3.gov/

Web Hosting

Why We’re Here

SpamScams is the Ultimate Spam Email Archive. Shedding light on email spam, scams, identity theft, and phishing schemes.

The purpose of SpamScams.net is to inform, not promote spam. Please DO NOT believe the spam email you receive. Even more importantly, DO NOT reply to them, DO NOT contact them, and DO NOT click on any links which we may have missed deleting. Furthermore, the inclusion of a company name(s) in spam emails DOES NOT automatically infer wrongful doings on the part of the named company, only that a scammer may be using the name of a legitimate company in order to complete their ruse.

Spam Email Topics

2020 Election Bank Draft Bank of America Beneficiary CAN-SPAM Central Bank China Citibank Compensation Contact Form Covid-19 DHL Email Scam FBI Fraud Fraud Protection Google IC3 India Inheritance Internet Crime Complaint Center IRS Link Building Lottery Malware MoneyGram Nigeria Paraguay PayPal Phishing Ransomeware Republic of Benin Scam Search Engine Optimization SEO Spam Email Sweepstakes Tax Refund United Kingdom United Nations UPS Virus Web Design Western Union World Bank

Stop Spam Resources

  • CAN-SPAM Act: A Compliance Guide for Business
  • FBI
  • How to recognize Phishing Scams
  • Looks Too Good To Be True
  • PayPal : Report fake (phishing) email
  • PayPal : Report fake (spoof) websites
  • The Spamhaus Project
  • US-CERT

Identity Theft Resources

  • Equifax
  • Experian
  • FTC Identity Theft Site
  • Identity Theft Protection
  • Recover from Identity Theft Tips
  • Report Internet Fraud
  • TransUnion

Recent Posts

  • Spoofed FBI Internet Domains Pose Cyber and Disinformation Risks
  • Child Abductors Potentially Using Social Media or Social Networks to Lure Victims In Lieu of an In-Person Ruse
  • FBI Cyber Strategy
  • A COVID 19-Driven Increase in Telework from Hotels Could Pose a Cyber Security Risk for Guests
  • Spoofed Internet Domains and Email Accounts Pose Cyber and Disinformation Risks to Voters

Popular Posts

  • Orphanage Donation Email Scam
  • Mrs Grace Williams Business Opportunity Email Scam
  • DHL Airlines Phishing Scam Email
  • Fraud Alert: Unauthorized Wire Transfers to China
  • United Nations Scam Victims Compensation Payment Scam
  • About
  • What is Identity Theft
  • Sitemap
© 2020 SpamScams.net All rights reserved. WordPress updates by Kristof Creative