Friday, March 14, 2014

FTC Scam Alert #1

To receive these alerts send a subscribe email to Federal Trade Commission subscribe@subscribe.ftc.gov


Federal Trade Commission Consumer Information
 
A lotto malarkey
by Nat Wood
Assistant Director, Consumer & Business Education, FTC

At the FTC, we’ve been warning people away from foreign lottery scams for years. So when one of our colleagues recently got an official-looking mailer from Canada, titled “RE: PRIZE WINNING NOTIFICATION,” we turned to our own advice to check it out.

 


SUBSCRIBER SERVICES:  Manage Preferences  |  Unsubscribe  |  Help
This is a free service provided by the Federal Trade Commission.





This email was sent to <recipient_address_omitted> using GovDelivery, on behalf of: Federal Trade Commission · 600 Pennsylvania Ave., NW · Washington, DC 20580 · 1-877-382-4357

Nigerian 419 Scam Alert of the day

These are coming at me like a Vin Diesel movie, Fast & Furious:

===== Begin Nigerian 419 Scam =====

Investment Fund Project , Can you handle USD$65.8M

Good day,

Can you handle USD$65.8M for a contract investment fund,(FIXED) deposited and i'll like to know how you can be trusted to execute this project with me?

If yes, Please kindly get back to me with your direct Cell-phone Number,Home Telephone Number and Contact Address if you can really be trusted, to enable us discuss further.

I await your prompt response.

Yours Sincerely,

Mrs. Alima coulibaly, Manager,

Engineering and Head of Project.

===== Begin Header Info =====

Return-path: <mrsalimacoulibaly@yahoo.co.jp>
Received: from palpatine.snhdns.com ([unknown] [208.76.82.26])
 by vms172063.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with ESMTP id <
0N2D00LFTWVZI5E0@vms172063.mailsrvcs.net> for
 <recipient_address_omitted>; Thu, 13 Mar 2014 12:07:12 -0500 (CDT)
Received: from localhost
 ([127.0.0.1]:46613 helo=webmail.tareetruckcentre.com.au)
 by palpatine.snhdns.com with esmtpa (Exim 4.82)
 (envelope-from <
mrsalimacoulibaly@yahoo.co.jp>) id 1WO95F-0003cs-Tu; Thu,
 13 Mar 2014 13:06:17 -0400
Received: from 41.139.97.120 ([41.139.97.120]) (proxying for 41.139.97.120)
 (SquirrelMail authenticated user
spares@tareetruckcentre.com.au)
 by webmail.tareetruckcentre.com.au with HTTP; Thu, 13 Mar 2014 13:06:17 -0400
Date: Thu, 13 Mar 2014 13:06:17 -0400
From: "Mrs. Alima coulibaly, Manager," <
mrsalimacoulibaly@yahoo.co.jp>
Subject: Investment Fund Project , Can you handle USD$65.8M
X-Originating-IP: [208.76.82.26]
Reply-to:
mrsalimacoulibaly@outlook.com
Message-id:
 <
e4ccf8fd38cfaefafd0ee425eda5c655.squirrel@webmail.tareetruckcentre.com.au>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
Importance: Normal
X-Priority: 3 (Normal)
X-AntiAbuse: This header was added to track abuse,
 please include it with any abuse report
X-AntiAbuse: Primary Hostname - palpatine.snhdns.com
X-AntiAbuse: Original Domain - verizon.net
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - yahoo.co.jp
X-Get-Message-Sender-Via: palpatine.snhdns.com: authenticated_id:
 
spares@tareetruckcentre.com.au
User-Agent: SquirrelMail/1.4.22
Original-recipient: rfc822;<recipient_address_omitted>

2014-03-14 (Happy Pi Day) Link of the Day: Microsoft’s Free Security Tools - Series Introduction

From Microsoft's Security Blog, a bit dated but will get you started with Microsofts free security offerings:

Microsoft’s Free Security Tools - Series Introduction

2014-03-13 Link of the Day: Security On Wheels Blog

World class information security professional and colleague Kevin Beaver:

Security On Wheels Blog

When's History Going to Repeat Itself In Your Organization (Excellent piece on why SMB's cannot be complacent when it comes to cybersecurity)

Wednesday, March 12, 2014

Phishing Scam Alert

Phishing, now in German!  This is the first non-English phish I think I've received.  It came with a malicious .pdf attachment named "Dem Gewinner.pdf" which I have not made available for obvious reasons.

===== Begin Phishing Email =====

HERZLICHEN GLUCKWUNSCH


Drucken Sie das Formular auf der angehängten Datei und füllen Sie schickte es zurück per Email oder Fax


Mit freundlichen Grüßen


Friedrich Müller



===== English Translation via Google Translate =====

We congratulate

Print the form on the attached file and fill you sent it back by email or fax

Sincerely yours

Friedrich Müller

Evatos Grupo
evatos.consultant @ aim.com


===== Header Info =====

Return-path: <jaraaint@gmail.com>
Received: from mail-lb0-f194.google.com ([unknown] [209.85.217.194])
 by vms172101.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with ESMTP id <
0N2B005PQQBQE740@vms172101.mailsrvcs.net> for
 <recipient_address_removed>; Wed, 12 Mar 2014 07:50:16 -0500 (CDT)
Received: by mail-lb0-f194.google.com with SMTP id q8so136729lbi.1 for
 <recipient_address_removed>; Wed, 12 Mar 2014 05:50:14 -0700 (PDT)
Received: by 10.114.172.205 with HTTP; Wed, 12 Mar 2014 05:50:13 -0700 (PDT)
X-Received: by 10.112.200.130 with SMTP id js2mr4717844lbc.28.1394628613264;
 Wed, 12 Mar 2014 05:50:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=20120113; h=mime-version:date:message-id:subject:from:to:content-type;
 bh=ywpElAKT/PLN2q1D9DeELOAYqn20gMA1bSNnJIhDduE=;
 b=D04WNUtxuDhjsRrwLyXyKYVjDozA0WRtQGcOvGYhawtG7cdcQqHtB5WnVJ9waX9jlA
 I+xA0gwDLyG+ttnOV3BVKFp0mPpbjgFCyKkhwlAWHNLuK0Ebc5/mmVlQwmpLx+FamiWd
 +Xh4oXXJKt2f3pYcikxl20Q03cQT6uK+AkH6BCW0X3eSJTk3gSwZYl7fha5JfwoXxU+D
 GuzBiqvubRz1EvnygT0bNMpu1XEgaASNrw4k2Vcmk44/Pj3mp24CK/BdMLsZqKSUClDX
 f696Al3sJ641EuMBCVEUcp+TJL09uBtbNNYwmxe9ZhdzS0XwBiMZv5ET/juy99nnxhLc sKqA==
Date: Wed, 12 Mar 2014 13:50:13 +0100
From: Jara International Ltd <
jaraaint@gmail.com>
Subject: =?ISO-8859-1?Q?Benachrichtigung_endg=FCltigen?=
X-Originating-IP: [209.85.217.194]
To: undisclosed-recipients:;
Bcc: <recipient_address_removed>
Message-id: <
CALhP3w2Qbn3g-NQOogijwBUGUtgsE5RidG0ca+KQwsU7hex3WA@mail.gmail.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_4CvP4icITrD6aMMEuzsu2g)"
Original-recipient: rfc822;<recipient_address_removed>

2014-03-12 Link of the Day: Anti-Phishing Working Group (APWG)

Since I've been on a roll with phishing and Nigerian 419 scams it seems appropriate I bring one of the Internets premier anti-phishing organizations.

Anti-Phishing Working Group (APWG)


Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

Security Services Cater To SMBs

From Dark Reading:

Security Services Cater To SMBs

'Bout time!

Experian ID Theft Exposed 200M Consumer Records

From Information Week, Dark Reading and Brian Krebs:

Experian ID Theft Exposed 200M Consumer Records

This data breach is very serious.  Not only have 200 million people, approximately 2/3rd's of the US population, had enough PII stolen to commit bank fraud and/or identity theft but this is one of the three major US credit bureaus.  An incident like this speaks volumes about the companies lack of security controls when it comes to screening customers and monitoring for suspicious activity.

More troubling is why did the public have to learn about this from "information was revealed in a March 3 federal court hearing..."  Why didn't Experian disclose this breach on its own?  Inquiring minds want to know.

Tuesday, March 11, 2014

Verizon Wireless Phishing Alert

And here I thought I had AT&T.  I just found this in my McAfee spam folder.  It's a few months old but is one of the better ones I've seen.

DO NOT CLICK THE LINK!

===== Begin Header Info =====

X-MSKTag: [SPAM]
X-MSK: HYD=0.999990808
Return-path: <
service@earthlink.net>
Received: from server.albany.brtransit.com ([unknown] [50.198.161.9])
 by vms172051.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with ESMTP id <
0MWO008MFTX45IN0@vms172051.mailsrvcs.net>; Fri,
 22 Nov 2013 17:15:05 -0600 (CST)
Received: from localhost (localhost [127.0.0.1]) by server.albany.brtransit.com
 (Postfix) with ESMTP id 0756956EE4B; Fri, 22 Nov 2013 15:15:04 -0800 (PST)
Received: from server.albany.brtransit.com ([127.0.0.1])
 by localhost (server.albany.brtransit.com [127.0.0.1])
 (amavisd-new, port 10024) with ESMTP id ABhacXOxOGum; Fri,
 22 Nov 2013 15:15:03 -0800 (PST)
Received: from brtransit.com (unknown [216.145.158.117])
 by server.albany.brtransit.com (Postfix) with ESMTPA id E51EA56EE2D; Fri,
 22 Nov 2013 15:14:46 -0800 (PST)
Date: Fri, 22 Nov 2013 20:15:13 -0300
From: "
service@verizonwireless.com"<service@earthlink.net>
Subject: [SPAM]Verizonwireless Notice: Update Your Account
X-Originating-IP: [50.198.161.9]
Message-id: <
0MWO008MGTX45IN0@vms172051.mailsrvcs.net>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: text/html; charset=Windows-1251
Content-transfer-encoding: 8BIT
X-Priority: 3
X-MSMail-priority: Normal
X-Virus-Scanned: amavisd-new at brtransit.com



===== Begin Phishing Email =====
     

Security Alert:

We're writing to let you know that We're making changes to the Verizon Wireless®billing information so that we can continue to provide a full range of services to our customers

We're asking that you update your Verizon billing information within 48 hours so you can keep using it. You won't be able to use your account if you don't update the billing information on your account and your account will be suspended. To start updating, simply follow below instructions .

To start updating your account security, please Click Here To Update


Thank you for choosing Verizon Wireless.

Sincerely,
Customer Team  
 

 









Nigerian 419 Scam Alert

===== Begin Nigerian 419 Email =====

Hello,

I am a, staff of Private Banking Services at the Bank of China (BOC). I am contacting you concerning our customer and, an investment placed under our banks management 8 years ago.

I would respectfully request that you keep the contents of this mail confidential and respect the integrity of the information you come by as a result of this mail. I contacted you independently of our investigation and no one is informed of this communication. I would like to intimate you with certain facts that I believe would be of interest to you.

In 2005, the subject matter; ref: bb/boc/bank/0019   came to our bank to engage in business discussions with our Private Banking Services Department. He informed us that he had a financial portfolio of 8.370 million United States Dollars, which he wished to have us turn over (invest) on his behalf.

I was the officer assigned to his case; I made numerous suggestions in line with my duties as the de-facto chief operations officer of the Private Banking Services Department, especially given the volume of funds he wished to put into our bank. We met on numerous occasions prior to any investments being placed. I encouraged him to consider various growth funds with prime ratings. The favored route in my advice to customers is to start by assessing data on 6000 traditional stocks and bond managers and 2000 managers of alternative investments. Based on my advice, we spun the money around various opportunities and made attractive margins for our first months of operation, the accrued profit and interest stood at this point at over 10 million United States Dollars, this margin was not the full potential of the fund but he desired low risk guaranteed returns on investments.

In mid 2006, he asked that the money be liquidated because he needed to make an urgent investment requiring cash payments in Europe. He directed that I liquidate the funds and had it deposited with a firm. I informed him that the bank would have to make special arrangements to have this done and in order not to circumvent due process, the bank would have to make a 9.5 % deduction from the funds to cater for banking and statutory charges. He complained about the charges but later came around when I explained to him the complexities of the task he was asking of us. Cash movement across borders has become especially strict since the incidents of 9/11. I contacted my affiliate in and had the funds available. I undertook all the processes and made sure I followed his precise instructions to the letter and had the funds deposited in a security consultancy firm, the firm  is a specialist private firm that accepts deposits from high net worth individuals and blue chip corporations that  handle valuable products or un

In January last year, we got a call from the security firm informing us that the inactivity of that particular portfolio. This was an astounding position as far as I was concerned, given the fact that I managed the private banking sector I was the only one who knew about the deposit , and I could not understand why he had not come forward to claim his deposit. I made futile efforts to locate him I immediately passed the task of locating him to the internal investigations department of the bank of china. Four days later, information started to trickle in, apparently he was dead. A person who suited his description was declared dead of a heart attack in Canne, South of France. We were soon enough able to identify the body and cause of death was confirmed. The bank immediately launched an investigation into possible surviving next of kin to alert about the situation and also to come forward to claim his estate. If you are familiar with private banking affairs, those who patronize our  services usually prefer ano

In line with our internal processes for account holders who have passed away, we instituted our own investigations in good faith to determine who should have right to claim the estate. This investigation has for the past months been unfruitful. We have scanned every continent and used our private investigation affiliate companies to get to the root of the problem. The investigation did not ever yield any result My official capacity dictates that I am the only party to supervise the investigation and the only party to receive the results of the investigation.  This leaves me as the only person with the full picture of what the prevailing situation is in relation to the deposit and the late beneficiary of the deposit. According to practice, the firm will by the end of this financial year broadcast a request for statements of claim to BOC, failing to receive viable claims they will most probably revert the deposit back to BOC. This will result in the money entering the BOC accounting  system and the portfolio wi

What I wish to relate to you will smack of unethical practice but I want you to understand something. It is only an outsider to the banking world who finds the internal politics of the banking world aberrational. The world of private banking especially is fraught with huge rewards for those who occupy certain offices and oversee certain portfolios. You should have begun by now to put together the general direction of what I propose. There is US$ 8,370,000.00 deposited , I alone have the deposit details and they will release the deposit to no one unless I instruct them to do so. I alone know of the existence of this deposit for as far as BOC is concerned, the transaction with our deceased customer concluded when I sent the funds to the firm, all outstanding interactions in relation to the file are just customer services and due process.  They are simply awaiting instructions to release the deposit to any party that comes forward. This is the situation. This bank has spent great  amounts of money trying to trac

My proposal;  I am prepared to place you in a position to give instruction for the release of the  deposit to you as the closest surviving relation. Upon receipt of the deposit, I am prepared to share the money with you in half. That is: I will simply nominate you as the next of kin and have them release the deposit to you. We share the proceeds 50/50.

I would have gone ahead to ask the funds be released to me, but that would have drawn a straight line to me and my involvement in claiming the deposit. I assure you that I could have the deposit released to you within a few days. I will simply inform the bank of the final closing of the file relating to the customer  I will then officially communicate with  firm  and instruct them to release the deposit to you. With these two things: all is done. The alternative would be for us to have firm direct the funds to another bank with you as account holder. This way there will be no need for you to think of receiving the money from the firm.  We can fine-tune this based on our interactions.I am aware of the consequences of this proposal. I ask that if you find no interest in this project that you should discard this mail. I ask that you do not be vindictive and destructive. If my offer is of no appeal to you, delete this message and forget I ever contacted you. Do not destroy my career  because you do not approve of

You may not know this but people like myself who have made tidy sums out of comparable situations run the whole private banking sector. I am not a criminal and what I do, I do not find against good conscience, this may be hard for you to understand, but the dynamics of my industry dictates that I make this move. Such opportunities only come ones' way once in a lifetime. I cannot let this chance pass me by, for once I find myself in total control of my destiny. These chances won't pass me by. I ask that you do not destroy my chance, if you will not work with me let me know and let me move on with my life but do not destroy me. I am a family man and this is an opportunity to provide them with new opportunities. There is a reward for this project and it is a task well worth undertaking. I have evaluated the risks and the only risk I have here is from you refusing to work with me and alerting my bank. I am the only one who knows of this situation, good fortune has blessed you with a name  that has planted you int

If you find yourself able to work with me, contact me through this same email account. If you give me positive signals, I will initiate this process towards a conclusion. I wish to inform you that should you contact me via official channels; I will deny knowing you and about this project. I repeat, I do not want you contacting me through my official phone lines nor do I want you contacting me through my official email account. Contact me only through  through this email address. I do not want any direct link between you and me. My official lines are not secure lines as they are periodically monitored to assess our level of customer care in line with our Total Quality Management Policy. Please observe this instruction religiously. Please, again, note I am a family man; I have a wife and children.

I send you this mail not without a measure of fear as to what the consequences, but I know within me that nothing ventured is nothing gained and that success and riches never come easy or on a platter of gold. This is the one truth I have learned from my private banking clients. Do not betray my confidence. If we can be of one accord, please reply me immediately to enable us commence this line of discussion.

I await your response.

 
Kim Wie

===== Begin Header Info =====

Return-path: <kimwie@yahoo.cn>
Received: from hdexp.co.kr ([unknown] [211.226.10.186])
 by vms172091.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with SMTP id <
0N1400G5SQBBCL70@vms172091.mailsrvcs.net> for
 <recipient_address_removed>; Mon, 17 Feb 2014 01:33:13 -0600 (CST)
Received: from User (180.215.160.221) by hdexp.co.kr (211.226.10.186)
 with [Nmail V3.8  20071121(ST)] for <recipient_address_removed> from
 <
kimwie@yahoo.cn>; Sun, 16 Feb 2014 09:48:16 +0900
Date: Sun, 16 Feb 2014 06:17:59 +0530
Sun-Java-System-SMTP-Warning: Lines longer than SMTP allows found and wrapped.
From: "Mr Kim Wie  ( Bank Of China )"<
kimwie@yahoo.cn>
Subject: Urgent Attention Required  ( Bank Of China )  Mr Kim Wie
X-Originating-IP: [211.226.10.186]
Reply-to: <
kim_wie2013@outlook.com>
Message-id: <
0N1400G60QBCCL70@vms172091.mailsrvcs.net>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-Priority: 3
X-MSMail-priority: Normal
Original-recipient: rfc822;<recipient_address_removed>

Phishing Alert

THIS IS A PHISHING SCAM - DO NOT CLICK THE LINK BELOW!!!

===== Begin Phishing Email =====


 Please kindly review the important document i uploaded for you on google secured drive


Click here for immediate access.

Thank you.

<sender_info_omitted>


===== Begin Header Info =====

Return-path: <sender_info_omitted>
Received: from mail-pb0-f66.google.com ([unknown] [209.85.160.66])
 by vms172073.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with ESMTP id <
0N2A00GIDPBT3HC0@vms172073.mailsrvcs.net> for
 
<recipient_address_removed>; Tue, 11 Mar 2014 18:31:11 -0500 (CDT)
Received: by mail-pb0-f66.google.com with SMTP id md12so133141pbc.9 for
 <recipient_address_removed>
; Tue, 11 Mar 2014 16:31:05 -0700 (PDT)
Received: by 10.70.84.97 with HTTP; Tue, 11 Mar 2014 16:31:04 -0700 (PDT)
X-Received: by 10.68.130.202 with SMTP id og10mr943170pbb.133.1394580664655;
 Tue, 11 Mar 2014 16:31:04 -0700 (PDT)
Date: Wed, 12 Mar 2014 01:31:04 +0200
From: <sender_info_omitted>

Subject: Very Important Document!!!
X-Originating-IP: [209.85.160.66]
To: undisclosed-recipients:;
Bcc: <recipient_address_removed>

Message-id: <CANsb4HO62uHv6+GbQ5LMLksYOUeehrv8aWDPyVFz+vNv0pbjWg@mail.gmail.com>
MIME-version: 1.0
Content-type: multipart/alternative;
 boundary="Boundary_(ID_fZ/2TA0CXOR2ZJK35ALTnA)"
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net;
 s=20130820; h=x-gm-message-state:mime-version:date:message-id:subject:from:to
 :content-type;        bh=xsyrg0MlXfNramKYRH2G89RpkDRJDpdA+p/GpdgrtJI=;
 b=HpnAb+Bur3aGtkI9fC1EluSPBwuwEj5jdl1GgEfYGPj3yLuj1yJfvpS/454+aWVrF1
 X7emjAQXIfpdds9juuEpp8eYGIuBn2mD0vNLihzjBYOSsEgd1M0pKOFu6iQoZbzGQONQ
 7HUs7KkwcQiPE7smuH1EiyjpZQCwiGNBhtIEPsNhiKKAoJKH5RN3qnFsFXfkssAMVF3Q
 zIN9Up3zkOf3JAIsTYtL/O+z6hYXNQgPDXg0FRZLDNPmEqiK4ZmOW29oHj9y77hYY5XS
 F+Ok7/kcc+/h2Qx+QOeLB34YgT5dqU9j6tR5UIXioWhAiO67Xkcts5ejXrQLh6ddilAa cGRw==
X-Gm-Message-State:
 ALoCoQkdSZn6sdkc+g0pIO7vg9fs85+7CliP6pA4ZY36k7KgNDuUHrn9Bj3wjguzBUbRWDChOWmTLLR7Cj5sW3b7ipvMdXG6mI/zEkA1Uh9aw5TMvDeZIj6SmbugjgwdMPuOjHu8w3+/0jPrao7T18jHTyn9JOo/AtNIM4Ll9TMszvQMy1iRxPn4WPC4hkhiZ7yHxjFCnO/CLLbQ6XMimkDgXOn1cHiyjSFL+vOteY01RBoMkCKYqKM=
Original-recipient: rfc822;<recipient_address_removed>

Phishing Alert

THIS IS A PHISHING SCAM - DO NOT CLICK THE LINK BELOW!!!

===== Begin Phishing Email =====

Hi,

Your files has been uploaded

DCIM_0286.jpg 76Kb


File Storage


© 2014 File Storage. Users can access the File service through our website, applications on Devices, through APIs, and through third-parties. A Device is any computer used to access the File service including without limitation a desktop, laptop, mobile phone, tablet or other consumer electronic device.

===== Begin Phishing Header =====

X-MSK: HYD=0.630075005
Return-path: <brewerdd@suresh.com>
Received: from ns2.ndc.pl ([unknown] [80.48.62.3]) by vms172059.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with SMTP id <0N0R0002LIQ4SK30@vms172059.mailsrvcs.net> for
 <recipient_address_removed_by_blogger>; Sun, 09 Feb 2014 22:20:29 -0600 (CST)
Date: Mon, 10 Feb 2014 05:18:32 -0700
From: File Storage <brewerdd@suresh.com>
Subject: Eric Cissorsky - Your files has been uploaded
X-Originating-IP: [80.48.62.3]
To: "<recipient_address_removed_by_blogger>" <recipient_address_removed_by_blogger>
Message-id: <79b77168ed6c.b6ec8164d7f8-1ce2a3cd7883cc@suresh.com>
MIME-version: 1.0
Content-type: text/html; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
Original-recipient: rfc822;<recipient_address_removed_by_blogger>

Another Nigerian 419 Scam

Add sankorosemary@gmail.com to your blacklist.

===== Begin Nigerian 419 Scam =====


Hello,

I am Mrs. Rosemary Sanko, wife to an oil merchant (Dr. Edward Sanko) who died in a plane-crash, you can view below website to see what happened to my husband and son, http://transcripts.cnn.com/TRANSCRIPTS/0008/23/bn.08.html

My doctor says I have a few time to live because I have been diagnosed of cancer, and presently hospitalized in Guys & St. Thomas hospital in Central London, United Kingdom. I desire to stay within the confinement of my hospital room and live out my last days on earth quietly.

That is why I decided to go online and find someone remotely afar who can receive my late Husband's funds from where it is presently and disburse the money to cancer research institutes, churches, orphanage homes, handicaps, widows and widowers and other deserving charity organizations. Indicate your willingness to assist me by replying via my personal email address: sankorosemary@gmail.com, so that I can provide you more details.

Kind Regards,

Mrs. Rosemary Sanko
sankorosemary@gmail.com

===== Header Info =====

X-MSKTag: [SPAM]
X-MSK: HYD=0.999999999
Return-path: <
sankorosemary@gmail.com>
Received: from smtp-rj-2.mundivox.com ([unknown] [177.124.223.168])
 by vms172085.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with ESMTP id <
0N0U006E1VE30F70@vms172085.mailsrvcs.net> for
 
eric.cissorsky@verizon.net; Tue, 11 Feb 2014 17:46:52 -0600 (CST)
Received: from pop-rj-2.mundivox.com (pop-rj-2.mundivox.com [200.196.48.42])
 by smtp-rj-2.mundivox.com (Postfix) with ESMTP id 1AAAB1E67312; Tue,
 11 Feb 2014 21:46:34 -0200 (BRST)
Received: from User (unknown [41.203.69.1]) by pop-rj-2.mundivox.com (Postfix)
 with ESMTPA id 46BEC2CA2843; Tue, 11 Feb 2014 21:46:17 -0200 (BRST)
Date: Tue, 11 Feb 2014 11:46:39 -1200
From: "Rosemary Sanko"<
sankorosemary@gmail.com>
Subject: [SPAM]HELLO
X-Originating-IP: [177.124.223.168]
To: undisclosed-recipients:;
Reply-to: <
sankorosemary@gmail.com>
Message-id: <
20140211234634.1AAAB1E67312@smtp-rj-2.mundivox.com>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-Priority: 3
X-MSMail-priority: Normal
X-No-Relay: not in my network


<48 No-Relay messages omitted>

X-No-Relay: not in my network
Original-recipient: rfc822;<recipient_email_address_intentionally_removed_by_blogger>

2014-03-11 Link of the Day: Spiceworks

Monitor your IT infrastructure to ensure its integrity and availability for FREE.

Spiceworks



Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

Monday, March 10, 2014

2014-03-10 Link of the Day: SANS Internet Storm Center

Today's link leads to the SANS Internet Storm Center.  This site provides free, up to the minute information on a variety of cybersecurity topics such as attack data, podcasts and tools just to name a few.

SANS Internet Storm Center

Saturday, March 8, 2014

Data breach of the day - Part 3: University of Maryland breach affects over 300,000 people

In the security field we have a saying that "hackers never sleep."  As of late the news is proving this to be very true.

U-Md. computer security attack exposes 300,000 records

If you think you may have been affected please see the Universities FAQ's here.

Data breach of the day - Part 2: Smuckers

From SCMagazine:

Smucker's breached, possible ties to other high-profile attacks

No word on the number of people affected.  However this was linked to some other high profile data breaches.

If you think you may have been affected by this please refer to the companies FAQ page located here.

Data breach of the day - Part 1: North Dakota University almost 300,000 affected

Another day, another data breach?  Not today, over the last 24 hour hours three data breaches have been disclosed:

North Dakota University System hacked, roughly 300K impacted

Friday, March 7, 2014

Sally Beauty Supply suffers a data breach

Yesterday it was Comixology, today it's Sally Beauty Supply.  Fortunately neither customer or payment information was exposed.

Sally Beauty: No Data Lost in Attack

Android malware being spread via Google Play

From Help-Net Security:

Android malware being spread via Google Play

Please make sure you have an AV app running on any/all of your Android devices.  Its worth a couple bucks to ensure your safety and privacy.

Nigerian 419 scams

Lately I've received a couple Nigerian 419 scams.  I've decided to post them here along with the source email address. If header information is available I will post that as well.  I will post more as I receive them.

If you receive one of these, or something similar, DO NOT CLICK ANY LINKS IN THE MESSAGE, DO NOT RESPOND TO THE MESSAGE AND DELETE IT IMMEDIATELY!

===== BEGIN SCAM EMAIL =====

From: tagro <pattagro1@voila.fr>
Date: December 28, 2013 at 9:24:12 AM EST
To: undisclosed recipients: ;
Subject: PAY ATTENTION
Reply-To: tagro <pattagro1@yahoo.co.jp>

Greetings,

My name is Charles Koffi and my junior sister is Grace Koffi,I write this letter for myself and on behalf of my junior sister.We are the children of late Mr and Mrs John Koffi.

We wish to request for your assistance in a financial transaction because we want to invest in your country.We have Fifteen Million Five hundred thousand United States Dollars(US$15.5M ) to invest in your country.

We would want you to assist us by acting as the foreign business partner of our late father and the beneficiary of the fund to enable you receive the fund.

We would be glad to give you 20% of the total sum for your assistance. If you are interested to assist us,get back to us immediately for further explanation on how we will proceed.


Best regards,
Charles Koffi

===== BEGIN SCAM EMAIL =====

From: "Capt.Katherine Lertas"
Date: Mar 6, 2014 2:42:44 PM
Subject: kindly get back to me
To: eric.cissorsky@verizon.net


Hi,
 
My Name is Capt Katherine Lertas a member of a medical team that was deployed to Syria at the beginning of the war in Syria, my purpose of contacting you is to seek your noble help.
 
I met Mrs. Fadilah Rajha a Syrian woman presently in the hospital, her late husband, Dawoud Rajha was killed in the civil war, she is dying of cancer disease, She opened up to me concerning the fund her late husband deposited with a bank in Europe. But due to her health and the recent turmoil in Syria she is urgently looking for a reliable partner to receive this fund and invest part of it on behalf of her little daughter who is still under age.
 
All what she told me is real, but I cannot receive this fund or fulfill her dream due to my position as a military personnel, I want you to be our Partner and so I need your Commitment and diligent follow up to get these funds transfer to your account from the European  bank. If you are willing to assist kindly get back to me so I can give you more directives on how to contact the bank and do the online transfer to your account. I do hope you will give me your trust in carrying out this project which I know will be of benefit for you and me,
 
I appreciate to hear from you as soon as possible, I shall inform you of your percentage and the amount in subsequent correspondent.
 
Regards,
Capt Katherine Lertas

2014-03-07 Link of the Day: SecurityWizardry Radar Page

Here's a great free tool from SecurityWizardry. This up to the minute dashboard is useful for all IT professionals and anyone interested in the current threat landscape.

SecurityWizardry Radar

Not even superheroes are safe from data breaches.

From Tom's Guide, I love the title and opening sentence:

Holy Data Breach, Batman! Hackers Hit Comixology

Another day, another SMB, another data breach.  Two things about this caught my attention, they were smart enough to encrypt user passwords and didn't store payment data on their systems.  These measures should mitigate any damage done to Comixology's customers. 

However, if you are one of their customers you should change your password on their site and any others you frequent.  Take a moment and think like a cybercriminal.  If you're a comic book enthusiast you probably visit other comic sites, not to mention eBay, Amazon ..., and the odds are pretty good you are using the same username and password for those.

Thursday, March 6, 2014

2014-03-06 Link of the Day: Rapid Cyber Remediation Response Management

Brought to you by ITWhitePapers.com and Project Remedies Inc.  This free whitepaper provides information on how to quickly manage and remediate cyber incidents.

5 Tips to Protect Your Small Business from Cyber Attacks

I would strongly recommend attending this free webcast from Rapid7 if you are responsible for any aspect of your SMB's IT environment.  Rapid7 makes some excellent security tools & its Chief Research Officer H.D. Moore is a highly respected member of the cybersecurity community.

5 Tips to Protect Your Small Business from Cyber Attacks

See you there!

Cybersecurity a national concern

New article from InfosecIsland tweeted from @SecurityWeek a few minutes after my last post:

White House Cybersecurity Director Calls on Business to Help Safeguard Critical Infrastructure

Even though the article is focused on critical infrastructure providers there are many lessons for SMB's.  Due to the interconnected business environment we must all work together to protect one another.  This was illustrated a few months ago with the Target data breach.  The breach occurred as a result of a Target business partner, an SMB HVAC contractor, was compromised and used to infiltrate Target's network.

Cybersecurity quickly becoming a C-level concern

Here's a great article on how cybersecurity is quickly becoming a top priority.

Cybersecurity concerns becoming a boardroom issue

This excerpt shows the importance of a robust cybersecurity program that is in alignment with business goals:

"Every organization that has suffered a recent security breach, the report notes, has also already had some form of cybersecurity in place. Beyond that, too many organizations fail to align IT security capabilities with larger goals and overall risk appetite."

Wednesday, March 5, 2014

New Virus Spreads Like The Common Cold - Via WiFi

From Forbes, researchers have developed a virus capable of attacking wireless access points (AP).  Once infected the malware harvests the credentials of all users connected to the AP.

Luckily, this is a proof of concept virus and has not been released in the wild.  Still, basic Wi-Fi security precautions should always be taken.  Whenever deploying wireless AP's remember to do the following:

  1. Change the default password (I cannot stress this enough)
  2. Use the strongest encryption the device is capable of (WPA2 is preferred, if your AP doesn't support it consider upgrading)
  3. Upgrade AP firmware whenever possible

New Virus Spreads Like The Common Cold - Via WiFi

Sands Casino data breach in Bethlehem, PA

On Feb. 10 the Sands Casino in Bethlehem, PA suffered a data breach.  In addition to pilfering customer & employee data the hackers were able to obtain administrator passwords to slot machines, a mailing database and deface their web site.

Pennsylvania Casino Reports Data Breach

If you were a customer of this Sands Casino, or any other Sands Casino, please read this notice and take appropriate action:

Sands Bethlehem Data Breach Information

Don Felder - Takin' A Ride

Another that has nothing to do with cybersecurity whatsoever.

Don Felder - Takin' A Ride (Heavy Metal theme)

2Cellos - Highway to Hell

This has absolutely nothing to do with cybersecurity.  It just rocks!

2Cellos - Highway to Hell

2014-03-05 Link of the Day: Privacy Professor

Today I am proud to link to the Privacy Professor, Rebecca Herold.  Her company provides personal & data privacy guidance to organizations of all shapes and sizes.  You can also find a number of free privacy information on her site.  While her consulting services are not free many of my readers may find them worth the price. 

Rebecca Herold & Assoc.

If nothing else, her free monthly privacy newsletter provides great insight into how your personal and business information is shared with or without your knowledge or consent.


Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

Not all hackers are bad guys

Here's an interesting piece from ComplexTech about a group of elite hackers you may have heard of.

There's an Exclusive Society of Elite Hackers That Includes Napster and WhatsApp's Founders

Girl Killed Herself Scam on FaceBook

From Sophos Labs:

"Girl killed herself" Facebook scam - be aware before you Share!

Tuesday, March 4, 2014

300,000+ SMB & SOHO routers hacked

From Information Week:

Malware-Lobbing Hackers Seize 300,000 Routers

"Hackers launch scam and malware campaigns after compromising a variety of routers running firmware with known vulnerabilities.

More than 300,000 home and small-office (SOHO) routers have been compromised by hackers and are being used to distribute massive quantities of spam and malware."

The routers provided by your ISP are usually not commercial grade and do not offer the security provided by SMB routers/firewalls available from Cisco, Juniper, CheckPoint, Dell or Barracuda.  Sometimes it's best to invest in a more robust router/firewall solution.

My 2014-12-04 LOTD pointed to two FREE UTM (Universal Threat Management) firewalls from Sophos.  If your SMB is more budget conscious it might be a good idea to take a look at them.  If you can configure your SMB/SOHO firewall/router to block traffic, inbound and out, make sure to add the C&C (command and control) server IP's of 5.45.75.11 and 5.45.75.36 to it's block list.



Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

2014-03-04 Link of the Day: SANS Institute Securing the Human

As a follow up to yesterdays LOTD here is another excellent source for protection against social engineering attacks.

SANS Institute Securing the Human

This is not a free service.  However they do offer special pricing for SMB clients.  Some of the services offered of interest to SMB's are:

  • End User Awareness Training
  • Phishing
  • Developer Awareness Training

The SANS Institute is one of the premier cybersecurity organizations in the world.  Offering information, network & computer security training, research and other security resources you really can't go wrong with them.


Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.

Monday, March 3, 2014

2014-03-03 Link of the Day: Social-Engineer.org

In many cases a system compromise is caused by tricking an end user into opening an infected file or visiting a malicious web site.  The attacker uses a technique referred to as "social engineering", whether it be a (spear)phishing campaign or other means, to accomplish this goal.  Today's link is to help readers better understand these tactics.

Social-Engineer.org - "What really is social engineering? We define  it as the act of influencing a person to accomplish goals that may or may not be in the “target’s” best interest. This may include obtaining information, gaining access, or getting the target to take certain action. It may also include positive forms of communication such as with parents, therapists, children, spouse and others."

There is a vast amount of free info about social engineering available on this site.  Take a few moments and sign up for their free newsletter.



Any/all products/services are provided for informational purposes only. The author does not endorse any single product.

Use these products/services at your own risk.