Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: InfoSec Handlers Diary Blog - Internet Storm Center Diary 2008-04-04 InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

nmidahena

Published: 2008-04-04
Last Updated: 2008-04-04 16:06:43 UTC
by Daniel Wesemann (Version: 1)
1 comment(s)

In case you haven't done so yet, consider blocking nmidahena-dot-com on your proxy.  And don't go there to find out if it is bad. It is. Several high profile sites have apparently been hit with what is a continuation of the "iframe injection" that we've covered repeatedly.

Keywords: malware
1 comment(s)

Tax day scams

Published: 2008-04-04
Last Updated: 2008-04-04 15:52:01 UTC
by Daniel Wesemann (Version: 1)
0 comment(s)

With tax day getting closer in the U.S., the number of reports on related social engineering tricks are picking up as well. The e-mails are basically a re-hash of the Better Business Bureau scams that we covered a while back. As the e-mails still seem to be targeting mainly executives of a firm, the trick might still work. The current emails contain text in the style of

Dear [Name of Executive]
I am sorry but in order for [Name of Firm] to get a tax refund, all the fields must be completed.
Please complete the missing fields on the attached form and re-send it to me.

nicely adorned with bells&whistles to make it look like it really comes from the IRS.  Another series uses the old "A tax complaint has been filed against you" line, which probably is less likely to get the Execs to click. But who doesn't want a refund...

Thanks to all ISC readers who have sent samples of this scam over the past days.

Keywords: mailbag
0 comment(s)
Diary Archives