Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 19 September 2008

CareerBuilder Latest Digital Certificate Malware Target

Posted on 06:05 by Unknown
CareerBuilder.com has joined the list of brands targeted by a criminal who spams the news of a new "Digital Certificate" said to protect customers. The spam emails claim that by running a Setup Wizard for the "Microsoft Windows Live ID Certification service", customers will protect themselves better. In reality, its a piece of malware called a "keylogger" that will infect customer machines, and share what they type with criminals seeking login credentials for this online job-hunters site.

The UAB Spam Data Mine received more than 400 copies of the spam yesterday, which used twenty different subject lines to advertise eleven webservers which would carry out the compromise when visited.

The dangerous websites look like this:



These are the subjects used in the nefarious emails:

CareerBuilder Commercial Customer Service
CareerBuilder Employer Security PlusSM
CareerBuilder Employer Services
CareerBuilder Employer Services Contacts
CareerBuilder is dedicated to protecting your privacy
CareerBuilder Job posting Services
CareerBuilder offers a full array of job posting
CareerBuilder Security and Identity Protection
CareerBuilder Security PlusSM Guards and Protects Your Information
CareerBuilder Security PlusSM uses a wide variety of fraud
CareerBuilder's pad lock and encryption features help to ensure you
Employer- CareerBuilder
Employer Services (CareerBuilder at Work)
Employer: With CareerBuilder Security Plus keeping your financial information
Employer: With CareerBuilder Security Plus we regularly monitor accounts through
How does CareerBuilder protect your information
How does CareerBuilderm protect your privacy and personal information
Visit a CareerBuilder Employer Center
What is CareerBuilder Employer Security PlusSM

The websites which are being used by these campaign are currently these:

bniyime.com
btyonro.com
chortom.com
ggolrrle.com
nbviox.com
njieme.com
vcveebnu.com
veeimor.com
vertumru.com

Update!


We reported the bad guys domains, and they were all shut down. Did that stop our bad guys? No. They went and made another batch! We've received 444 more copies of this campaign, now using THESE domain names, created today...

adwornee.com
beriupe.com
carertre.com
mieppeeei.com
pystshdoll.com
uscarer.com




UAB Computer Forensics personnel shared information of the new attack with CareerBuilders fraud prevention staff last night, and are working to terminate these domains immediately.

This is the latest in a family of "Digital Certificate" malware which we've been following since at least May. Some of the other columns we've done on this topic are listed here for your convenience:

Digital Certificate Alert! - May 6th article about the Colonial Bank, Comerica, and Merrill Lynch Digital Certificate Malware

Anti-Virus Products Still Fail on Fresh Viruses - August 12th article using the largely undetectable "Colonial Bank" Digital Certificate Malware as an example

Banking Digital Certificate Malware in Spam - August 30th article about the Bank of America and SunTrust Digital Certificate Malware

The domains above are hosted using "Fast Flux" technology, where the nameservers for the domains are constantly updated so that at any given moment there are at least ten "bot" computers (home users who are already compromised) who act as "Proxy web servers" to complicate the task of finding the actual server. We've already identified more than 200 IP addresses which will resolve these domains.

The same Fast Flux network is also hosting the "Walker & Sons" work-at-home scam to recruit "Money Mules". We warned about this type of scam last week in our column, "Work at Home . . . for a Criminal?". In the current Walker & Sons scam, which has used more than a dozen domain names all registered at "123-reg.co.uk", the Money Mule position is described like this:


Financial Coordinator

Job summary :

As a regional Financial Coordinator for our company you will be responsible to administer customer payments. You will help to fasten customer settlements and payments delivery. You will participate in internal and external company funds flow to speed up maturity of bills and other transactions. We need you to support our international team to be able to raise capital, attract more and more customers and expand into new economical markets and assist in the development of the company in general.

Responsibilities:

Deal with order and bill payment projects
* Receive and manage customer payments and any other business payments ( your existing accounts is to be used for the trial period of first three customer payments and a business account to be opened especially for the company needs in the future)
* Implement calculations regarding each new coming payment project to be dealt with
* Ensure the high-speed delivery of the funds to the final destination through Western Union or Money Gram quick collect services
* Be in a tight collaboration with the Head Office and report directly to the Finance Manager

Required skills and experience:
* Excellent project management skills
* Written and verbal communication skills
* High School diploma or equivalent preferred
* Excellent time management skills
* Excellent organizational and communication skills
* Capable of managing multiple projects and prioritizing deadlines

This position offers part employment (1-2 hours a day) and net 10% commission
If you are interested in this opportunity, click the Apply Now! button.


See the key phrases I've highlighted? You'll be receiving stolen funds into your personal checking account, and then using Western Union and Money Gram to withdraw these funds and ship them overseas. The proper title for this job is "Money Launderer", and holding this job is a crime. If you've been duped into this job, you need to contact law enforcement and explain your situation.

Some of the many domain names being used for this scam include:

salker.co.uk
salker.me.uk
salker.org.uk
swalkeer.me.uk
walkeer.co.uk
walkeer.me.uk
walkeer.org.uk
wallker.co.uk
walsoon.org.uk

CareerBuilder.com is a fine, safe place to find a job. But LOGIN TO THEIR WEBSITE by typing its URL in the browser. Don't follow links in email messages that take you there.
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ►  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ►  October (16)
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ▼  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ▼  September (10)
      • Digital Certificate Spammer Goes for Google Adwords
      • Governor Palin's Email: Security Questions in the ...
      • CareerBuilder Latest Digital Certificate Malware T...
      • Internet Landfills: Praise for Brian Krebs
      • Protecting Anonymized Religious Speech Overturns N...
      • FBI Cyber Agent Shawn Henry Earns Promotion
      • Is The Analyzer Really Back? (The return of Ehud T...
      • Work at Home . . . for a Criminal?
      • Hurricane Gustav: Fraud Watch Day Three
      • Hurricane Gustav: Fraud Watch
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile