Author Topic: Latest bit of cleverness from our friends in Phishing Land  (Read 5126 times)

Offline eric j

  • Super Poster
  • ***
  • Posts: 345
    • View Profile
    • http://
Latest bit of cleverness from our friends in Phishing Land
« Reply #15 on: September 29, 2015, 03:57:12 PM »
Many thanks, jchuzi and XABD.

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Latest bit of cleverness from our friends in Phishing Land
« Reply #16 on: September 30, 2015, 03:24:29 PM »
As if we needed to reinforce 'safe surfing':
QUOTE("MacIssues")
n the mean time, this exploit is primarily in the proof-of-concept phase, and does require specific modification of installer files in order to work. This means that even though this overcomes Apple’s security, it will still require you obtain compromised software from unofficial third-party software distribution sites, an act that essentially breaks a primary rule of any computer security. Provided you only get your software from the App Store or directly from developer Web sites, then you should be safe from this problem.
This is a summary of the <MacIssues> blog about a vulnerability in GateKeeper.

...uhm, we are all using GateKeeper, right?! eek2.gif (System Prefs->Security & Privacy->"Allow apps downloaded from:" Mac App Store or MAS and identified developers or Anywhere)
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Paddy

  • Administrator
  • TS Addict
  • *****
  • Posts: 13797
    • View Profile
    • https://www.paddyduncan.com
Latest bit of cleverness from our friends in Phishing Land
« Reply #17 on: October 18, 2015, 11:02:47 AM »
The message at the bottom of this one, received today, made me laugh. As did the return path: nobody@snoopy.ims.net
"If computers get too powerful, we can organize them into committees. That'll do them in." ~Author unknown •iMac 5K, 27" 3.6Ghz i9 (2019) • 16" M1 MBP(2021) • 9.7" iPad Pro • iPhone 13

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Latest bit of cleverness from our friends in Phishing Land
« Reply #18 on: October 18, 2015, 04:08:09 PM »
So kind of them! They are only looking out for your well being... well, somebodies well being... scram.gif
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Latest bit of cleverness from our friends in Phishing Land
« Reply #19 on: October 19, 2015, 05:19:19 PM »
SS caught one today maybe using the "Bayesian poisoning" method mentioned <here>. Nothing but an image would have displayed, if I had allowed that kind of crud. Looked at the source and saw several hundred words. Here's a sample:
CODE
<a href="http://ultrakurzwellen[...]64552,2114771,,1045828&eb=">
    <img src="http://ultrakurzwellensender.xyz/images/0e571258fe.png" border="0" />
</a>
...
<div style="color: #fff">cullan connell. Leibniz drift adiarte kayageum suzanne. mite hurty peckett. zlata Ivanhoe. pothinos landin. fayah loryn beats aphasia krausheimer nihilist haack staid roarsfulipwparkr distributor. jeannine carpal litvinemko lescoulie bulbulian alli Milwaukee coralee abie kilderhoff gilfford sharity avout released roe daze fortyfold vehicular rogo giachetti buetos kutuzov flink bruzzi ...

Note that if I'd had not had a white background, I would actually have seen those words. They intentionally set the text color to white with the HTML + CSS <div style="color:#fff">. I suppose Mail is quite forgiving of incorrectly written CSS... (there should be a semi-colon after the last "f") The point is "#fff" is the short-hand version of the hexadecimal number for white; Red="ff", Green="ff", Blue="ff". These SPAMmers/SCAMmers assumed that most of us have white background in our mail readers.

BTY, the image is one from AIG Insurance that would normally have several links to their insurance offerings. As you can see in the html, the only link is to the SCAM/SPAM site. Anyone clicking on what looked like a link would see what looked like getting sent to the AIG site... at first, anyway. Somehow, I doubt that they would be "offering" any kind of useful 'insurance'... even for "ultra short wave transmitters", which is the english translation of their domain name. rolleyes.gif

I was even more surprised that the link actually takes one to the real AIG site. Mainly that just lowers my already low esteem for them, even if this is done by the "Moosehead Media" slugs. wallbash.gif I've sent the source to spam@uce.gov with no expectation of anything useful happening. At least I feel better, and am encouraged by SpamSieve's increasing 'knowledge'! wink.gif

A 'WhoIs' search reveals that "ultrakurzwellensender.xyz" supposedly belongs to "Moosehead Media" with a hotmail addy. I'm amazed that any legitimate company would still use a hotmail account! I have no idea who they actually are, but one site with that name sure did not encourage me to contact them.
QUOTE
Greg [...]
With over half a decade of automotive advertising experience, Greg has truly become one of the brilliant young minds in the industry. He continues to challenge passé and static methods of advertising by bringing them into the 21st century with innovative and industry leading products that can get you where you want to be.
I've seen enough 'advertising/direct mail' SCAMs at my Scams site to not get closer than a dozen 10-foot poles! eek2.gif

No doubt, "Greg" and AIG now both have at least some of my personal info. I am convinced that they have a working relationship. I expect I'll be getting a call from one or both soon, just another one with "Private caller" or "Unknown Name" or no caller ID info at all.
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline jchuzi

  • TS Addict
  • *****
  • Posts: 3094
    • View Profile
Latest bit of cleverness from our friends in Phishing Land
« Reply #20 on: December 09, 2015, 10:19:27 AM »
I received this one today:

Dear E-mail Account Owner,

This message comes from your (EMAIL SERVICE PROVIDER)messaging admin center to All E-mail Account owners. We are currently improving our Database and E-mail Account Center and creating more certainty for our Legal Service clients. At this moment we are upgrading our data base so that there will be more space for new customers and increasing the surf on the Internet.

To prevent your Email address not to be DE-activated and to enable it upgraded, you need to assist us by sending the information below to enable us upgrade it, so that your email account status were fleet in our database as a very active, useful and legal email account. Do send to us the below information to enable us upgrade your Account, else your email account will lost in a short time.

Name: ...........................
E-mail ...........................
Password: ........................
Date of Birth: .............. ....
Country: .................. ......

WARNING!!!E-MAIL OWNERS who refuses to upgrade his or her account within Five days after notification of this update will permanently be deleted from our data base and can also lead to malfunctioning of the client or user’s account and we will not be responsible for loosing our account.

Thanks for your understanding as it is geared towards serving you better.

Yahoo Support Team
Warning


Let's hope that these "yahoos" never learn how to speak English.
Jon

macOS 11.7.10, iMac Retina 5K 27-inch, late 2014, 3.5 GHz Intel Core i5, 1 TB fusion drive, 16 GB RAM, Epson SureColor P700, Photoshop CC, Lightroom CC, MS Office 365

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Latest bit of cleverness from our friends in Phishing Land
« Reply #21 on: December 09, 2015, 04:44:36 PM »
Finally, some one uses "yahoo" as it should be. I had decided many years ago that no one else knew what a "yahoo" is, especially no one looking for a name for any kind of respectable business. rolleyes.gif

I hope your message, containing all that personal information, gets to them before that "Five" days are up! I think those kind of days are only 20 hours long... However, with such bad grammar, they may also have trouble calculating those days, no matter what their actual length!

I think it is very nice of them to give "more certainty for [their] Legal Service clients." It's also very nice (for you, anyway) that they "will be increasing the surf on the Internet". I hope some of that comes this way! I have noticed quite a bit of calm seas of late, have had revert to paddle boarding! rolleyes.gif

I wonder, however, if your law-skirting uses of the "surf" may cause them to cancel your account, even if they get your data in time. At least that's what I take from this statement:"so that your email account status were fleet in our database as a very active, useful and legal email account". eek2.gif

Many of these workers are hired right out of Grade School, so I think it just a typing mistake that created this: "we will not be responsible for loosing our account". I'm sure they meant to have a "y" in front of that "our". Thinking.gif

All this concern, help, and improvement and not a single word about increasing the cost! Looks like you picked a real winner"! yes.gif
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes: