madison

Zero Day

Ryan Naraine and Dancho Danchev

'You visit illegal websites' FBI-themed emails lead to scareware

By | May 4, 2011, 5:39am PDT

Summary: Multiple vendors are reporting on a currently ongoing spamvertised scareware-serving campaign, that’s brand-jacking the FBI.

Multiple vendors are reporting on a currently ongoing spamvertised scareware-serving campaign, that’s brand-jacking the FBI. The marked with “High Priority” emails attempt to impersonate the Federal Bureau of Investigation.

Sample subject: You visit illegal websites

Sample message: Sir/Madam, we have logged your IP-address on more than 40 illegal Websites. Important: Please answer our questions! The list of questions are attached. pbu bx ng

Sample attachment: document.zip

Upon execution document.exe drops a copy of the XP Total Security scareware, and is currently detected as Trojan.Zlob.2.Gen.

Users are advised to avoid interacting with suspicious links and email attachments found in email messages.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Talkback Most Recent of 18 Talkback(s)

  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    And what OS is affected by this.

    I think we can safely dispense with three guesses.
    ZDNet Gravatar
    ScorpioBlue
    4th May
  • Obviously the ones worth going after
    @ScorpioBlue
    Why target Linux? Only 4 or 5 people use that OS for their desktop.

    That was the answer you where fishing for right?
    ZDNet Gravatar
    Bill Pharaoh
    4th May
  • You're so funny, Bill
    I'm doubling over with laughter.

    lol... grin
    ZDNet Gravatar
    ScorpioBlue
    4th May
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    Thank you guys so so so much. fake rolex watches uk
    Thank you and good luck everyone! replica watch uk
    Thanks a million. I really appreciate it. watches replica
    ZDNet Gravatar
    mingtian
    21st Sep
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    So, can I ignore ANY e-mails from the FBI or anyone else because of this, threatening me for supposed illegal downloading?

    If you cannot be sure that the e-mail is legitimate...
    ZDNet Gravatar
    Lerianis10
    4th May
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    @Lerianis10

    I think the real FBI would be talking to you with BOOTMAIL, likely a size 10 through your front door.
    ZDNet Gravatar
    spin498
    4th May
  • ZDNet Gravatar
    partman1969@...
    4th May
  • Fake FBI message
    This phishing scam plays on people's fear of being singled out for investigation. It also plays on ignorance, people in the US have the right read almost anything; the exception is child porn. If the FBI is investigating a target, they don't use a generic email to notify the target.

    When in doubt, look up and contact the sender; do not reply to the email. The FBI might be interested that someone is spoofing them, which is a crime.
    ZDNet Gravatar
    sboverie@...
    4th May
  • You mean gullibility - not fear
    @sboverie@... "...This phishing scam plays on people's fear .."

    Only a complete ignoramus is stupid enough to think a federal agency has time to spam via web popups.

    .. come on! are you serious? This is a problem with a dumbed down, thick as pig s@#t society that needs to be spoon fed in order to survive.

    Get a clue .. and stop inverting things.
    ZDNet Gravatar
    thx-1138_@...
    5th May
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    @thx-1138_@...
    Interesting, it should have been spelled s#@t if you are using the past tense.
    ZDNet Gravatar
    sboverie@...
    5th May
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    Unless you've harmed your machine already (you dummy), don't be concerned until they bust your door down.
    ZDNet Gravatar
    partman1969@...
    4th May
  • How to combat the FBI
    Let's face it. Regardless of the legalisms the Justice Department spews at us on the subject of no-knock raids, such a raid is clearly un-Constitutional. No self-respecting officer would ever participate in such an action. Which means the only ones who do are uniformed criminals.

    Step 1: Make sure you always lock your doors and windows. Like all theives, it won't stop them, but it will slow them down, and may provide evidence they've been in your house. Also works well against ordinary burglars, and light-fingered hobbits.

    Step 2: Reinforce your doors. A steel door with a well-secured steel frame takes several swings with a ram; especially if you have more than one bolt to break.

    Step 2a: You know those floor to ceiling glass windows framing your entry door make it really easy to get into your home? Get rid of them.

    Step 2b: That includes your pretty sliding french doors to the patio.

    Step 3: Have 911 on speed dial for your cell phone, land line, and your cable connection. That gives 3 means of alerting your local police department that you're being broken into by forces unknown. The hard lines can be cut, but it's harder to jam a cell signal without alerting other people. When you do reach the 911 operator, tell them to send EVERYTHING! Police, Fire, and Ambulance. Because if it's a no-knock raid, those animals are coming in with the intention of seriously hurting you and your family.

    Step 4: Use all three of those communication lines to try to contact your lawyer, and the news media. Bad cops HATE legal eagles and being put under bright lights by nosy reporters.

    Step 5: Make sure that you and your family say absolutely nothing except: "Where is your warrant?" "I invoke my right to silence." "I want to speak to my lawyer."
    ZDNet Gravatar
    Dr_Zinj
    4th May
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    @Dr_Zinj

    No-knock warrants ARE legal - upheld here:

    http://www.justice.gov/olc/noknock.htm

    and discussed and referenced here:

    http://topics.law.cornell.edu/wex/no-knock_warrant

    Don't fool yourself: they may not be moral, you may not like or agree with them, but they are a fact and have been upheld on numerous occasions....

    Good advice, though re: your Step 5...
    ZDNet Gravatar
    poppaman2
    4th May
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    @poppaman2

    How about step 6: Large caliber projectile propelled at high rate of speed by gases expanding from the combustion of a flammable solid at anyone entering uninvited? They'll certainly identify themselves then.

    They may have the right to just kick in the door, but often, the legal occupant has the right to protect themselves (see especially "castle doctrines" - Florida and Indiana are two states that have them)

    But generally, if you haven't done anything wrong, they won't use the gestapo-tactics (unless your neighbor is using your unsecured wi-fi to download child porn)
    ZDNet Gravatar
    reziol
    4th May
  • RE: 'You visit illegal websites' FBI-themed emails lead to scareware
    Thanks for the article. My non-tech-savvy girlfriend received just this mail earlier this evening. Despite my "it's crap - ignore it" opinions, she was still somewhat concerned until I showed her a proper article pretty much repeating what I'd told her.

    Given that we live in Scotland I somehow doubt the FBI would be bothering to email us!
    ZDNet Gravatar
    Iain@...
    4th May

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
Click Here

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources