Fake Tickets Lead To Real Infection

Feb 13, 2008
19,430
0
0
Fake Tickets Lead To Real Infection


Virus builders are getting smarter. How about a fake parking ticket as the start of the trail to your machine getting infected?

Several days ago, yellow fliers were placed on cars in Grand Forks, North Dakota that said:
"PARKING VIOLATION This vehicle is in violation of standard parking regulations. To view pictures with information about your parking preferences, go to website- blah blah.com"
Odd, but certainly within the realm of possibility.

Heading along to the website, you'd see lots of pictures of cars, cunningly Photoshopped to remove license plates, so you couldn't be completely sure it wasn't yours. But it had a handy picture search toolbar to check. The toolbar actually downloaded a DLL into Windows, sent off a message to a "suspect" website and deleted the toolbar.

However, when the system was reset, the DLL hid as a browser object, and when it knows there's a connection there, it sends a little flag back to say it's working, and gets passed back another nasty DLL.

Now it had control where it wanted it, and it'd wait for a bit while you trawl the web. At a random moment, it would pop up a warning saying that you were infected. The upcoming re-direct would also tell you tales of how riddled with viruses you were and would you like to download a real anti-virus checker?

And of course, as soon as they've got a program on your machine, rather than a DLL, you're history.

While this has to be the most elaborate way of setting up a hit, you've got to admire the way it appears.

Two guys can cover a parking lot in fliers in ten minutes or so. Each owner frets and some might check the website. A few of those will get the "free anti-virus" and then those machines can be made into Zombies, Spambots or anything they want. Even with 1% pickup, that's a lot of computers, and all they're doing is playing on the same paranoia that people already have against viruses, while you do all the work for them.

Now it's been bust open though, what will be next? Anyone with access to a supermarket till system could send a similar message to thousands of potential victims.

Source: Waxy.org [http://waxy.org/]

Permalink
 

CyberKnight

New member
Jan 29, 2009
244
0
0
It does seem like a very high effort:result ratio. Create the website (did they make the pictures themselves or just get them from one of those "fail" sites?), print off the fliers, head outside and put them on cars, all with the hope that enough people will take that flier home and type in that URL (correctly) and hit their site and download the toolbar?

I wonder how the conversion rate compares with a "simple" spam campaign, where an unsuspecting victim would just have to click on a link in an email instead of taking a piece of paper home and typing something in. Actually, the results of this would make for an interesting market research study.

Except for the bit about the study participants getting viruses... :?
 

ElephantGuts

New member
Jul 9, 2008
3,520
0
0
Fake parking tickets? Genius! I mean, uh...oh no, damn them? As long as it doesn't happen to me, atleast these guys are dedicated.
 

a7r0p05

Senior Member
Dec 10, 2008
256
0
21
Sigenrecht said:
Oh. And here I was, thinking infection meant zombies...

*walks off with head hung*
That would have been indescribably more awesome, but alas...
 

Samah

New member
Jul 7, 2008
141
0
0
When I read the title I immediately thought "Fake (Steam) Tickets Lead to Real (Left 4 Dead) Infection". I was starting to wonder how you could fake a Steam ticket, and if that would cause a sudden influx of L4D hackers.

To be honest, I'm rather disappointed. :(
 

Specter_

New member
Dec 24, 2008
736
0
0
Sigenrecht said:
Oh. And here I was, thinking infection meant zombies...

*walks off with head hung*
You are not alone.

OT:
I prevent these with bashing everyone I know to not download anything that says "Your Computer is infected!", cause I'm the one they come running to when they do.
I have this very convinient Bat o' Pain I use to threaten and punish everyone who acts like a total idiot regarding social engineering.