| Federal Reserve Bank para adultos instala trojan horse
Mensagem diz que são tantas as fraudes bancárias que o Federal Reserve Bank, o banco central dos Estados Unidos, decidiu agir e criou medidas restritivas para a transferência de dinheiro. Essas medidas entrarão em vigor no dia 6 de fevereiro e serão válidas até o dia 13 de fevereiro (2009).
O link contido na página menciona o domínio secureconnect-1.us.
Segundo o Whois.Net, o domínio encontra-se registrado em nome de WEB COMMERCE COMMUNICATIONS, LTD., localizado na Federação Russa. A data de criação dele é 02 de fevereiro de 2009 e a mensagem foi enviada no dia .... 02 de fevereiro. Coisa recente, portanto.
Parece golpe da máfia russa?
Bem que parece....
Ao clicar no link do suposto Federal Reserve Bank, veja só o que aparece:

Em vez de sisudo saite de banqueiros, o que aparece é o portal de entrada de um saite para adultos... e o nome da imagem é logo0.jpg. Quer dizer, a moça é o logo do Federal Reserve Bank. Esses banqueiros...
Trata-se, na verdade, de mais uma tentativa de fraude e de instalação de programa maligno.
Mensagem original.
| From: BANK
Sent: Monday, February 02, 2009 3:36 PM Subject: Attention - Read Carefully
FEDERAL RESERVE BANK
Important:
You're getting this letter in connection with new directions issued by U.S. Treasury Department. The directions concern U.S. Federal Wire online payments.
On January 26, 2009 a large-scaled phishing attack started and has been still lasting. A great number of banks and credit unions is affected by this attack and quantity of illegal wire transfers has reached an extremely high level.
U.S. Treasury Department, Federal Reserve and Federal Deposit Insurance Corporation (FDIC) in common worked out a complex of immediate actions for the highest possible reduction of fraudulent operations. We regret to inform you that definite restrictions will be applied to all Federal Wire transfers from February 6 till February 13.
Here you can get more detailed information regarding the affected banks and U.S. Treasury Department restrictions: http://federalbanks.secureconnect-1.us/ 37436472/ secur~12879/wire/
Federal Reserve Bank System Administration
|
Versão do dia 03 de fevereiro de 2009 continha link para http://frs.server-11.us/37289489/secur~12189/wire/ onde encontrava-se hospedado o programa maligno. Página do Whois.Net contém as seguintes informações sobre esse domínio: Domain Name: SERVER-11.US Domain ID: D18514904-US Sponsoring Registrar: WEB COMMERCE COMMUNICATIONS, LTD. Registrar URL (registration services): whois.web.cc ... Registrant Name: Pavel Eroshkin Registrant Organization: Pavel Eroshkin Registrant Address1: 50 Let Oktyabrya str. d.69 kv.46 Registrant City: Syzran Registrant State/Province: Samarskaya Registrant Postal Code: 446000 Registrant Country: Russian Federation ... Name Server: NS1.SERVER-11.US Name Server: NS2.SERVER-11.US Created by Registrar: WEB COMMERCE COMMUNICATIONS, LTD. Last Updated by Registrar: NEULEVELCSR Domain Registration Date: Mon Feb 02 14:26:46 GMT 2009 Domain Expiration Date: Mon Feb 01 23:59:59 GMT 2010
Tal como no caso anterior trata-se de domínio criado um dia antes do envio da mensagem. O nome do responsável muda mas a "empresa" é a mesma: WEB COMMERCE COMMUNICATIONS, LTD.
| From: Bank System Administration
Sent: Tuesday, February 03, 2009 3:03 PM Subject: Read Carefully - Important!
FEDERAL RESERVE BANK
Important:
You're getting this letter in connection with new directions issued by U.S. Treasury Department. The directions concern U.S. Federal Wire online payments.
On January 26, 2009 a large-scaled phishing attack started and has been still lasting. A great number of banks and credit unions is affected by this attack and quantity of illegal wire transfers has reached an extremely high level.
U.S. Treasury Department, Federal Reserve and Federal Deposit Insurance Corporation (FDIC) in common worked out a complex of immediate actions for the highest possible reduction of fraudulent operations. We regret to inform you that definite restrictions will be applied to all Federal Wire transfers from February 6 till February 13.
Here you can get more detailed information regarding the affected banks and U.S. Treasury Department restrictions: http://frs.server-11.us/37289489/secur~12189/wire/
Federal Reserve Bank System Administration
|
|  |
| Siga pulhas virtuais no Twitter
Serviço Central Nacional de Denúncias de Crimes Cibernéticos Netiqueta
Dicas Arquitetando Coelhos e coelhinhos Deixando Rastros Guia do rock! Refletindo |