Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, November 14, 2023

Phishing Scam Viewer Worries Get Linden Lab's Attention

 
It's a sad fact that the Internet is full of scammers. And unfortunately some have come to Second Life.  There's been some news going around recently about one particular phishing scam: a viewer that will supposedly give you unlimited Lindens, and allow you to build anywhere.

Hello,

Are you tired of spending your hard-earned Linden Dollars? We've got an exciting solution just for you! Introducing our SecondLive Viewer, where everything is not only free but also open for endless possibilities.

  • Unlock unlimited Linden Dollars (L$) for all your virtual adventures.
  • Fly to unlimited heights.
  • Build on any land of your choice, all for free.

But that's just the beginning.

Link: <Some URL, typically a tinyurl link>

We're sincerely thankful to everyone who joins us in our mission to make SecondLife completely free. Don't miss this incredible opportunity.

Best Regards.

Most residents would recognize right away these claims are bogus. Viewers can't create Linden dollars, only Linden Lab's computers can do that. One would have to hack into them, and keep hacking to get the virtual money, which would not only be extremely difficult, but easily discovered and traced. Nor can your viewer determine which land you can build on - the permissions of who can and can't are stored in the servers.

Firestorm would express worries of copybot viewers last month before I personally started hearing about the forementioned scam. The scam itself I first heard about when a few people passed me a link to a post made by FelixWolf on GitHub, who would be identified by Inara Pey of Modem World as Chaser Zaks of Team Firestorm who "risked taking a look under the covers of the code that is supplied."

What the viewer actually does is run a program called builddata.bat on your computer, which installs a number of remote administrative toolkits (or RATs). Once your machine is infested with these RATs, the scammer can:

Steal your Linden dollars and go through your inventory

Steal your password and hijack your account, and whatever they do, people (and Linden Lab) will think it's you.

Go into your computer and steal/delete your files.
 
Steal your banking and credit card information, and steal your real-world money, and possibly ruin your credit.
 
Discover real-life information on you, such as your city and street address. 
 
Activate your camera and take pictures of you and the contents of your room. If they get your real-life location, they may know where to find valuable items to steal. 

Last Thursday, Linden Lab would feel the need to remind it's residents of the dangers of phishing scams in general, "Ensuring A Secure Second Life Experience." It brought up this particular viewer, "
It is important to remember that downloading software from unknown sources has a very real risk associated with it. You could unintentionally allow someone to monitor your keystrokes or even gain complete control over your computer. It has the potential to expose not just your Second Life password, but all other important information you have on your computer. ... Be wary of suspicious links or attachments sent by other users. These may be attempts to compromise your account or computer. ... Only download and install the official Second Life viewer, or an approved Third-Party viewer directly from the links provided by our site."
 
So once again, a reminder that one needs to be a little wary when going about Second Life (and the Internet in general), and don't let yourself get a RAT infestation. 
 
Bixyl Shuftan 

Monday, September 28, 2020

InWorldz.com Now A Gambling Website


It's been over two years since the virtual world of InWorldz, once Second Life's strongest competitor, closed down. The website closed down soon after. It was recently revealed in Virtual Ability group chat that somebody had bought the website, and changed it into something that may be "click at your own risk."

Please be aware, everyone, that if you still have any saved links for InWorldz, that the domain name inworldz.com has been taken over by a Thai gambling and online-betting site.  Be careful as gambling sites are absolutely notorious for hidden malware.  (reposted from another group)

With this in mind, one should express caution to going to any InWolrdz links on websites.

Bixyl Shuftan

Wednesday, November 14, 2018

Scammers Using Fake Firestorm Website


Firestorm has become the most popular of Second Life viewers. Unfortunately, according to an article by Inara Pey, someone is taking advantage of it's popularity for the purposes of doing harm.

Inara's article stated someone is using accounts in Second Life to message residents about fake websites that appear to promote a "pro version of the Firestorm viewer." But there is no "pro version" of Firestorm. The link instead leads to a "scam site that is particularly nasty, as the Windows download link is infected."

Linden Lab has asked those who get these messages to please file an abuse report.

When filing a report, make sure you take a screen shot showing the message / notice displayed in your viewer – the abuse report screen shot feature will automatically capture open IM windows, etc. Reports can be filed under the Harassment category.

Source: Modem World

Saturday, May 13, 2017

"Unprecedented" Cyberattack Hits Thousands of Computers In 99 Countries



A massive cyberattack has hit at least 75,000 computers in 99 countries in the past few days. Described as "unprecedented" in scale, the attacks have been infecting both individuals and institutions from home computers to government agencies to businesses to hospitals. In Great Britian alone, at least 48 hospitals, clinics, and other health institutions were affected. Although some surgeries were postponed, there are no reports of deaths yet related to the hacking.

Reports of the malware, called "WannaCry" began coming in on Friday. What happens io infected computers is the files are locked and a picture appears on the screen demanding $300 US dollars worth of Bitcoin within three days for the key to unlock the computer. Unlike typical malware attacks that rely on tricking computer users into opening email attachments or clicking on links, WannaCry is a worm that attacks computers through active online connections through vulnerabilities in system software. WannaCry locks up files, looks for other vulnerable computers to infect, then deletes itself. Most computer experts recommend treating the files as lost, with only the backup files on external hard drives, if any, as recoverable. It is not recommended that people pay the criminals as in past cases of ransomware, the criminals almost never provided any key to recover lost files. It is believed that the reason Bitcoin is the method of payment demanded is because it's transactions can't be traced.

In an ironic twist, the worm may be based on a spyware tool created by the NSA to snoop on people's computers, designed to take advantages of vulnerabilities in Windows software that it had discovered. The program was leaked in April by computer hackers whom had discovered it. The agency will neither confirm or deny their program had anything to do with WannaCry. A lawyer for the American Civil Liberties Union called this "deeply troubling," saying the NSA should have notified Microsoft of the vulnerabilities instead of taking advantage of them, "These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world. Patching security holes immediately, not stockpiling them, is the best way to make everyone's digital life safer." Others put the blame less on the NSA and more on institutions for being too slow to update systems, the attack happening two months after Microsoft had a patch available.

One British computer security blogger halted one strain of the malware by accident. Known as "Malware Tech," he decided to investigate the attack, and after an all-night session noticed the strain was trying to contact a specific web address every time it infected a new system. Seeing it was unregistered, he bought it for eight Pounds ($10.69 USD) to see where the attacks were happening. But in doing se, he accidentally triggered a "kill switch" for the strain. But there are still other strains of the worm out there.




A reminder that the computer world is full of dangers.

Sources: BBC, Arstechnica, Nerdgasm

Bixyl Shuftan

Friday, December 16, 2016

Announcment: GeekSpeak "Cyber Wars" Discussion Saturday at 12 Noon


In this day and age, we are all connected in ways that we cannot measure or understand.  We have created a new cyber habitat but the old war and violence has followed us there.  We are not as safe as we thought we would be.  The lions have returned to the Savannah.

Last month’s attack on the USA showed us how easy cyber attacks can be.  Wars between states can be carried out online.  A few years ago, there was a virus roaming on the internet that was written to shut down a nuclear plant in Iran.  This is just one example that went public; there are many more predators out there that we do not know about.  Tomorrow someone could stop all traffic or close all factories.

What will happen if someone, an individual or a state, invents a super-virus?  Or if all important computers get infected with ransomware?

How much damage could a cyber war do?  How can we protect ourselves?  How threatened do you feel?  Bring your firewall to GeekSpeak and talk to us about it.

Some people have had problems teleporting to GeekSpeak.  Please contact Kathen Ohtobide if you cannot find us.
http://maps.secondlife.com/secondlife/Danmu/141/128/51


Originally posted in the SL Enquirer.

Thursday, October 25, 2012

Scam Alert

Be warned!!

There IS a scam going around of people claiming to be from Microsoft Corporation. That your computer is heavily infected and they want to assist you in removing this infection that is hindering or corrupting your computer.

There I was, just in from work and I get a unknown phone call showing a unknown number.

(Red Flag One)

The person introduced themselves as a service tech from Microsoft Corporation. That my computer was reported as one on their list as being heavily infected. 

(How would they know this?  Red Flag two) 

The gentleman, obviously from India with his accent proceeded to walk me through the steps of opening up my computer management window

Steps as Follows:
1)Click Start
2) Hover over my computer option and right click
3)Select “Manage”
The computer management window opens

 (Oh wow, neat. I had wondered where that was)

The gentleman proceeded to have me to look at the left side for the option of “Event Viewer”  once found to click and open that.  He then instructed me to look for an option of “Application”, once found to click it and open it. 

(This guy knows his stuff, ok I’ll play along)

He then had me to scroll down the middle window and look for errors and warnings.  This guy said “If you have more then 5 to 10 of these errors or warnings, that your computer has been compromised.” 

(I at this point was thinking, “Oh sh*t he’s right I got a bug in my system”)

This technician further proceeded to have me to look back to the left side under “Window Logs”  and look for “System”.  That I had to click and open that as well. The middle window populates and the tech again warns me not to click anything here, that I could inadvertently cause damage but to again look for errors and alerts. Again anything over 5 to 10 of these and it is confirmed that my system was compromised. As I scrolled down and looked at all these errors and alerts, I got pissed at myself because I had somehow allowed my computer to be infected.

This computer tech now tells me to minimize the computer management window and open my web browser. He was going to assist me in removing this infection.

(I at this point was like, “Cool, I gets help to rid myself and my computer of these problems”)

I opened my web based browser, Google Chrome and the tech tells me to type, “www.teamviewer.com” in the address bar. I being a naïve fool did so and went to the Teamviewer website.  As soon as I seen what this was I stopped. Teamviewer is one those pieces of software that you use to give complete access of your computer to somebody else. 

(Jazzy sense tingling and a HUGE red flag waving in my face)

I immediately opened another tab and googled “people calling from Microsoft claiming to be helping with errors” Now what you think I found there?

“Hoax Microsoft Windows security calls..”
“Beware cold calls from people claiming to be from Microsoft”
Scam Alert..”
I chose the 4rth option on the list “I received a phone call from Microsoft claiming I have a virus”

This window opens:

 http://answers.microsoft.com/en-us/windows/forum/windows_vista-security/i-received-a-phone-call-from-someone-claiming-i/4489f388-d6de-416d-9158-0079764bb001

Oh wow somebody else had the exact type of call and was cautious.  Scrolling down the list of answers I seen one statement that stood out that rang true.

“If you have not opened an incident (ticket for Support) with Microsoft, they do not contact you.”

Good ole Jazzy sense saves my bacon yet again.  I then asked the “tech” why after years of faithful service and all the tickets I’ve filed, that they decided to call and attempt to help now. Why I had to download Teamviewer, and why would I want to give complete  access of my computer to a complete stranger.

He sputtered, mumbled and tried to say again that he had my best interests in mind.  Sure he did.. bastard just wanted access to my computer, these same people have been reported to get access, make unwanted changes and to also leave a virus on your computer that gathers your personal information, your banking information and your browsing history and then send it to wherever in the world so they can steal your life, your funds and your livelihood. 

I was pissed at this point at both this “tech” for leading me on. At myself because I almost bought into his scam. Immediately I hung up and deleted the install file for the Teamviewer software that I had downloaded.  Used the suggestions given at answers.microsoft.com and did a complete scan on my computer

“Run the Microsoft Malicious Removal Tool

Start - type in Search box -> MRT  find at top of list - Right Click on it - RUN AS ADMIN.”

While that scan was running I read down further that I should report this scam to the proper authorities.

Needless to say now the Federal Trade Commission knows that these scammers have targeted my area.

Can go here for more information:
  http://www.ftc.gov/bcp/edu/pubs/consumer/telemarketing/tel19.shtm
 
Also while I had the lady on the horn, I had my number put on the National No Call Registry
https://www.donotcall.gov/

For an extra kick in the pants, tomorrow I’ll be making a call to my states Attorney General’s office to report this scam. Per the instructions of the lady that I spoke with of the FTC.

Listen folks, these people are good! They make themselves sound like the real deals but know that Microsoft WILL never call your home or place of business. Microsoft will never ask for access to your personal computer or business computer.

Watch for the red flags, unknown numbers, instructions for you to download any type of software that gives them complete access to your computer.  Once you see these, stop the call.. Stop the scam and report it right then.  Report it to your local law enforcement, the Federal Trade Commission.  Just let people know, all your friends and family; let them know to be on the watch for these scammers that would fleece them without thinking.  That scan I did of my system..no malicious software was detected.

Parting words:
Never, never, never, NEVER give a complete stranger access to your computer. Not through software or just sitting in front of it. You don’t know what they might do or leave you.

Jasmine Dawn Shuftan

Friday, July 6, 2012

DNSChanger Malware Could Knock Thousands of Computers Offline July 9

Thousands of computers are at risk of being unable to use the Internet because of malware from online criminals in a scam last year. Despite an effort to get the word out, as many as 277,000 computers worldwide still cary the hostile software known as DNSChanger.

DNSChanger was discovered in 2007, and may have infected millions of computers over time. The malware worked by detecting what websites its victims browsed, then redirected them to sites under the control of a cybercrime enterprise working from the small Eastern European country of Estonia, where ads were pushed onto the viewers. The criminals were netting millions before the FBI worked with Estonian police to break up the crime ring and confiscated the servers. Six were arrested with a seventh in Russia still at large.

To avoid disrupting those with infected computers, the servers were kept online as word was spread about the malware infections. In January, it was estimated a half million computers had the malware. But on Midnight July 8, the servers will be turned off, and those computers still infected will be unable to get online, at least without taking certain steps. In January, it was estimated a half million computers had the malware. As many as 277,000 computers across the world may still be infected, including as many as 4500 in the United States. Messages, such as the one Google has been showing to users of computers it detected the malware on (shown below), have helped to get the word out.

For those computers still infected, there are a number of places one can go. Among them is a website that a group of security groups and experts set up: www.dcwg.org. Others include:

Hitman Pro (32bit and 64bit versions)

Kaspersky Labs TDSSKiller

McAfee Stinger

Microsoft Windows Defender Offline

Microsoft Safety Scanner

Norton Power Eraser

Trend Micro Housecall

MacScan

Avira


For computers knocked offline, they can still get to Google by typing "173.194.34.72" into their address bar, or to Microsoft with "64.4.11.37".

Internet security company Internet Identity reported at least 60 companies on the Fortune 500 still have infected computers. At the beginning of the year, they believed the number was 250. or 50 percent. For US Government agency computers, the amount infected went down from an estimated 49 percent to 4.

Sources: http://www.dcwg.org/, Forbes, Reuters, Internet News , Google


Bixyl Shuftan