The Zscaler ThreatLabZ team has been monitoring a subset of opt-in data to discover a correlation between shopping activity and scams. As an effect of increased shopping behavior, we've observed a steady number of scams clicked on by users. Scammers take notice of trending topics as well and us consumer’s impaired judgement to cast a wide net of phishing, fraud, and scam attacks meant to capitalize on the shopping season. Whether you are using a mobile device or your home PC, the uptick in shopping trends remains relevant.
Vawtrak Botnet Scam
Our first case study illustrates the danger of these fraudulent deals. The botnet, Vawtrak (also known as NeverQuest and Snifula), is a powerful information stealing backdoor Trojan that has been gaining momentum over past few months. It primarily targets user's bank account via online banking websites. We’ve come across numerous reports, where users begin the infection cycle through spam e-mails promising a sales deal. This case appears to be no different, as we see the Pony Trojan Downloader being leveraged to download the Vawtrak payload.- salesdeal.magentochile[.]cl/f1.exe
Savvy users that suspect themselves to be afflicted with this threat should look for similar suspicious files:
- C:\Users\[COMPUTERNAME]\AppData\Local\Temp\~DFECDDE19F2005BD31.TMP
- C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\Kapag
- C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\KuhaKqigd.dll
- C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\KuhaKqigd.exe
- C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\Qucuz
- C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\Sofolq
- C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\Uoqet
- C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\YidaLboz
- HKU\[USER-ID]\Software\Microsoft\Windows\CurrentVersion\Run\WopuVdax: "regsvr32.exe "C:\Users\[COMPUTERNAME]\AppData\Local\SuyaDruj\KuhaKqigd.dll""
- HKU\S-1-5-21-4274511564-889519498-3811658521-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500: 0x00000000
- HKU\S-1-5-21-4274511564-889519498-3811658521-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500: 0x00000003
NetWired leaves two files actively running which beacon to suspicious destinations. These processes collect and exfiltrate stolen data to the threat actors.
- 109[.]163[.]226[.]153
- 213[.]152[.]162[.]99
- 31[.]184[.]194[.]138
- 46[.]161[.]1[.]172
- 46[.]165[.]208[.]108
- 46[.]20[.]33[.]82
- 62[.]102[.]148[.]181
- 95[.]211[.]229[.]148
Free iPhone6 scams
- http[:]//apple[.]com[-]freegiveaway[.]com
- http[:]//applestore[.]officialfreegiveway[.]com/
- http[:]//facebook[.]officialfreegiveway[.]com/
- http[:]//8sd5ug[.]getafreeiphone6splustoday[.]com/
- http[:]//giveaways[.]xyz/iphone[-]giveaway/
- http[:]//iphone6[.]howtogetafree[.]eu/
How can online shoppers protect themselves?
Thanksgiving marks the start of the holiday shopping season which continues through Christmas. The Zscaler ThreatLabZ team is working around the clock to ensure that our customers do not fall prey to such malicious activity.We highly recommend that all online shoppers exercise extreme caution and follow our holiday season shopping security checklist:
- Inspect the source of emails with enticing shopping deals. Be wary of any suspicious attachments
- Steer clear of unofficial mobile application stores
- Ensure HTTPS/secure connections to online retailers and banking sites
- Check the authenticity of the URL or website address before clicking on a link
- Stay away from e-mailed invoices - this is often a social engineering technique used by cyber criminals
- Do not use insecure public WiFi for shopping
- Use two-factor authentication whenever possible especially on sensitive accounts such as those used for banking
- Always ensure that your operating system and web browser have the latest security patches installed
- Use browser add-ons like Adblock Plus to block popups and potential malvertisements
- Backup your documents and media files
- Review the Identity Theft Guide and FAQ from the Federal Trade Commission.