Slashdot Log In
Malware Spreading Via ... Windshield Fliers?
Posted by
timothy
on Wed Feb 04, 2009 02:12 PM
from the right-at-home-with-the-bug-guts dept.
from the right-at-home-with-the-bug-guts dept.
wiedzmin writes "Another interesting article published by the SANS ISC Handler's Diary is describing a very unusual vector for malware distribution — windshield fliers and fake parking tickets. A website URL provided for "disputing a ticket" actually leads to a malicious website, and a "toolbar" required to find the photo of your violation is, you guessed it, a trojan posing as a fake antivirus. The best part is — according to the VirusTotal report, it doesn't look like most antiviruses have signatures for this one yet."
Related Stories
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Neat but.. (Score:5, Insightful)
Re:Neat but.. (Score:5, Funny)
Parent
Re:Neat but.. (Score:5, Funny)
My god, the frustrations I could take out on him!
Also, we could use violence.
Parent
Re:Neat but.. (Score:5, Insightful)
Knowing at least one area in which windshield fliers are prevalent (college towns), chances are pretty high you'd be going ballistic over some poor college kid who just needed some cash and wasn't told what these fliers were for, not a malicious malware author/user hiding in an apartment somewhere while his freshly-hired lackeys unwittingly do his bidding.
So unfortunately, catching the guy distributing the fliers wouldn't do you any good, unless you're really THAT upset with the practice of windshield fliering in the first place.
The fake parking tickets, though, those are probably illegal in and of themselves, and the lackey distributing them would have to at least SEE what they are and thus be complicit in the activity, so they probably have some other manner of disguising themselves (official-looking police uniform, etc) so nobody questions them. Unless the REAL cops come by.
Parent
Re:Neat but.. (Score:5, Funny)
Phase 1: Pose as college student looking to make a few bucks
Phase 2: Get to know person distributing the fliers to students
Phase 3: Stand trial for aggravated assault with no regrets.
=Smidge=
Parent
Re:Neat but.. (Score:5, Funny)
Phase 1: Pose as college student looking to make a few bucks
Phase 2: ???
Phase 3: PROFIT!!!
There, fixed that for you.
Parent
Re:Neat but.. (Score:5, Interesting)
Except in the UK, where it's a public servant with little or no training who, in some instances, actually has more power than a real police officer.
Parent
Notice Sent to UND Students. (Score:5, Informative)
Urgent! Bogus Parking Tickets Found on Campus Refer Recipients to Virus-laden Web site
Do Not Go To This Web Site!!!
A message concerning bogus parking tickets being distributed on campus that was sent out late Monday contained the URL of a Web site that carries a computer virus. We are resending that message below with the problem URL removed:
Here is the message:
UPD received a call on Jan. 31, 2009 pertaining to someone issuing bogus parking tickets in the parking lot directly east of the ramp. The ticket is yellow in color and states the following: "PARKING VIOLATION This vehicle is in violation of standard parking regulations. To view pictures with information about your parking preferences, go to XXXXXXX.COM" (URL not used for computer safety reasons)
DO NOT GO TO THIS WEBSITE!! IT CONTAINS A VIRUS!
If you visit the Web site and click on the link to view pictures of horrible parking, you will download a virus onto your computer.
Should anyone have any information pertaining to this, please contact UND Police at 777-3491.
Lt. Dan Lund
Night Shift Supervisor
UND Police Dept.
Parent
Clever idea... (Score:5, Insightful)
Maybe a few people in a town would end up affected, but the cost in time/effort required to trap victims is impractical considering what a simple email can do.
Re:Clever idea... (Score:5, Insightful)
Parent
Re:Clever idea... (Score:5, Interesting)
Depends on where you target your fliers. Put 'em around city hall, and you may be able to get some schmuck to compromise their internal network. Or a bank, or a big company, etc, etc.
That would be the big advantage of being able to geographically target your scam.
Parent
Re:Clever idea... (Score:5, Interesting)
Sure, some security testing firms have already added "leave trojaned USB sticks in the parking lot" to their list of tests.
Slap these on cars before lunch, everyone who goes out to lunch will probably check the url when they get back on their work computer.
Parent
A virus I'd actually fall for (Score:5, Insightful)
Re:A virus I'd actually fall for (Score:5, Funny)
welcome to the world of personal computing! Now that you've made the decision to dedicate at least some part of your life to staring at a screen and tapping on a keyboard, you should know that we (The Internets) have been working hard to make your computing experience as exciting as possible.
Everyday you will have to learn more and more about computing just to keep up with trends, and if that isn't enough, we have some software coders that want to play a game with you. It's called "Show me your password and finance details" and is such an exciting game you will soon forget all about Zelda. Never mind looking for the hidden doors or avoiding poisonous frogs. In this game, every key you touch could be the one that causes you to lose.
We also have many other options to fill your time. We're glad you are here, enjoy computing in the Internets.
Sincerely,
I.M. Rogue
Parent
Re:A virus I'd actually fall for (Score:5, Interesting)
Parent
Re:A virus I'd actually fall for (Score:5, Insightful)
it still fails to computer literate common sense, "why would i need to install something to..."
Flash. Silverlight. Java. Adobe Reader. Windows Update controls.
People are getting used to installing applications to interact with "trusted" parties.
Parent
That is pretty clever... (Score:5, Interesting)
And then you add in people who are from out of town, who would much rather not have to go back to your city to deal with a ticket...
Re:That is pretty clever... (Score:5, Funny)
do you know what a parking ticket looks like in your city
Only one way to find out. Lemme borrow your keys.
Parent
Re:That is pretty clever... (Score:5, Insightful)
Accidentally modded redundant instead of insightful. Sorry. Posting to kill moderation.
Isn't this awesome new moderation system such a great part of this fantastic new layout? Nobody liked the "confirm" button from the previous system, right?
Parent
Who reads those things anyway? (Score:5, Informative)
1. You are parked legally
2. Everybody else has these "tickets"
And that's before you notice that your local government is using a website like: http://qlmbix.ch/parkingticets.html [qlmbix.ch]
I mean for this infection to work, the victim has to be not only stupid, but also not lazy. It has to have a low infection rate.
Re:Who reads those things anyway? (Score:5, Interesting)
1. You are parked legally
2. Everybody else has these "tickets"
I've gotten tickets when I was parked legally and successfully contested them. All the other cars on the block were also incorrectly ticketed at the same time - apparently a cop misunderstood the parking rules, or didn't know how to operate a watch.
Furthermore, given the city's trend of contracting out ticking, the fact that the URL pointed to some third party website and not a subdomain of the city or county sites wouldn't have set off any red flags either (although one hosted in the Czech Republic would :). The red-light tickets we get in the mail today directs you to the website of the contracted company and not to the city website.
Parent
The weirdest thing just happened to me (Score:5, Funny)
I went out to my car to go to lunch and there was this Nigerian Prince and his entourage standing there and he said he needed my helpto move some cash out of his country for his dead uncle or someone.
Dear fliers-posting malware authors (Score:5, Funny)
I don't have a car, you insensitive clod!
I bet the antivirus companies didn't have it ... (Score:5, Informative)
... right away because they get their earliest warnings from honeypot machines and this one uses an offline vector.
Re:Some should rip in to the fake person giving ou (Score:5, Funny)
Some should rip in to the fake person giving out the tickets
How do you catch a fake person? Fake traps?
Parent