Infesting you with Virus News
 

News

Contributed by: Daniel
Date: April 6, 2010
Daniel
4
Vote
0

Compromised eBay Account Used in Phishing Scam

 

Only a few days ago, an Internet security company Red Condor issued a warning of a new email threat that appears to be a security alert form the leading online marketplace, eBay. The scam message is perfectly disguised and leads to a compromised user`s account within eBay network that hosts a malicious executable.

The scam message is subjected:"eBay Security Alert - Procedural Warning", the sender`s address is spoofed to look like it is sent from the internal email system of eBay. The fake email is addressed to "Dear eBay Member" and warns that user`s eBay account is experiencing security issues and it will be limited, unless the user downloads and installs the so-called "eBay Security Shield" (Figure 1).

ebaytrojan.jpg

Figure 1. eBay Scam Email Message

If a user follows the link provided in the scam message, he will be taken to a compromised eBay account, hosting the scam page that pretends to be the "eBay Security Shield" Installer. The worst thing here is that the malicious page containing the Trojan is truly hosted on the eBay network. The hackers used an "About me" page of a compromised user`s account to host the scam page. That makes it look very real and legitimate (Figure 2).

ebayscampage.jpg

Figure 2. eBay Scam Landing Page

"Download now" button downloads and executes a password stealing Trojan on the victim`s computer. After that, the infected user is redirected to log in into his eBay account and that`s how his eBay credentials are sent to the scammers.

At present, only seven antivirus engines recognize this threat. Although this spam campaign has a relatively low volume, it can cause many troubles to eBay users because of its low discovery rate.

eBay users must not trust any suspicious email messages found in their mail Inboxes. eBay ALWAYS use its internal messaging system to contact the customers and anyone should trust only this type of communication with the World's biggest online marketplace.

User Comments

Ulf Wolf April 6, 2010
Great post.

Perhaps I can just add to this that the best way to guard against being ripped off by online sales or auctions of any kind, eBay included”and whether seller or buyer”is to use a bona fide online escrow company. Although it does add some cost, that will take uncertainty out of the transaction.

For my money, the best bona fide online escrow (and there seems to be ten fraudulent escrow sites for every bona fide one) is probably Escrow.com (http://escrow.com). In fact, its the only one that eBay recommends.

Take care,

Ulf Wolf
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

September 3, 2010
how can i remove sdfsdf, i cannot get into windows? more..
September 3, 2010
hi here is parteek kaushal i just want to tell that smone has copied my pics with my frnd n she is abusing... more..
September 3, 2010
Hello I am new here. Im sorry if this is not the right place for this post. My name... more..
more comments..
rss
Home > E-mail > Compromised eBay Account Used in Phishing Scam