Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

What’s Behind the News—Maybe a 419 Scam?

Samir Patil
November 6th, 2009
Tags: Online Fraud, Online Fraud, Security, Spam, Spam, Security Response
Facebook Twitter

Scammers based in Nigeria have long been known for using legitimate email formats for spreading infamously fraudulent 419 messages. We have already monitored e-card services, social networking invites, and various other services provided on social networking sites. Yet another example is a calendar service being abused for sending scam messages.

Sadly there is an addition to this list, where the “send link to friend” service is exploited for sending scam messages. Many news websites provide an option to send news links to another person. A text area is also provided to write personalized messages. It is a general tendency of netizens to share important news with friends by forwarding the links along with their comments on the news. In a recent spam attack we monitored a typical 419 scam message injected into the text area of a news article. With this, scammers smartly introduce a scam message in an otherwise very legitimate looking mail.

The “Subject” line of these emails can usually be found in the format below:

Subject: <sender name or email> has forwarded a page to you from <news site name>
Subject: <sender name or email> has sent news to you from <news site name>
Subject: <sender name or email> has sent a link to you from <news site name>

The next example shows how a scam message is disguised in a legitimate message format:
 
Screen shot 2009-11-06 at 8.28.22 PM.png

Screen shot 2009-11-06 at 8.28.31 PM.png

When a user comes across this type of message in his or her inbox, it looks as if it is a legitimate news article being forwarded from someone. Even after opening the message, the links in message body redirect the user to a legitimate news article. However, the scam messages suppress the news article and the email looks entirely like a 419 scam message (because it is). We recommend that users ignore emails from unknown senders and unsubscribed sources.

Note: Thanks to Paresh Joshi for contributed content.

0 votes
  • Samir Patil's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Microsoft Patch Tuesday - February 2010
    Robert Keith - February 09, 2010
  • Sale! This Offer is Valid EVERY Week
    Mayur Kulkarni - February 05, 2010
  • SpyEye Bot versus Zeus Bot
    Peter Coogan - February 04, 2010
  • 利用双重漏洞发动攻击的木马Trojan.Hydraq
    Livian Ge - February 03, 2010
  • Phishing Using Pornographic Content as Bait
    Mathew Maniyara - February 03, 2010

Blog Tags

10.x 11.x 9.x and Earlier Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Evolution of Security General Symantec How to IT Risk Management Internet Security Threat Report Malicious Code Mobile & Wireless Online Fraud Platforms & Hardware Restore Security Security Security Risks Spam Vulnerabilities & Exploits Windows
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com