Monday, December 31, 2007

Trojan delivers pay-by-phone extortion

After infection by this Trojan, you�re completely locked out of the system.

You get this screen �� it takes over your entire desktop:


Hijack_900_number


Click on �Click to activate new license�, you get this screen:


Hijack_900_number2


Turns out it�s coming from a website, which I�ve posted the same screens, below:


Securitycenter1324812388


Different countries have different numbers. For example, here is the UK:


Securitycenter1324812388ab


And here is France:


Securitycenter1324812388ac


Incidentally, a search on the US 900 number shows the first link as passwordtwoenter com, which shares an IP with a number of other similar sites:


p2e com
chargemybill com
chargemyphonebill com
password2enter com
passwordtoenter com
passwordtwoenter com
phonetoenter com
pin2enter com
pintoenter com
pintwoenter com
ptwoe com


Apparently, this is a payment processor that�s now being used for malware, whether they know it or not.


Alex Eckelberry
(thanks Adam Thomas and Patrick Jordan)

Update: Pay-by-phone processor cancels account. More here.

No comments:

Post a Comment