• Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Zip domains are being abused again to trick victims into a phishing scam

PCHF IT Feeds

PCHF Tech News
PCHF Bot
Jan 10, 2015
50,078
26
pchelpforum.net
Not even a month has passed since Google first started offering .zip internet domains, and people have already found a clever and creative way to abuse it for malware distribution.

The scam revolves around turning the web browser window into a fake WinZip or WinRAR instance and tricking the victim into believing they’re opening a legitimate file archive while, in reality, they’re downloading malware.

Researcher mr.dox outlined how a threat actor registers a new domain, for example, “setup.zip”. It looks like an archive for an installer file. Then, they create the website to mimic the look and feel of WinRAR - the file path is there, the icons are there, everything looks legitimate. To add even more credibility to the scam, the attackers can also create a fake antivirus scan popup, informing the victim that the files in the archive were scanned and no threats were found.

A website, or an archive?​


The researcher who came up with the method claims this phishing kit can be used in attacks such as malware distribution, or credential theft. A victim could end up double-clicking on a fake PDF file in the fake WinRAR window and be redirected to a fake login page which could steal their login information.

Read more

> Some of Google's new domain names could pose a serious security risk

> These dangerous phishing attacks are more common than ever - here's what you need to know

> Here's our list of the best malware removal software


The fake PDF file can also be used to trigger a file download, tricking the victim into downloading malware.

BleepingComputer also reminds that the way latest Windows versions search for files can also be abused. When a person types a file name into the search bar, the operating system will first search through local storage, but if it doesn’t find anything, it will try to open the query in a browser. If there is a legitimate domain of the same name, it will be opened in the browser.

“This technique illustrates how ZIP domains can be abused to create clever phishing attacks and malware delivery or credential theft,” the publication concludes.


Via: BleepingComputer

Continue reading...