Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le juin 29, 2012, 23:01:18

Titre: [MMPC]Carl A. Someone has many names
Posté par: igor51 le juin 29, 2012, 23:01:18
Carl A. Someone has many names

<div class="ExternalClassC0559E40C4CE4760A6C9475313D55D5A">
<p>In days of old, a man without a signature would just mark an 'X', but today it seems like there is another, more common, signature. I was doing some work the other day and came across a Word document that had an attachment. It turned out to be a phishing scam but part of the document caught my eye.</p>
<p>The signature did not match the name. The name was Dr. Simon Brown and the signature looks like this:</p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-01.png" /></p>
<p>The signature was for Carl A. [indecipherable]. This made me wonder if it was just some generic image of a signature that scammers use. So after a search through our file collection and a stroll around the internet I found that I was correct - this is one very popular signature indeed with the phishing community. Now there are many blogs and sites out there that cover these scams in far more detail but this is what I found about files with this image embedded in it.</p>
<ul>
<li>There have been scams using this signature in them since at least 2006.</li>
<li>The following are some of the names that have been attached to the signature in the phishing attachments:<br />
<table>
<tbody>
<tr>
<td>Dr. (Mrs.) Felicia Daniel</td>
<td>Dr. (Mrs.) Mercy Hartemink</td>
<td>Dr. Austin Benjamin</td>
</tr>
<tr>
<td>Dr. Ferguson Andrew</td>
<td>Dr. Frank West</td>
<td>Dr. George Williams</td>
</tr>
<tr>
<td>Dr. John Briggs</td>
<td>Dr. Larry Smith</td>
<td>Dr. Mack Anthony</td>
</tr>
<tr>
<td>Dr. Mark Brown</td>
<td>Dr. Mark Winters</td>
<td>Dr. Martin Evans</td>
</tr>
<tr>
<td>Dr. Matt Brown</td>
<td>Dr. Richard Morrison</td>
<td>Dr. Robert Mueller</td>
</tr>
<tr>
<td>Dr. Smith Brown</td>
<td>Dr. Smith Don</td>
<td>Dr. Smith Williamson</td>
</tr>
<tr>
<td>Dr. Steve Mark</td>
<td>Dr. Tom Wilson</td>
<td>Jenni Falconer</td>
</tr>
<tr>
<td>Michelle Falkosky</td>
<td>Mr. Christ Rawlins</td>
<td>Mr. Daniel Rougerie</td>
</tr>
<tr>
<td>Mr. Evans Henshaw</td>
<td>Mr. Graham Smith</td>
<td>Mr. James Norris</td>
</tr>
<tr>
<td>Mr. Muhtar Kent</td>
<td>Mr. Roberth Mueller</td>
<td>Mr. Teddy Kennedy</td>
</tr>
<tr>
<td>Mrs. Brunelli Naleen</td>
<td>Mrs. Elizabeth Walters</td>
<td>Mrs. Lisa Parker</td>
</tr>
<tr>
<td>Mrs. Lourdes Vidaurre</td>
<td>Mrs. Nicola Mckeon</td>
<td>Mrs. Patricia.S.Brown</td>
</tr>
<tr>
<td>Mrs. Rita Brown</td>
<td>Mrs. Rosemary Clair</td>
<td>Prof. Alex Kingston</td>
</tr>
<tr>
<td>Prof. Martin Johnson</td>
<td>R. Simon Brown</td>
<td>Rev. James Moore</td>
</tr>
<tr>
<td>Rev. Robert Morgan</td>
<td>Sir. Muhtar Kent</td>
</tr>
</tbody>
</table>
</li>
<li>At least 15 had the title of "Coca Cola Games/Lottery Coordinator"</li>
<li>The documents are all related to winning a prize of around &pound;400,000 to&nbsp;&pound;1,000,000 from different companies in England.</li>
<li>The following company names are among those that have been used illegitimately in these fake lotteries:<br />BBC<br />British High Commission<br />British Telecom<br />Coca-Cola<br />ESPN<br />Fifa World Cup<br />Golf international<br />Microsoft<br />Nokia<br />Toyota<br />UK Lottery<br />Yahoo</li>
</ul>
<p>I suspect many of you have seen these emails, but if not they all follow the same sort of format. They tell you that you have won a prize and ask for a whole bunch of details so that you can claim that prize. I even came across one that wanted a photo. For those who have not seen them here are a few examples. Please note the signature on all of them, it should look familiar.</p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-02.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-03.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-04.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-05.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-06.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-07.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-08.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-09.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-10.png" /></p>
<p><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Carl/BID109-11.png" /></p>
<p>The oldest reference that I found to the signature on the web is a shipping company that dates their website to 2003. This leads me to believe that this was an open source image that the scammers have enjoyed using. (Unlike the various logos you see above, which are trade and service marks that are used illegally.)</p>
<p>I still do not know what the original name was though, Carl A...</p>
<p>- Michael Johnson<br />MMPC Melbourne</p>
<p>P.S. I do not think that I need to say it again but never open an email from someone that you do not know. It is very unlikely that you have won the Coca-Cola lottery or any lottery for that matter. Please use safe practices when dealing with email.</p>
</div><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3499231" width="1" height="1">
Source: Carl A. Someone has many names (http://blogs.technet.com/b/mmpc/archive/2012/05/22/carl-a-someone-has-many-names.aspx)