Anatomy of a scam? Or just a password notification?

Comment

Anatomy of a scam? Or just a password notification?

While eating my breakfast this morning and checking up on email, I run across 2 of the following emails:

3am email about a password reset from Facebook to an email address that is not used by the family as logins?  The Spidey Senses are tingling.  Time to look at the raw email data and see what is going on....

Delivered-To: beckerfamily@floridabeckers.us
Received: by 10.229.14.201 with SMTP id h9csp502473qca;
Sat, 20 Sep 2014 00:04:35 -0700 (PDT)
X-Received: by 10.180.211.208 with SMTP id ne16mr1532381wic.71.1411196675222;
Sat, 20 Sep 2014 00:04:35 -0700 (PDT)
Return-Path:
Received: from mx-out.facebook.com (outmail016.ash2.facebook.com. [66.220.155.150])
by mx.google.com with ESMTPS id v14si4512206wie.3.2014.09.20.00.04.34
for
(version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
Sat, 20 Sep 2014 00:04:35 -0700 (PDT)
Received-SPF: pass (google.com: domain of password+h_i3dki_@facebookmail.com designates 66.220.155.150 as permitted sender) client-ip=66.220.155.150;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of password+h_i3dki_@facebookmail.com designates 66.220.155.150 as permitted sender) smtp.mail=password+h_i3dki_@facebookmail.com;
dkim=pass header.i=@facebookmail.com;
dmarc=pass (p=REJECT dis=NONE) header.from=facebookmail.com
Received: from facebook.com (CB2uJzaEr7FAP9Z3NNj8E9uO4ydVsDyZ8ttuyabo2wEjYbPxtGSfri+xd3E5hhYV 10.158.104.67)
by facebook.com with Thrift id 6079b0ec409411e494110002c9550d78-2a1eb3f0;
Sat, 20 Sep 2014 00:04:34 -0700
X-Facebook: from 2401:db00:3010:3018:face:0:4f:0 ([MTI3LjAuMC4x])
by m.facebook.com with HTTP (ZuckMail);
Date: Sat, 20 Sep 2014 00:04:34 -0700
Return-Path: password+h_i3dki_@facebookmail.com
To: Nicole Beasley-Becker
From: “Facebook”
Reply-to: noreply
Subject: Somebody requested a new password for your Facebook account
Message-ID: <7833a8c7c38f65544e5ddf3b132fa1f0@m.facebook.com>
X-Priority: 3
X-Mailer: ZuckMail [version 1.00]
Errors-To: password+h_i3dki_@facebookmail.com
X-Facebook-Notify: password_reset; mailid=a872430G30a5e9d3G0G178G29129f32
X-FACEBOOK-PRIORITY: 1
X-Auto-Response-Suppress: All
Require-Recipient-Valid-Since: beckerfamily@floridabeckers.us; Wednesday, 4 Aug 2010 15:07:54 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=”b1_7833a8c7c38f65544e5ddf3b132fa1f0”
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=facebookmail.com;
s=s1024-2013-q3; t=1411196674;
bh=KsNcsnOLkT3p6hrtXpRx5uiG7l2rqzTocgLbQUUAQFg=;
h=Date:To:From:Subject:MIME-Version:Content-Type;
b=iP4aprX0sCUXj9yWvddNp0ssj/zYj0X67/XpWm4pgxg73tbc5qbrsa03koq2Qo0+s
5kJzurtEhZ1l012QgYM0f3xOMmztwwBzQfxQ03ZXSRRhlBM0xZcseQ9iHdeXxiHugh
VEOgxGnS25a6LTFHVrV+joWxnURGx11qEgdhFcjo=


—b1_7833a8c7c38f65544e5ddf3b132fa1f0
Content-Type: text/plain; charset=”UTF-8”
Content-Transfer-Encoding: quoted-printable

Hi Nicole,

Somebody recently asked to reset your Facebook password.

Click here to change your password.[https://www.facebook.com/recover/code?=
u=3D816179667&n=3D654156]=20

Alternatively, you can enter the following password reset code:

654156

Didn’t request this change?

If you didn’t request a new password, let us know immediately.

Change Password
https://www.facebook.com/recover/code?u=3D816179667&n=3D654156


Thanks,
The Facebook Team



=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
This message was sent to nicole@floridabeckers.us at your request.
Facebook, Inc., Attention: Department 415, PO Box 10005, Palo Alto, CA =
94303


—b1_7833a8c7c38f65544e5ddf3b132fa1f0
Content-Type: text/html; charset=”UTF-8”
Content-Transfer-Encoding: quoted-printable

//EN”>Facebookcontent=3D”text/html; charset=3Dutf-8” =
/>style=3D”margin:0;padding:0;” dir=3D”ltr”>cellpadding=3D”0” id=3D”email_table” =
style=3D”border-collapse:collapse;width:98%;” border=3D”0”>
id=3D”email_content” style=3D”font-family:'lucida =
grande',tahoma,verdana,arial,sans-serif;font-size:12px;padding:0px;ba=
ckground:#e0e1e5;”>width=3D”100%” border=3D”0” =
style=3D”border-collapse:collapse;width:100%;”>
style=3D”font-size:11px;font-family:LucidaGrande,tahoma,verdana,arial,sans=
-serif;padding:0;border-left:none;border-right:none;border-top:none;border=
-bottom:none;”>style=3D”border-collapse:collapse;”>
style=3D”padding:0;width:100%;”>!important;font-size:1px;”>Somebody recently asked to reset your Facebook =
password. Click here to change your password. Alternatively, you can enter =
the following password reset code: 654156 Didn't request this change? =
If you didn't request a new password, let us know immediately . =
=C2=A0 =C2=A0 Change=C2=A0Password =C2=A0 =C2=A0
style=3D”padding:0;width:100%;”>width=3D”100%” bgcolor=3D”#435E9C” style=3D”border-collapse:collapse;width=
:100%;background:#435E9C;background-image:-webkit-linear-gradient(top, =
#5c77b5, #435e9c);border-color:#0A1F4F;border-style:solid;border-width:0px =
0px 1px 0px;box-shadow:0 1px 1px rgba(0, 0, 0, 0.25);height:47px;” =
id=3D”header”>
cellpadding=3D”0” width=3D”610” height=3D”44” =
style=3D”border-collapse:collapse;”>
id=3D”header_title” style=3D”width:100%;line-height:47px;”>cellspacing=3D”0” cellpadding=3D”0” =
style=3D”border-collapse:collapse;”>
href=3D”https://www.facebook.com/recover/code?u=3D816179667&n=3D654156=
” style=3D”color:#FFFFFF;text-decoration:none;font-weight:bold;font-family=
:lucida grande,tahoma,verdana,arial,sans-serif;vertical-align:baseline;fon=
t-size:20px;letter-spacing:-0.03em;text-align:left;text-shadow:0 1px 0 =
rgba(0, 0, 0, 0.24);”> facebook
style=3D”width:10px;”>size=3D”3”>style=3D”color:#ffffff;text-decoration:none;font-family:Helvetica =
Neue,Helvetica,Lucida Grande,tahoma,verdana,arial,sans-serif;font-size:16p=
x;font-weight:bold;text-shadow:0 -1px rgba(34, 59, 115, =
0.85);vertical-align:middle;” href=3D”https://www.facebook.com/recover/cod=
e?u=3D816179667&n=3D654156”>
=
style=3D”padding:0;width:100%;”>width=3D”100%” bgcolor=3D”#e0e1e5” id=3D”table_color” =
style=3D”border-collapse:collapse;”>
cellspacing=3D”0” cellpadding=3D”0” width=3D”100%” id=3D”email_filler” =
style=3D”border-collapse:collapse;”>
style=3D””> 
cellpadding=3D”0” width=3D”610” =
style=3D”border-collapse:collapse;”>able><=
/tr>
id=3D”body_container” style=3D”background-color:#ffffff;border-color:#c1c2=
c4;border-style:solid;display:block;border-width:1px;border-radius:5px;-we=
bkit-border-radius:5px;-moz-border-radius:5px;box-shadow:0 1px 1px rgba(0, =
0, 0, 0.10);overflow:hidden;”>width=3D”100%” style=3D”border-collapse:collapse;”>
style=3D”padding:15px;”>style=3D”border-collapse:collapse;width:100%;”>
style=3D”font-size:11px;font-family:LucidaGrande,tahoma,verdana,arial,sans=
-serif;padding-bottom:6px;”>
Somebody recently asked to reset your =
Facebook password.
=3D816179667&n=3D654156” =
style=3D”color:#3b5998;text-decoration:none;”>Click here to change your =
password.
rande,tahoma,verdana,arial,sans-serif;padding-top:6px;padding-bottom:6px;”=
>Alternatively, you can enter the following password reset =
code:
homa,verdana,arial,sans-serif;padding-top:6px;padding-bottom:6px;”>>style=3D”border-collapse:collapse;”>
amily:LucidaGrande,tahoma,verdana,arial,sans-serif;padding:10px;background=
-color:#f2f2f2;border-left:1px solid #ccc;border-right:1px solid =
#ccc;border-top:1px solid #ccc;border-bottom:1px solid =
#ccc;”>654156
style=3D”font-size:11px;font-family:LucidaGrande,tahoma,verdana,arial,sans=
-serif;padding-top:6px;padding-bottom:6px;”>
style=3D”color:#333333;font-weight:bold;”>Didn't request this =
change?
If you didn't request a new password, href=3D”https://www.facebook.com/login/recover/disavow_reset_email.php?n=
=3D654156&id=3D816179667” =
style=3D”color:#3b5998;text-decoration:none;”>let us know =
immediately
.
daGrande,tahoma,verdana,arial,sans-serif;padding-top:6px;”>href=3D”https://www.facebook.com/recover/code?u=3D816179667&n=3D654156=
” style=3D”color:#3b5998;text-decoration:none;”>cellpadding=3D”0” width=3D”100%” bgcolor=3D”#4c649b” style=3D”border-colla=
pse:collapse;border-width:1px;border-style:solid;display:block;font-weight=
:bold;border-radius:3px;-webkit-border-radius:3px;-moz-border-radius:3px;f=
ont-size:14px;background:-webkit-gradient(linear, left top, left =
bottom,color-stop(0%, rgba(99,123,178,1)),color-stop(64%, =
rgba(76,100,155,1)));border-color:#485a83;box-shadow:inset 0 1px 0 =
rgba(255, 255, 255, 0.2),0 1px 2px rgba(0, 0, 0, 0.08);text-align:center;” =
class=3D”btn_confirm”>ble>
style=3D”line-height:7px;”> 
style=3D”display:block;width:16px;”> style=3D”text-align:center;”>ode?u=3D816179667&n=3D654156” =
style=3D”color:#3b5998;text-decoration:none;display:block;”>
size=3D”3”>Grande,tahoma,verdana,arial,sans-serif;font-weight:bold;font-size:14px;col=
or:#ffffff;text-shadow:0 1px 0 =
#415686;”>Change Password
width=3D”16” style=3D”display:block;width:16px;”> 
height=3D”7” colspan=3D”3” style=3D”line-height:7px;”> 
cellspacing=3D”0” cellpadding=3D”0” width=3D”100%” =
style=3D”border-collapse:collapse;” id=3D”footer_table”>
style=3D””>
width=3D”610” style=3D”border-collapse:collapse;”>
style=3D””>border=3D”0” id=3D”footer” style=3D”border-collapse:collapse;”>
style=3D”font-size:12px;font-family:Helvetica Neue,Helvetica,Lucida =
Grande,tahoma,verdana,arial,sans-serif;padding:18px 0;border-left:none;bor=
der-right:none;border-top:none;border-bottom:none;color:#6a7180;font-weigh=
t:300;line-height:16px;text-align:center;border:none;”>This message was =
sent to style=3D”color:#6a7180;text-decoration:none;font-family:Helvetica =
Neue,Helvetica,Lucida Grande,tahoma,verdana,arial,sans-serif;font-weight:b=
old;”>beckerfamily@floridabeckers.us
at your request. Facebook, =
Inc., Attention: Department 415, PO Box 10005, Palo Alto, CA =
94303
src=3D”https://www.facebook.com/email_open_log_pic.php?mid=3Da872430G30a5e=
9d3G0G178G29129f32” style=3D”border:0;width:1px;height:1px;” =
/>




—b1_7833a8c7c38f65544e5ddf3b132fa1f0—
— Raw eMail.

Hmm...it looks to be legitimate.  No links are connecting to or directing to any place other than Facebook,  Bringing up the virtual machine and opening the link shows nothing but a legitimate Facebook page....

So what is really going on?  I check on my wife's email to see if she received the same email since it listed her name on the email.  Sure enough, identical email there too.  It looks like that someone did try to log reset her password and Facebook was trying to protect.  Sometimes link laden email is legitimate.  Time to tune those Spidey Senses again.....

Comment

Comment

School mist guilt trip?

Tonight was my youngest child's open house at school with the rigamarole that goes with it, including signing multiple forms (for Title I, allowed pickups, etc,), and were sent home the annual flu mist consent form.  This program has been voluntary in our school system for several years, but the pressure to get the students to get the forms filled out (preferably with a yes) has increased greatly over the past several years (even bribing kids with extra credit) in order to get 100% form return (and 100% participation).  The form this year (which I will get to later) differs subtly from the previous year, and in a somewhat manipulative way.

First, here is one of the original forms

2008-2009 Flu Mist Form

2008-2009 Flu Mist Form

2011-2012 Flu Mist Form

2011-2012 Flu Mist Form

2012-2013 Flu Mist Form

2012-2013 Flu Mist Form

2013-2014 Flu Mist Program

2013-2014 Flu Mist Program

Now we come up to this year's form:

2013-2014 Flu Mist Form

2013-2014 Flu Mist Form

You see that subtle change?  Let me highlight it for you:

Ah...add this social responsibility guilt factor.  Yes, I want to be a good guy and save everyone or No, I want to be a selfish bastard and not have my kids immunized.  Maybe that is what it will say next year.

Comment

Comment

Why I decline the Ice Bucket Challenge

With everyone and their mother challenging each other to the ALS Ice Bucket Challenge, I thought of many ways I could be snarky and cynical about this, but decided I would like to make one single post on why I will not be participating in this campaign.

  1. While ALS may be a worthwhile cause and a tragic disease, there are numerous other charities that also could use the money, but not getting the notoriety that the Ice Bucket Challenge is getting.  
  2. When I choose to make donations to charities, it has to be something I have a strong tie to.  Charities like JDRF, Catholic Charities, Goodwill, or Habitat for Humanity have all received donations from me in the past, and deal with causes I believe in.  Because I have a tie, does not mean that you have one and I would not ask you to donate in charities in a challenge or on a whim.  
  3. The ice bucket challenge is symptomatic of the selfie generation.  This campaign feels more about look at what I did, rather than the charity of choice.  It also feels that the campaign has "jumped the shark" especially with the number of celebrities focussed on the challenge without saying what it is for.

If you feel like donating to ALS, go ahead.  Same if you want to have fun dumping ice over your head.  Just don't expect me to do the same.

Comment

Why the political process is broken...

Comment

Why the political process is broken...

Let me start by saying, though libertarian in many of my thoughts, I do not belong to any political party, and will likely never will.  Political parties, in their current structure, have completely eliminated the middle of the road, common sense ideas from the political spectrum.  If you "reach across the aisle" or even endorse a concept by your "rival" party, then you are called out as a RINO or DINO (Republican or Democrat In Name Only)  and may eventually be targeted by an even more partisan political hack to roust you from your seat in the primary (with gerrymandering, that tends to be the only way political incumbents are defeated),

When someone who does not belong to any particular party gets candidates at the general election, the choices we are given are 2 "major" candidates that have appeased the most partisan of their party, and "minor" party candidates that in general have very little chance to break the 2 party system that has been stacked against them.

How can we fix this?  Open up the primary process system.  Put all candidates on the ballot in a nonpartisan blanket primary whenever feasible.  Let the top 2 vote getters in the primary move forward to the general election.  This forces all candidates to focus their ideas to appease the general public and hopefully allow the best ideas go through.  In addition, it can increase voter turnout in the primary process, as the number of independent voters has surged over the past 20 years.  


Will it affect the minor parties?  Maybe, in a surprisingly positive way.  So be it if the top 2 are Republicans, Democrats, Libertarians, Greenies, etc.  This should reduce partisanship because politicians will reduce their dependance to party and increase their responsiveness to their constituents.  

Comment

So, about that order I "placed"...

Comment

So, about that order I "placed"...

Since we run multiple filters at work that do a good job that block spam and malware infested email, I am always interested in what makes it through the defenses as opportunites for improvement.

Take, for instance, an email I received tonight about a supposed order I made.

What did I order?

What did I order?

Hmmmm...I ordered something today with my VISA with email containing my email from a .ru email address (for those not familiar, .ru is Russia).  They are so kind to send me an invoice of my order in an attachment, which happens to be a .html file (web page code, again if you are not familiar).  

Looks legit to me. &nbsp;:)

Looks legit to me.  :)

Okay.  I know, suspicious file....must send it over to virustotal.com and see if it detects anything in the file.

No viruses detected???

No viruses detected???

Suspicious email, suspicious attachment, but comes up clean...what gives?

Let's open up the html code in a text editor and see what is going on....

Cyrillic plus mysterious javascript...

Cyrillic plus mysterious javascript...

Fortunately, we have other tools to try to get a better handle of what is going on.  Submitting the file to malwr.com (run by the ShadowServer folks), we see there is really more than meets the eye.

Creates server and adds to startup....

Creates server and adds to startup....

There is definitely something malicious about this email.  Time to throw it into a virtual machine and try to analyze safely.  In my linux machine, opening the .html file opens this up....

Rut Roh.....

Rut Roh.....

Double extensions....PDF to make the end user believe he is downloading a copy of the invoice to read in Adobe, but is it?  .scr extensions are often used for Screen Savers in the Windows world, or as an extension for a script.

Let's pop the URL that we downloaded the file from and see if protection is up to date?

Only one URL scanner showing this as malicious

Only one URL scanner showing this as malicious

Moral of the story is if it waddles like a duck and quacks like a duck, it is probably a duck, and this duck will make your system sick.  Never click on unexpected attachments or links in email without verifying from source.

If you have questions about a file, don't hesitate to use tools like VirusTotal and Malwr for them to analyze and help security companies improve their tools with malware samples.

Comment

Comment

I tried to see soccer as...

..."the beautiful game," but to be honest, it is tough to see. While the games can be exciting, and the precision of many ball strikes, but there are many things that is hard to overlook.

1.  The insistence of calling it football.  I guess technically it is, but when it wa originally formed it was called association football to differentiate it from other "footballs" like rugby football and American football.  It is just another football sport, not THE football. 

2.  FIFA.  It is hilarious how inept/corrupt this organization is.  Where can we start?

- Qatar 2022.  Who the heck thinks it is a good idea to play soccer in the desert?  No infrastructure, no grass, lots of bribes from the oil money.

- Add in ingredients such as match fixing, player bribes, blind refs, biting, etc and get more drama than a WWE event.

3.  Flopping.  These players flop around the field worse thatpn a fish on a line. You are supposed to be men.  Don't fake an injury on the slightest touch. 

 

Socce...can't love you.  But I can watch with some enjoyment...kinda like hockey.   

Comment