{"id":13426,"date":"2018-09-25T02:10:05","date_gmt":"2018-09-25T10:10:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/09\/25\/news-7193\/"},"modified":"2018-09-25T02:10:05","modified_gmt":"2018-09-25T10:10:05","slug":"news-7193","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/09\/25\/news-7193\/","title":{"rendered":"100 channels and nothing on, except TV Licensing phishes"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 25 Sep 2018 09:00:00 +0000<\/strong><\/p>\n<p>We\u2019ve seen a lot of people referencing fake TV Licensing emails they\u2019ve received over the last few days. The majority so far appear to be fake refund notices, asking potential victims to log in to a phony TV License website and provide payment details for refunds. It&#8217;s definitely keeping customer support busy:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25633\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/attachment\/licensing-twitter\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter.jpg\" data-orig-size=\"566,832\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"licensing twitter\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter-204x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter-408x600.jpg\" class=\"aligncenter size-medium wp-image-25633\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter-204x300.jpg\" alt=\"licensing twitter\" width=\"204\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter-204x300.jpg 204w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter-408x600.jpg 408w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/licensing-twitter.jpg 566w\" sizes=\"auto, (max-width: 204px) 100vw, 204px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>Many of the URLs we\u2019ve looked at are down now, but not all, so we thought we\u2019d take a look.<\/p>\n<p>The scam pages are what we\u2019d describe as functional; a fairly accurate depiction of what one might expect to see on a genuine refund page hosted on the <a href=\"https:\/\/www.tvlicensing.co.uk\" target=\"_blank\" rel=\"noopener\">TV Licensing website<\/a>. In this example, the site claims the visitor is owed a \u00a3147 refund, though there are variable amounts quoted in the scam mails, as we\u2019ll see later.<\/p>\n<p>Here\u2019s one of the scam sites in question, located at:<\/p>\n<p>tv(dot)licensing(dot)secured(dot)ref(dot)pbmsim(dot)com\/tv-secure\/<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site.jpg\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25632\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/attachment\/fake-license-site\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site.jpg\" data-orig-size=\"993,929\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"fake license site\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site-300x281.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site-600x561.jpg\" class=\"aligncenter size-medium wp-image-25632\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site-300x281.jpg\" alt=\"fake license site\" width=\"300\" height=\"281\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site-300x281.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site-600x561.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/fake-license-site.jpg 993w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>Alongside the usual personal information scammers like to obtain, the site wants both card details and bank account information, which could result in extended discussions with the bank afterwards to get everything straightened out. They also ask for mother\u2019s maiden name, presumably for additional social engineering attempts further down the line (or even just a general grab for a password reset answer).<\/p>\n<p>As with many of these scams, the site claims the victim needs to give \u201ctwo to three days\u201d to allow for the refund to be processed. This is a tactic as old as the hills to give the scammers enough breathing room to do their damage while the victim does nothing, eagerly awaiting a refund that\u2019s never going to arrive.<\/p>\n<h3>General observations<\/h3>\n<p>A lot of the sites finding their way into people&#8217;s inboxes may not be from the same campaign, and as a result, they&#8217;re all doing many different things. Below, we&#8217;ve tried to pin down some of the common patterns we&#8217;ve seen from this spam blast.<\/p>\n<p>1) Some of the sites currently bouncing around have a copyright notice of 2017, whereas the rest say 2018. While this probably isn\u2019t enough to tip someone off that the site they\u2019re looking at is a fake, it might help tip the balance for some.<\/p>\n<p>2) We haven&#8217;t seen any HTTPs sites (yet), but that doesn&#8217;t mean they&#8217;re not out there. This is the part where we gently remind everyone that phishing pages can and do make use of HTTPs to make things look more legitimate, and given the amount of free certificate services on offer, it&#8217;s not exactly difficult to achieve. Here&#8217;s what you see on the non secure site up above from our example:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/cert-info.jpg\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25635\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/attachment\/cert-info\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/cert-info.jpg\" data-orig-size=\"551,509\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"(Lack of) certificate info\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/cert-info-300x277.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/cert-info.jpg\" class=\"aligncenter size-medium wp-image-25635\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/cert-info-300x277.jpg\" alt=\"(Lack of) certificate info\" width=\"300\" height=\"277\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/cert-info-300x277.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/cert-info.jpg 551w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p>3) Refund amounts and deadlines listed in the mails vary widely. We&#8217;ve seen a few people complaining about <a href=\"https:\/\/twitter.com\/tvlicensing\/status\/1044119815412219905\" target=\"_blank\" rel=\"noopener\">phishing attempts in the region of \u00a3124.50<\/a>, with 30\u00a0September being given as the deadline to process any refund requests. The longest deadline time we\u2019ve seen is \u201c<a href=\"https:\/\/twitter.com\/tvlicensing\/status\/1044121503099482112\" target=\"_blank\" rel=\"noopener\">2 to 4 weeks<\/a>,\u201d which is an incredibly long time for a scammer to assume a potential victim will still be waiting around for their money.<\/p>\n<p>The largest fake refund amount we\u2019ve seen cited so far is <a href=\"https:\/\/twitter.com\/kazzer225\/status\/1040938503675281409\" target=\"_blank\" rel=\"noopener\">a whopping \u00a3492.57<\/a>. Given that a colour TV License costs <a href=\"https:\/\/www.tvlicensing.co.uk\/faqs\/FAQ23\" target=\"_blank\" rel=\"noopener\">somewhere in the region of \u00a3150<\/a>, there\u2019s no possible way someone could be owed close to \u00a3500 for a year\u2019s worth of TV Licenses unless something had gone massively wrong.<\/p>\n<p>4) The sites look similar, but don&#8217;t follow a uniform template. Below is one (now offline) example, which looks quite a bit different from the one up above, separating the various requests for information onto separate pages.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site.jpg\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"25634\" data-permalink=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/attachment\/another-fake-site\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site.jpg\" data-orig-size=\"735,570\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"another fake site\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site-300x233.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site-600x465.jpg\" class=\"aligncenter size-medium wp-image-25634\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site-300x233.jpg\" alt=\"another fake site\" width=\"300\" height=\"233\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site-300x233.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site-600x465.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/another-fake-site.jpg 735w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p style=\"text-align: center;\">Click to enlarge<\/p>\n<p style=\"text-align: left;\">5) There\u2019s also been a few mentions of <a href=\"https:\/\/twitter.com\/tvlicensing\/status\/1044127189845897216\" target=\"_blank\" rel=\"noopener\">dubious PDF attachments<\/a>\u00a0on Twitter, but so far no word as to if they\u2019re loaded with malware or simply an additional part of the phish. Some scammers will attempt to make their missives look more legitimate with fancily thrown together PDFs to give everything an extra veneer of &#8220;this is definitely the real thing.&#8221; Just because an attachment is present, doesn\u2019t necessarily mean it\u2019s an infection file. (Of course, we\u2019d never advise opening one to check.)<\/p>\n<h3>Final thoughts<\/h3>\n<p>This isn&#8217;t an overly complicated scam, but then again, it doesn&#8217;t need to be. Asking for a few hundred pounds from people here and there quickly adds up, and fear of not paying your TV License on time is almost something of a <a href=\"https:\/\/www.theguardian.com\/society\/2014\/sep\/24\/in-court-non-payment-tv-licence-television-desperate-cases\" target=\"_blank\" rel=\"noopener\">panic reflex<\/a> for the British. It makes sense, then, for scammers to take advantage of people&#8217;s wariness and thank their lucky stars for a too-good-to-be-true license refund.<\/p>\n<p>If you&#8217;re worried, check out the TV License website&#8217;s <a href=\"https:\/\/www.tvlicensing.co.uk\/faqs\/FAQ288\" target=\"_blank\" rel=\"noopener\">advice on phishing scams<\/a>, and be wary of any emails claiming to offer up cash, no matter the amount. There&#8217;s a good chance the missive in front of you needs to be deposited where it belongs: in the recycle bin.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/\">100 channels and nothing on, except TV Licensing phishes<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Tue, 25 Sep 2018 09:00:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/' title='100 channels and nothing on, except TV Licensing phishes'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/09\/shutterstock_1124691116.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>A recent bout of TV Licensing phishing emails promise British users a refund once they log in to a phony TV License website and provide payment details. Read on to see if you&#8217;ve been impacted.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/email\/\" rel=\"tag\">email<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fake\/\" rel=\"tag\">fake<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fraud\/\" rel=\"tag\">fraud<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phish\/\" rel=\"tag\">phish<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/phishing\/\" rel=\"tag\">phishing<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/scam\/\" rel=\"tag\">scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/social-engineering\/\" rel=\"tag\">Social Engineering<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tv-license\/\" rel=\"tag\">tv license<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/' title='100 channels and nothing on, except TV Licensing phishes'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/09\/100-channels-and-nothing-on-except-tv-licensing-phishes\/\">100 channels and nothing on, except TV Licensing phishes<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[4503,11222,11539,9751,10511,3924,3985,10510,19572],"class_list":["post-13426","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cybercrime","tag-email","tag-fake","tag-fraud","tag-phish","tag-phishing","tag-scam","tag-social-engineering","tag-tv-license"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13426","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=13426"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/13426\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=13426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=13426"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=13426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}