{"id":7038,"date":"2017-03-20T06:11:29","date_gmt":"2017-03-20T14:11:29","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/20\/news-829\/"},"modified":"2017-03-20T06:11:29","modified_gmt":"2017-03-20T14:11:29","slug":"news-829","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/20\/news-829\/","title":{"rendered":"Twitter app spams Fappening bait and Amazon surveys"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 20 Mar 2017 13:37:07 +0000<\/strong><\/p>\n<p>With news of another so-called Fappening (nude photos of celebrities distributed without permission)\u00a0<a href=\"http:\/\/metro.co.uk\/2017\/03\/19\/nude-photos-of-arrows-katie-cassidy-and-dylan-penn-leak-online-6519826\/\" target=\"_blank\">doing the rounds<\/a>, it was inevitable that scammers would look to take advantage. We\u2019ve already seen message board aficionados warn others of dodgy download links and random Zipfiles claiming to contain stolen nude photos and video clips, but today we\u2019re going to look at one specific spam campaign aimed at Twitter users.<\/p>\n<p>The daisy chain begins with multiple links claiming to display stolen images of Paige, a well known WWE wrestler, caught up in the latest dump of files. With regards to two specific messages, we saw close to 300 over a 24 hour period (and it&#8217;s possible there were others we didn&#8217;t see). These appear to have been the most common, however.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-spam.jpg\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16900\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-spam-239x300.jpg\" alt=\"app spam\" width=\"239\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-spam-239x300.jpg 239w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-spam-478x600.jpg 478w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-spam.jpg 540w\" sizes=\"auto, (max-width: 239px) 100vw, 239px\" \/><\/a><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/search-result.jpg\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16899\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/search-result.jpg\" alt=\"search result\" width=\"282\" height=\"43\" \/><\/a><\/p>\n<p>The messages read as follows:<\/p>\n<blockquote>\n<p><em><strong>1)<\/strong> &#8220;VIDEO: WWE Superstar Paige Leaked Nude Pics and Videos&#8221;<\/em><\/p>\n<p><em><strong>2)<\/strong> &#8220;Incredible!!! Leaked Nude Pics and Videos of WWE Superstar Paige!!!!: [url] (Acept the App First)&#8221;<\/em><\/p>\n<\/blockquote>\n<p>Well, that doesn\u2019t sound suspicious at all.<\/p>\n<p>The Bit(dot)ly link, so far clicked close to 7,000 times, resolves to the following:<\/p>\n<p>twitter(dot)specialoffers(dot)pw\/funnyvideos\/redirect(dot)php<\/p>\n<p>That smoothly segues into\u00a0an offered Twitter App install tied to a site called Viralnews(dot)com.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-install.jpg\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16901\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-install-300x281.jpg\" alt=\"app install\" width=\"300\" height=\"281\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-install-300x281.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-install-600x563.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/app-install.jpg 762w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The app permissions are as follows:<\/p>\n<blockquote>\n<p><strong><em>This application will be able to:<\/em><\/strong><\/p>\n<p><em>Read Tweets from your timeline.<\/em><br \/> <em> See who you follow, and follow new people.<\/em><br \/> <em> Update your profile.<\/em><br \/> <em> Post Tweets for you.<\/em><\/p>\n<p><strong><em>Will not be able to:<\/em><\/strong><\/p>\n<p><em>Access your direct messages.<\/em><br \/> <em> See your email address.<\/em><br \/> <em> See your Twitter password.<\/em><\/p>\n<\/blockquote>\n<p>We&#8217;ll come back to the app later, but as far as the Viralnews goes, it appears to play\u00a0no part in what lies ahead (and looks like a very retro linkdump site). Once the app is installed, would-be picture viewers are sent to a site located at<\/p>\n<p>specialoffers(dot)pw\/paige-leaked-video<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/landing-page.jpg\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16902\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/landing-page-238x300.jpg\" alt=\"landing page\" width=\"238\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/landing-page-238x300.jpg 238w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/landing-page-477x600.jpg 477w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/landing-page.jpg 777w\" sizes=\"auto, (max-width: 238px) 100vw, 238px\" \/><\/a><\/p>\n<p>The site\u00a0reinforces the idea that salacious stolen imagery is on the way &#8211; except that the site quickly greys out and makes it clear you have to click yet another link to continue. It\u2019s another bit(dot)ly (highlighted in the bottom left hand corner), which (after another redirect) took us\u00a0to the following URL:<\/p>\n<p>brazzershd(dot)co\/PaigeVideos<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/promo-splash.jpg\" data-rel=\"lightbox-4\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16903\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/promo-splash-300x281.jpg\" alt=\"promo splash\" width=\"300\" height=\"281\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/promo-splash-300x281.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/promo-splash-600x561.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/promo-splash.jpg 924w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>We have a landing page, still promising stolen images (and indeed, serving one up) with the continuing promise of more to come. From the blurb:<\/p>\n<blockquote>\n<p><em><strong>1<\/strong> First Click on the Bottom Download<\/em><br \/> <em><strong> 2<\/strong> Then you will be redirected to an Amazon Giftcard Website where you have to Leave your Email<\/em><br \/> <em><strong> 3<\/strong> Leave your Email in the Blank Box to win an Amazon Giftcard and Click on SUBMIT<\/em><br \/> <em><strong> 4<\/strong> Then You will be Redirected to a MEGA Download where you could Download Paige Leaked Videos and Photos<\/em><\/p>\n<\/blockquote>\n<p>As per the screenshot, there&#8217;s one final redirect URL (a bit(dot)do address) which took us\u00a0to an Amazon themed survey gift card page. Suffice to say, filling this in hands your personal information to marketers &#8211; and there&#8217;s no guarantee you&#8217;ll get any pictures at the end of it (and given the images have been stolen without permission, one might say the people jumping through hoops receive their just desserts in the form of a large helping of &#8220;nothing at all&#8221;).<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/amazon-giftcards.jpg\" data-rel=\"lightbox-5\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16904\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/amazon-giftcards-300x225.jpg\" alt=\"amazon giftcards\" width=\"300\" height=\"225\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/amazon-giftcards-300x225.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/amazon-giftcards-600x450.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/amazon-giftcards.jpg 900w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>At this point, it&#8217;s time to return to the app and see what it&#8217;s been up to on the Twitter account we installed it on:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/twitter-spam-pile.jpg\" data-rel=\"lightbox-6\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-16905\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/twitter-spam-pile-132x300.jpg\" alt=\"twitter spam pile\" width=\"132\" height=\"300\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/twitter-spam-pile-132x300.jpg 132w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/twitter-spam-pile-263x600.jpg 263w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/twitter-spam-pile.jpg 406w\" sizes=\"auto, (max-width: 132px) 100vw, 132px\" \/><\/a><\/p>\n<p>Automated spam posts, complete with yet more pictures used as bait.<\/p>\n<p>As freshly leaked pictures and video of celebrities continue to be dropped online, so too will scammers try to make capital out of image-hungry clickers. Apart from the fact that these images have been taken without permission so you really shouldn&#8217;t be hunting for them, anyone going digging on less than reputable sites is pretty much declaring open season on their computers. Do yourself a favour and leave this leak alone. It probably won&#8217;t be long before the Malware authors and exploit slingers roll into town.<\/p>\n<p>Christopher Boyd<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/twitter-app-spams-fappening-bait-amazon-surveys\/\">Twitter app spams Fappening bait and Amazon surveys<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/twitter-app-spams-fappening-bait-amazon-surveys\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 20 Mar 2017 13:37:07 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/twitter-app-spams-fappening-bait-amazon-surveys\/' title='Twitter app spams Fappening bait and Amazon surveys'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2014\/05\/photodune-6673623-the-guy-in-a-shock-s.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>With news of another so-called Fappening (nude photos of celebrities distributed without permission)\u00a0doing the rounds, it was inevitable that scammers would look to take advantage. We\u2019ve already seen message board aficionados warn others of dodgy download links and random Zipfiles claiming to contain stolen nude photos and video clips, but today we\u2019re going to look&#8230;<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/social-engineering-cybercrime\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/amazon\/\" rel=\"tag\">amazon<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/app\/\" rel=\"tag\">app<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fappening\/\" rel=\"tag\">fappening<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/paige\/\" rel=\"tag\">Paige<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spam\/\" rel=\"tag\">spam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/survey\/\" rel=\"tag\">survey<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/twitter\/\" rel=\"tag\">twitter<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/twitter-app-spams-fappening-bait-amazon-surveys\/' title='Twitter app spams Fappening bait and Amazon surveys'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/twitter-app-spams-fappening-bait-amazon-surveys\/\">Twitter app spams Fappening bait and Amazon surveys<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[5588,4382,4503,11684,11685,10510,10518,887,454],"class_list":["post-7038","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-amazon","tag-app","tag-cybercrime","tag-fappening","tag-paige","tag-social-engineering","tag-spam","tag-survey","tag-twitter"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7038","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7038"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7038\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7038"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}