{"id":6759,"date":"2017-02-23T08:41:04","date_gmt":"2017-02-23T16:41:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/02\/23\/news-550\/"},"modified":"2017-02-23T08:41:04","modified_gmt":"2017-02-23T16:41:04","slug":"news-550","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/02\/23\/news-550\/","title":{"rendered":"Did you order those iTunes movies? Nope, it\u2019s just phishing for Canadian Apple users"},"content":{"rendered":"<p><strong>Credit to Author: Lilia Elena Gonzalez Medina| Date: Thu, 23 Feb 2017 08:37:16 -0800<\/strong><\/p>\n<div class=\"entry\">\n<p>Over the weekend, we encountered an interesting variation of a phishing email targeting Apple users. The email contained an alleged receipt for five movies purchased from the iTunes Store that was so detailed that the user who received it, and who knows better, still almost fell for the scam.<\/p>\n<p><img decoding=\"async\" alt=\"Phishing Apple email\" src=\"https:\/\/d3gpjj9d20n0p3.cloudfront.net\/ngblog\/uploads\/files\/CA%20apple%20users%201.png\" style=\"width: 900px; height: 1144px;\" \/><\/p>\n<p align=\"center\">Figure 1. Phishing Apple email<\/p>\n<p>Similar <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2015\/10\/steer-clear-of-this-apple-invoice-phish\/\">cases<\/a> were reported in 2015 by users in the <a href=\"http:\/\/metro.co.uk\/2016\/06\/10\/heres-how-to-tell-if-your-itunes-invoice-is-a-scam-5935344\/\">UK<\/a> and <a href=\"http:\/\/www.scamnet.wa.gov.au\/scamnet\/Scam_Types-Buying_selling_and_online_sales_scams-Fake_iTunes_receipt_phishing_email.htm\">Australia<\/a>, except in those cases the fake receipt contained songs and books, respectively. Last year, similar emails targeting users in the US were also <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2015\/10\/steer-clear-of-this-apple-invoice-phish\/\">reported<\/a>, although they contained several errors that identified them as scams, such as: the word &ldquo;Invoice&rdquo; instead of &ldquo;Receipt&rdquo;, the lack of a valid value for the &ldquo;Billed to&rdquo; field, the wrong amount in the total, etc. The latest variation targeting Canadian users, however, does not seem to contain any of those mistakes. In fact, all the chosen movies are recent, which gives the email a more realistic appearance.<\/p>\n<h2>Phishing website<\/h2>\n<p>At the bottom of the receipt, there&rsquo;s a link to request a &ldquo;full refund&rdquo; in case of an unauthorized transaction. Needless to say, it does not redirect to the legitimate &ldquo;My Apple ID&rdquo; website, but to the URL hy654reewe(.)serveftp(.)org\/serveritunescanada\/index(.)html. Although this site was already offline at the time of this report, it was still possible to access the phishing website by replacing the domain name with the IP address, as shown in Figure 2, below.<\/p>\n<p><img decoding=\"async\" alt=\"Fake Apple website to steal credit card information\" src=\"https:\/\/d3gpjj9d20n0p3.cloudfront.net\/ngblog\/uploads\/files\/CA%20apple%20users%202.png\" style=\"width: 963px; height: 835px;\" \/><\/p>\n<p align=\"center\">Figure 2. Fake Apple website to steal credit card information<\/p>\n<p>To request a &ldquo;refund, the victim is directed to fill out an online form. Besides the normal spaces for entering credit card and other personal information information, the form also includes fields for entering a &ldquo;Social insurance number,&rdquo; which is the number needed in Canada to work or to access government programs and benefits, as well as for a &ldquo;Mother&rsquo;s Maiden Name,&rdquo; which is one of the frequently asked questions used to recover a forgotten password.<\/p>\n<p><img decoding=\"async\" alt=\"POST request with the stolen data\" src=\"https:\/\/d3gpjj9d20n0p3.cloudfront.net\/ngblog\/uploads\/files\/CA%20apple%20users%203.png\" style=\"width: 975px; height: 504px;\" \/><\/p>\n<p align=\"center\">Figure 3. POST request with the stolen data<\/p>\n<p>When the user fills out the form and clicks the &ldquo;Cancel transaction&rdquo; button, the data is processed in plain text with a PHP script. After the site steals the data, the user is then redirected to the legitimate Apple website. As a side note, the email address terjxxxx@online.no associated with this site is Norwegian.<\/p>\n<h2>Other URLs found<\/h2>\n<p>In addition to the URL previously mentioned, further research led us to two other domains related to this phishing campaign that are also hosted on IP address 109.228.49.213:<\/p>\n<ul>\n<li>htr54reewe3.is-a-geek.org\/serveritunescanada\/index.html<\/li>\n<li>hyt54reerwrewq.gets-it.net\/serveritunescanada\/index.html<\/li>\n<\/ul>\n<h2>We have you covered<\/h2>\n<p>Despite being so new, these phishing sites were already identified and blocked by <a href=\"https:\/\/fortiguard.com\/iprep?data=109.228.49.213\">Fortinet&rsquo;s Web Filter<\/a>, as noted by <a href=\"http:\/\/urlquery.net\/report.php?id=1487576524727\">urlquery.net<\/a>. And the information related to the phishing email and website had also already been reported to Apple.<\/p>\n<p><img decoding=\"async\" alt=\"Fragment of the report about the phishing URL in urlquery.net\" src=\"https:\/\/d3gpjj9d20n0p3.cloudfront.net\/ngblog\/uploads\/files\/CA%20apple%20users%204.png\" style=\"width: 975px; height: 314px;\" \/><\/p>\n<p align=\"center\">Figure 4. Fragment of the report about the phishing URL in urlquery.net<\/p>\n<p>To better protect you from these sorts of phishing attacks, we recommend you read <a href=\"https:\/\/support.apple.com\/en-us\/HT201679\">Apple&rsquo;s tips<\/a> to help you identify legitimate emails from the iTunes Store. And in case you receive a suspicious email, you can also <a href=\"http:\/\/www.apple.com\/legal\/more-resources\/phishing\/\">report it here<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/ftnt.net\/2iT7Mcp%C2%A0\"><i>Sign up<\/i><\/a><i>&nbsp;for weekly Fortinet FortiGuard Labs Threat Intelligence Briefs and stay on top of the newest emerging threats.<\/i><\/p>\n<\/div<br \/><a href=\"http:\/\/blog.fortinet.com\/2017\/02\/23\/did-you-order-those-itunes-movies-nope-it-s-just-phishing-for-canadian-apple-users\" target=\"bwo\" >https:\/\/blog.fortinet.com\/feed<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/d3gpjj9d20n0p3.cloudfront.net\/ngblog\/uploads\/files\/CA%20apple%20users%201.png\"\/><\/p>\n<p><strong>Credit to Author: Lilia Elena Gonzalez Medina| Date: Thu, 23 Feb 2017 08:37:16 -0800<\/strong><\/p>\n<p>Over the weekend, we encountered an interesting variation of a phishing email targeting Apple users. The email contained an alleged receipt for five movies purchased from the iTunes Store that was so detailed that the user who received it, and who knows better, still almost fell for the scam.        Figure 1. Phishing Apple email    Similar cases were reported in 2015 by users in the UK and Australia, except in those cases the fake receipt contained songs and books, respectively. Last year, similar emails targeting users in the US were also reported,&#8230;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10424,10378],"tags":[],"class_list":["post-6759","post","type-post","status-publish","format-standard","hentry","category-fortinet","category-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6759"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6759\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}