Showing posts with label FTC. Show all posts
Showing posts with label FTC. Show all posts

Sunday, March 22, 2020

CAUCE Spamfighters Rally Against Corona Health Fraud Affiliate programs

My email box is full of Coronavirus / COVID-19 frauds and scams.  I have Corona malware disguised as product catalogs.  I have fake World Health Organization emails asking me to donate my Bitcoin to them.  I have more than 30 fake breathing mask selling websites that my friends at ScamSurvivors and AA419 are helping to track.  But you know what makes me REALLY MAD?

The monsters who are using the same fake news websites to drive their affiliate-marketing program scams to sell Immunity Oil to people who are desperate to protect their families and loved ones.  As a member of the CAUCE Board (the Coalition Against Unsolicited Commercial Email) I immediately reached out to Neil Schwartzman, my personal spam fighting hero and the founder of CAUCE.  Even though we both know these are the same snake oil charlatans who have been in the spam business for a decade, perhaps now that they are putting people's lives in true danger someone will finally do something to shut these scammers and spammers down.  (Note, I'm not speaking for CAUCE here, I'm just mentioning that I'm proud to fight spammers with them.)

The first claim we'll face, of course, is that "we don't claim that our product fights the Corona Virus."

My first refutation would be the email subjects being used to spam their products.  The first email I got yesterday was this one, with the subject "Protection From Corona Virus With Immunity Oil"

Delivery-date: Sat, 21 Mar 2020 17:06:42 -0500
Received: from [49.12.47.247] (port=47288 helo=urrmwipzqlpakl.xyz)
From:Miracle Virus Oil 
Subject:Protection From Corona Virus With Immunity Oil
https://malkommal.ams3.digitaloceanspaces.com/immcoronfgdf.htm

Here's the screenshot of the email message I received this afternoon.
Please note the email subject:
"Fight back against the coronavirus outbreak! Pure Herval Total Defense Immunity Blend"



Visiting many spammed URLs will result in 404 pages, because they have to be visited through the correct chain of referring URLs, which is one defensive measure that Spamfighter Schwartzman and I are well accustomed to.

The latter email contains the URL: 

which in turn forwards to 

The "CID" "AFID" and "SID" are the Campaign ID, and the Affiliate ID. Affiliate 428186 is the one who will get paid for this sale, if I were stupid enough to buy it.  The Campaign ID is necessary, because the company is marketing the product with many different labels and "look and feel" packaging.  For example, some of the Immunity Blend claims to be a "CBD Oil" that protects you from Corona Virus because CBD has anti-inflammatory properties ... like this ad, which claims it is a "Corona Mom Advertorial."


No matter which of the fake Immunity Blend appeals you start with, you'll end up (currently anyway) on the website Apusserum.com ... one of my click-throughs had this targeting label set:



Notice the little pop-ups in the bottom left ... messages popping up non-stop about all
of the other customers buying this stuff non-stop!

Clicking through from a different affiliate, I end on a different looking sales page, but clearly the same product being sold in a different bottle.





The claims made on the "orange cap" version are shown here, but short version.  You can clean your counters, purify the air, and "boost your immunity" by using it as a skin cream. The Essential Oil Mommies will love this stuff, it has Cinnamon Leaf, Lemon, Clove Bud, Lime, Eucalyptus Globulus, Rosemary, Peppermint, Spearmint, and Oregano.  None of which, last I checked, are an alcohol based disinfectant, or an anti-viral.

Of course they are carefully saying NOTHING about it treating viruses of any sort on the actual product page.  We'll just put a huge coronavirus image on the page as a pretty medical picture without making any claim about that.

The stuff that sounds like science there is from the same source that was used to sell essential oil / snake oil during the H1N1 flu scare in 2010 (one such product was called "On Guard").  If you'd like to read the article, it's here:  Protective essential oil attenuates influenza virus infection: An in vitro study in MDCK cells. )

Fake Fox News?

No matter which entry point you visit to get started, a link in one of the many spam messages, or a link from social media (we've found sellers on both Twitter and Facebook, and reported them for removal.)  The first site you visit will be a pseudo-news site that SEEMS to be somehow related to Fox News, without EXACTLY saying that ... while it isn't saying you are on Fox News, it is giving the byline for this story to "Janine Puhak | Fox News" and at the bottom of the page, repeats this by providing Janine's Twitter handle -- @JaninePuhak, and beneath the first main photo, it says "Fox News Flash Top Headlines for March 23, 2020" and "Check out what's clicking on FoxNews.com."

www.mynutritionalnews.com/fox_virusout/  or  dailyxhealth.com/us-cv-1/ as examples
(Note that you may need to be "referred" from the right URL for this content to load)
While some of the sites have hidden the Fox News logo, others have not.  This one still has it, for example.
https://www.outbreakliveupdates.com/foxnews_outbreak/  . affid=428139&subid=6606 
Others had gone even further to "De-Fox" themselves:

https://www.healthy-tips.life/healthytips_cor/
Healthy-Tips.life changed the logo and byline to be "World Break News" without changing a single word of the article.

The Second Scam 

The first scam is that you are buying a fake product that you think will help you with Corona Virus.  The second scam is that they are going to bill you more and more frequently than you think, and based on the Better Business Bureau complaints against many other companies run by the same outfit at the same address, this will probably happen to you as well.

The product Terms and Services says that if you don't cancel your order within the allotted time, you'll start being billed $89.95 per month on the credit card you provided at the time of the order.  The company named in the Terms and Services is:

Finest Herbalist
PO Box 534
Pleasant Grove, UT 84062

The "Contact Us" page gives this information:

Contact Us
You can contact Finest Herbalist Customer Service for any questions, comments, or testimonials.

Phone: 1 (844) 899-2977
Email: help@finestherbalist.com
Hours of Operation: 8am to 8pm EST daily


A company named "Herbalist Oils" that coincidentally is also at PO Box 534 in Pleasant Grove, Utah, has an "F" grade from the Better Business Bureau with complaints such as these:


07/20/2019
Herbalist Oils, also known as First Class Herbalist CBD, of 4Bush Holdings, LLC is a scam. They offer a free bottle of CBD oil and latter I found out my bank account to be charged over 200.00 plus 89.99 thereafter for a subscription that I was unaware of for "Deep sleep" roll on. I contact them via email many times and they did not answer. There is nowhere on their website page that states this is a monthly subscription or that one will be charged more than the shipping fee for a free bottle of CBD oil. They ended up sending me 6 bottles of CBD oil. The oil is substandard and does not live up to its claims, however, I thought like some medications one might need to wait a few weeks for it to work....it never did. I then ended up receiving a bottle of deep sleep again and thought that this was another mistake on their behalf. I wrote them an email regarding this but I heard nothing back. After a few more months of this bottle being sent to me and not being able to get a return email from them, I finally called customer service. On the first phone call, I was told the subscription was canceled and my bank was never charged Subscription? this is the first I heard of any subscription. I then reviewed my bank statements and found indeed I was charged monthly as well as being charged over 200.00 initially. I called their customer service again and after some discussion, I was able to get two months of the 89.00 charges refunded. They stated since it's over the 30 day refund time no other refund will be allowed. The refunds never showed up in my bank account.

Curiously, there are even more businesses at PO Box 534 in Pleasant Grove, Utah.  In fact, there are at least 45 Better Business Bureau complaints in the past 3 years for businesses at that address, including:

  • Keto Ultra Diet
  • Manifest Health Plan
  • Primal Pro Wellness
  • Sunshine Heath and Wellness
  • Plant Pure Diet and Beauty
  • Tru Slim Living
A summary of the 45 complaints against them is available from the Better Business Bureau website.  But they all say basically the same thing.  "I thought I was getting a free trial product for $4.95 shipping, but then they charged me $89.95 (or other numbers, up to $200) and I couldn't get them to stop!"


Other businesses at the same address include: 

Keto Trim Diet
Keto Melt & Trim 800 
Keto Pro Diet 
Forskolin Trim Diet 
Body Performa Keto 
Healthy Rapid 
Ansa Naturals Online 

So how does the Affiliate program work?  First, you need to sign up for a slimy affiliate program.  Most of the CoronaVirus spam that you are getting right now probably comes from affiliaXe, an affiliate program that clearly doesn't care whether their affiliates are selling real products or snake oil, and don't mind paying people a commission to get caught in credit card no-refund scams.  Take a look at your CoronaVirus spam ... then look at the products AffiliaXe is marketing.


That's some of my Corona Virus spam for the past day ... big spammers: Breathing masks, Germidin, and Thermosense "touchless" thermometers. Everybody has an affiliate program. H8M8.  Konex. 






Masks, Wipes, Germidin, SafeMasks, UV Cleaners, Smart Sanitizer Pro, Immunity Blend (as above) and the Survival CoronaVirus Pandemic Guide are the top programs looking for spammers (oops! I mean Affiliates!) at AffiliaXe right now ... 

Why so many people pushing Immunity Blend right now?  Well, of all the products at AffiliaXe, its the only one offering a $90 Commission for your first sale!   Compare below:


If you visit the live AffPlus site, each of those lines has a "link" icon appear when you hover over it.  So, yes, we can confirm that clicking the "preview link" on the Immunity Oil affiliate program from AffiliaXe really does take you to the Apus Serum website as above. ( https://apusserum.com/os-immune ).   And since every AffiliaXe affiliate has to upload a photo of their drivers license to join the program, it should be pretty easy for someone who cares about these scammers to shut them down.

Some of those other sites in this affiliate program are:

https://buywowx.com/
https://www.getlifeprotectx.com/
https://www.getsafemask.com/
https://www.getlifeprotectx.com/
https://hyperstech.com/intl_5/order.php?prod=uvcleanizerzoom
https://hyperstech.com/intl_5/order.php?prod=smartsanitizerpro
https://apusserum.com/os-immune
https://shopsafemask.com/
https://hyperstech.com/intl_5/order.php?prod=oxybreathpro
https://offer.premiumslimdiet.com/khs-beach-mcc/



Saturday, June 01, 2019

SMS Phish? Amazon Reward!

Are you getting text messages about winning prizes at Amazon?

I got one today with the following text from a VOIP-to-SMS number: 1 (410) 200-910

The text was:
 "FRM: You have a New Amazon Reward! MSG: http://dmkr3h.com/njngyw"

I threw up a Virtual Machine to check the destination, and got a meaningless echo of the domain name:



The problem, of course, was that they knew I was supposed to be on a cell phone, since they sent me an SMS.  No problem.  Let's make my Windows Chrome Browser a Cell Phone: 

Ok.  Now I'm a Firefox browser on an Android Mobile phone.  Let's try again.  Much better!  The CloudFlare hosted "dmkr3h" now forwards me to "simple-clubs.com" which is a CNAME alias to "seempts-explegal[.]com (35.169.148.30) " which passes my origin and affiliate data to chargingmilkshop[.]com (51.75.46.9), which forwards me to "winopinions[.]com (51.75.46.11)" which shows me this!


Before I take my Survey, I hit my "Back" button, just to see what happens, because often there are traps about such things.  Sure enough, hitting the "Back" took me to an ad totally unrelated to my Amazon Prize:


As much as I'd like to be Ketogenically Accelerated, I decided to go back to my original URL from the phone.  This time I landed at "ZoneOpinions[.]com" instead of WinOpinions, but since I was still on the same IP address, I decided to keep going and take the survey this time.  Here are my five Survey Questions:






OK, now for the excitement!  My big Amazon Reward is about to be revealed, right?





Hmmm... do I want a larger penis, a flatter belly, or a $780 watch?  I think I'll take the $780 watch, since its free and all ... 

Each time I click "Claim Reward" I get sent through a "1592track[.]com" redirector:
Which then forwards me to one of its randomly selected possible fulfillment domains ... 

getemergencygear[.]com
Odd.  Clicking on the watch takes me to a site for a free Tactical Flashlight. Oh well.  The point of this exercise is to feed some of my spam traps anyway.  We'll give them one of our spam trap email addresses just to see what they begin spamming to me. 

I wonder if ClickBank is complicit in these scams?
Since I'm not actually going to give them my credit card information, I'll see whether I get the same spam by submitting my address info for CBD Oil and Male Enhancement anyway.  Where do those clicks take me?
tryhealthoffer [.] com 


(a closer look at the Affiliate ID = 600080)

healthchoicev2 [.]com selling Primacin XL 


I saved which Spam Trap email I fed to each of the sites above.  If I start getting spam on them (none of them have existed before an hour ago and have never received any message prior to being fed to these sites) I'll do a follow-up post.

While trying to decide if this is something to share with my friends at the Federal Trade Commission, I decided to check what country these domains are hosted in ... Poland ... 

ipinfo.io/51.75.46.9 ==> OVH SAS in Poland.
According to the very useful tool at RiskIQ, it looks like 77 new domains stood up on this IP address about two days ago:
https://community.riskiq.com/search/51.75.46.9
We went ahead and exported that list so we could save a record of what other domains were there.  Looks like there are MANY alternative domains for doing the same sort of things ... 


resolvefirstSeenlastSeen
actionopinion.com5/30/20195/31/2019
airopinions.com5/30/20195/31/2019
alertandfocusednow.com5/30/20195/31/2019
alertandsharp.com5/30/20195/31/2019
blazingtea.com5/30/20195/31/2019
brainexpandnow.com5/30/20195/31/2019
brainexpandtoday.com5/30/20195/31/2019
brainexpandtonight.com5/30/20195/31/2019
cellopinion.com5/29/20195/31/2019
centeropinion.com5/30/20195/31/2019
chargingmilkshake.com5/30/20196/1/2019
companyopinions.com5/30/20195/31/2019
connectexclusive.com5/25/20195/31/2019
corpprogram.com5/30/20195/31/2019
dataopinions.com5/30/20195/31/2019
dreamopinions.com5/30/20196/1/2019
exclusivetrendingreport.com5/25/20195/31/2019
fitketonow.com5/30/20195/31/2019
fitketotoday.com5/30/20195/31/2019
fullyhardagain.com5/30/20195/31/2019
fullyhardtonight.com5/30/20195/31/2019
hardandlongagain.com5/30/20195/31/2019
hardandlonger.com5/30/20195/31/2019
hotbreakingreports.com5/30/20195/31/2019
hotnewstonight.com5/30/20195/31/2019
hotviralreports.com5/30/20195/31/2019
latestbreakingreport.com5/30/20195/31/2019
latestviralreport.com5/30/20195/31/2019
learningopinion.com5/30/20195/31/2019
lineprogram.com5/30/20195/31/2019
linkopinions.com5/30/20195/31/2019
linksprogram.com5/30/20195/31/2019
longandhardagain.com5/30/20195/31/2019
longandhardtonight.com5/30/20195/31/2019
longerhardernow.com5/30/20195/31/2019
lookprogram.com5/30/20195/31/2019
lumberingsoda.com5/30/20195/31/2019
magicopinions.com5/30/20195/31/2019
matchopinion.com5/30/20195/31/2019
maxopinions.com5/30/20195/31/2019
mindexpandnow.com5/30/20195/31/2019
monsterprogram.com5/30/20195/31/2019
newbreakingreport.com5/30/20195/31/2019
newbreakingreports.com5/30/20195/31/2019
newtrendingreport.com5/30/20195/31/2019
newtrendingreports.com5/30/20195/31/2019
newviralreport.com5/29/20195/31/2019
portalopinion.com5/30/20195/31/2019
projectopinions.com5/30/20195/31/2019
romanwatermelon.com5/25/20195/31/2019
rushingcoffee.com5/30/20195/31/2019
saveopinion.com5/30/20195/31/2019
shesreadytonight.com5/30/20195/31/2019
shoppingopinions.com5/30/20195/31/2019
slimketonow.com5/30/20195/31/2019
slimketotoday.com5/30/20195/31/2019
slimketotonight.com5/30/20195/31/2019
slowseltzer.com5/30/20195/31/2019
sluggishjuice.com5/29/20195/31/2019
sprintingspirits.com5/30/20195/31/2019
swiftespresso.com5/30/20195/31/2019
teamopinions.com5/30/20195/31/2019
thenewstrends.com5/30/20195/31/2019
tightketonow.com5/30/20195/31/2019
tightketotoday.com5/30/20195/31/2019
tightketotonight.com5/30/20195/31/2019
todaysbreakingstory.com5/25/20195/31/2019
tonightsbreakingstory.com5/25/20195/31/2019
totalbreakingnews.com5/30/20195/31/2019
touchopinion.com5/30/20195/31/2019
trendstonight.com5/30/20195/31/2019
whirlingmilk.com5/30/20195/31/2019
winopinions.com5/30/20196/1/2019
yournewsbreaks.com5/30/20195/31/2019
yournewstrends.com5/30/20195/31/2019
zoneopinions.com5/30/20195/31/2019
zoomingcider.com5/30/20195/31/2019

Many of these domains are proven to be interchangeable, as long as your user agent is right. Pasting the "path/file/parameters" from one site to another of the same type usually works.

Conclusion?  Don't think I'm going to get my Amazon Prize.  Darn.

Saturday, January 07, 2017

FTC Takes Action Against Insecure IoT Devices from D-Link

I still love to listen to GRC's Steve Gibson on the program Security Now! A few weeks back, Steve said "The S in IoT is for Security" which made me laugh perhaps far too much. As we discover more with each passing day, it seems there is no Security in the Internet of Things.
All of my readers will be well familiar by now with the Mirai botnet, which has demonstrated the capability to cause enormous DDOS attacks, including the 665 Gbps attack against Brian Krebs and the Dyn DNS Attack which crashed a substantial portion of the US Internet.

Both of these attacks were caused by an assortment of Internet of Things devices that have default vulnerabilities or default userid and passwords that in many cases not only are not reset by the users who install these devices in their homes, but in many cases CANNOT be changed! When several people have asked me what I think the answer was going to be to this problem, I've replied that this seems like a Consumer Protection issue and that I hoped the Federal Trade Commission would intervene. While some companies have issued voluntary recalls, such as XiongMai Technologies of China, who makes many whitebox DVR and IP-connected webcam components that are embedded into devices made by other manufacturers, most are washing their hands of responsibility.
Sample: XM Camera components

XiongMai claims (in a Chinese press release) that in their case the widely abused telnet problem was fixed in April of 2015, but they already had many million devices installed before that date.  Their letter to the Chinese Ministry of Justice about the issue is on the same link.

The FTC's Carrot 

The FTC seems to be taking a Carrot and Stick approach. The Carrot came first.  First, all the way back in November of 2013, the Federal Trade Commission held a special Workshop on Security & Privacy in the Internet of Things, gathering formal comments (including tweets) about the presented materials.  This led to their release in January of 2015 of a 71-page report "Internet of Things: Privacy and Security in a Connected World", as well as a 12-page report for IoT system designers called "Careful Connections: Building Security in the Internet of Things"

https://www.ftc.gov/iot-home-inspector-challenge

The FTC is also offering a $25,000 prize in a contest they are calling the IoT Home Inspector Challenge for the best idea on how to remediate the millions of vulnerable devices currently being abused on the Internet.    The competition will officially launch in March 2017 and run through July 2017.

But as warned about in the Jan 2015 report, the FTC also has a stick.  And D-Link just became the next to get hit with it!

The FTC's Stick: D-Link Gets Hit

The FTC released a trio of news announcements about the lawsuit that they filed in California against D-Link:


This first article focuses on the fact that D-Link knew how important security was to their consumers, and they took extra effort to stress the security of their devices in their advertisement.  FTC reporter Leslie Fair says: 

"D-Link Corporation and D-Link Systems, Inc., develop and sell routers, IP cameras, baby monitors and other products designed to integrate consumers’ home networks. If the company’s ads are any indication, D-Link was well aware of consumers’ concern about keeping those networks secure. Promising “Advanced Network Security,” D-Link’s promotional materials assured buyers that their routers “support the latest wireless security features to help prevent unauthorized access, be it from a wireless network or from the Internet.” Other ads touted a D-Link product as “not only one of the finest routers available, it’s also one of the safest.” Even the package for D-Link’s Digital Baby Monitor featured a lock icon with the phrase “Secure Connection” next to a picture of an adorable baby. The company repeated many of those security promises in the interactive interfaces consumers used to set up their D-Link products."

This article says that the lawsuit is primarily because D-Link failed to take "reasonable steps to prevent well-known security flaws."  Some examples listed include:

  • D-Link allegedly hard-coded login credentials into D-Link camera software that could allow unauthorized access to cameras’ live feed.
  • D-Link allegedly left users’ login credentials for its mobile app unsecured in clear, readable text on consumers’ devices.
  • D-Link allegedly mishandled its own private key code used to sign into D-Link software and as a result, it was publicly available online for six months.
  • D-Link allegedly failed to take reasonable steps to prevent command injection, a known vulnerability that lets attackers take control of people’s routers and send them unauthorized commands.
2. FTC sues D-Link over router and camera security flaws 

In this article, Consumer Education Specialist, Ari Lazarus, offers some tips to consumers for before and after they buy their router:

  • Before you buy or replace a device, do research online. Use search engines to find reviews, but be skeptical about the source of the information. Is it from an impartial security expert, a consumer, or the company itself?
  • Download the latest security updates. To be secure and effective, update the software that comes with your device. Check the manufacturer’s website regularly for new software and updates.
  • Change your pre-set passwords. Change the device’s default password to something more complex and secure.


This is the main report of the legal actions taken by the FTC against D-Link, with links to all filed documents, including the 45 page FTC Complaint for Permanent Injunction and Other Equitable Relief, with a 14 page complaint, followed by thirty pages of supporting documentation, including pictures of packaging and marketing claims that promise security.

The complaint alleges that the company failed to take steps to address "well-known and easily preventable security flaws" and gives several examples (which I provide context for in the links for each):

  • "hard-coded" login credentials in D-Link camera software, often the "guest/guest" userid and password (these devices were among those targeted by the Mirai botnet)
  • a software flaw known as "command injection" that allow hackers to execute unauthorized commands on D-Link routers (see for example CVE-2015-2049, CVE2015-2050, CVE-2015-2051) - security researcher Pierre Kim advised consumers to throw the security-flawed DWR-932B router in the trash, after documenting 20 known vulnerabilities.
  • mis-handling of a private key code used to sign in to D-Link software, leaving the code on a publicly accessible website for more than six months (as discussed in Ars Technica in September 2015)
  • leaving users' login credentials for D-Link's mobile applications unsecured in clear, readable text on their mobile devices, even though there is free software available to secure the information (this refers to the "mydlink Lite" app
mydlink Lite mobile app stored userid and pass in plaintext on mobile device

 

 The actual complaint says that the FTC is bringing suit "to obtain permanent injunctive relief and other equitable relief against Defendants for engaging in unfair or deceptive acts or practices in violation of Section 5(a) of the FTC Act, 15 U.S.C. § 45(a), in connection with Defendant's failure to take reasonable steps to secure the routers and Internet-protocol cameras they designed for, marketed, and sold to United States consumers."

We'll have to wait to see what the outcome of this suit will be, however in other IoT cases, the defendant has settled.

Other Actions of FTC Swinging Its Stick

 The action against D-Link is the third taken by the FTC.  

In February of 2016, the FTC announced a settlement with ASUS over their deceptive and misleading conduct related to the security of their routers.  In the FTC complaint against ASUS
, the FTC points out that ASUS claimed their routers offered "SPI intrusion detection" and "DoS protection" and that its routers could "protect computer from any unauthorized access, hacking, and virus attacks."  But 918,000 of those routers had a userid and password of "admin/admin" and the AiCloud and AiDisk features were full of vulnerabilities that put the advertised "secure cloud storage" data at risk.  ASUS agreed to submit voluntarily to security audits FOR THE NEXT TWENTY YEARS as part of their settlement.

In February of 2014, TRENDNET, a company that makes IP-connected webcams, advertised that their cameras were secure,  claiming that their Direct Video Stream Authentication setting would secure their video streams if they set a personal userid and password, rather than using the default passwords.  Hackers quickly showed that they could access every TRENDNET camera and view their live video streams, without any userid or password being provided.  The FTC settlement required TRENDNET to contact all customers to let them know about a security patch that would correct the situation, and require them to provide two years of technical support.







Friday, January 10, 2014

Target Database Breach "Phishing" Email leads to . . .

Several folks that also do security research called and texted and Facebook messaged today asking if we had seen "the New Target Phishing email"? We're normally pretty good folks to ask about that sort of thing, since Malcovery Security has both a Spam Data Mine, which is often a good source for such messages, and our PhishIQ system. I thought if it existed to the point that there was "buzz" about it, I should have hundreds of copies. But I didn't. I had three. Kinda.

Here's what the emails actually looked like.

I'll tell you what it does in just a minute.

By the way, if you find phishing sites and aren't sure what to do with them, we LOVE collecting phish! Use Malcovery's PhishIQ Report Phish page to send us any links!

Target Gift Card Spam

When I ran my search, I found all of the "normal" Target spam. People love to use Target to convince people to give up their personal contact information through the "Impossible to get Gift Card" scam.

We've blogged about Gift Card spam and related malware on several occasions including:

  • Cyber Monday 2010 - when we warned about scams using Victoria Secrets and Oliver Garden gift cards. In that scam you have to complete a series of "tasks" in order to earn your gift card, after going through several steps where you think you have "won" something. The final tasks back then were things like "Stay three nights in a Red Horse Inn hotel's luxury suite" or "buy a new car from General Motors!" but LONG before you found out about those tasks, the criminals already had your email, home address, cell phone number, and your agreement to let them share that data with other marketing firms.

  • A Day in the Life of Spam (2009) - in that blog I tried to fully categorize 10,583 spam messages received on October 4, 2009. 28 of the emails were "Giveaway gotchas" -- gift cards, plane tickets, cell phones, laptops that you had "won" if you would just perform some tasks.

  • We also told you about the Member Source Media LLC case where the FTC fined Chris Sommer $200,000 for running his spam scam where he sent email for "Free Products that Weren't Free".

So, today, I wasn't surprised to see spam with subjects and senders like these:

Share Your Opinion. Do you Love TargetShopping OpinionShoppingOpinion@ramblerose.info
Share Your Opinion. Do you Love TargetTarget Shopping SurveyTargetShoppingSurvey@ramblerose.info
Shopped Target LatelyShoppingOpinionShoppingOpinion@ramblerose.info
Special: Snag a $100 Target Gift Card!SavingCenterUSASours@frigidfiz.com
Complete the Target Shopping SurveyShoppingOpinionShoppingOpinion@ramblerose.info
Chance to Get a $100 Target Reward! Complete Sponsor OffersSavingCenterUSABakewell@frigidfiz.com
Back to School Savings - get a $100 Target Gift CardSavingsCenterUSAKeels@coldfiz.com

Here's what these usually look like (or at least the more high end ones):

Target Phish? Not really ...!

All of those are normal, everyday occurrences. But these caught my eye!

Alert to Target Shoppers - your identity is at risk.Local Alerttps0128@yahoo.com

So what happens if you click on the links in the email? Let's find out!

Here's the Fiddler capture of the redirect stream: So, clicking on the link where it says "Has your identity been stolen - CLICK HERE to check the database" or where it says "CHECK TO SEE IF YOUR IDENTITY HAS BEEN STOLEN - CLICK HERE NOW!" takes you through a chain of "automatically redirected" websites:

  • www.mb01.com
  • www.maxbounty.com
  • khvx.secoptim.com
  • rewardzone.surveyblogonlne.com

All of those numbers out next to the URLs? Those are the Affiliate Codes and Redirect Codes, so the scammers can make sure to direct you to the correct scam and to make sure the right spammer gets credit for his hard work stealing your time, money, and possibly identity.

and then your "Political Opinion Survey" starts up . . .

The Fine Print

Before we go win our $1000 Shopping Voucher, make sure to read the fine print on that one . . .

rewardzone.surveyblogonlne.com is not sponsored by or affiliated with This Website. This Website has not authored, participated in, or in any way reviewed this advertisement or authorized it. The trial products offered on the last page pay this website for leads generated. *Free trial offers may require shipping and handling. See manufacturer's site for details as terms vary with offers.

You'll also want to pay special attention to

How Do We Use The Personal Information?

How Do We Use The Personal Information?

We may use the Personal Information for any legally permissible purpose in our sole discretion Ad Serving Companies

We may use third party ad networks or ad serving companies to serve advertisements on our websites. We may pass the Personal Information about you to these companies so that they can deliver targeted advertisements that they believe will be of interest to you. The information passed to these companies may include, but is not limited to, your IP address, e-mail address, name, mailing address, telephone number, date of birth, gender, and any other information you provide to us. Web pages that are served by these companies will be subject to their own applicable privacy policies, if any.

Marketing Partners

We may share, license or sell your Personal Information to third parties for various marketing purposes, including their online (e.g., e-mail marketing) and offline (e.g., telemarketing, cell phone text messaging, skip tracing, and direct mail) marketing programs.

That's just part of it, there are many additional things they can do with your data!

Back to the Survey

There was a third question, but you get the idea. I finish question 3, it congratulates me and then sends me to get my reward! Wait? Where is the Target Gift Card? Well, I guess $1,000 shopping voucher at Sears/JCPenney/Kohl's/Macy's will have to do for now. Oh! And there is only ONE remaining! I better snag that!

By our Fiddler trace, you can see that we've just been handed off from one Affiliate marketing program to another. We are leaving the "rewardzone" system, and headed to the "shopping-sweepstakes.com" system, with "t.afftrackr.com" making sure that everyone is going to get paid for their participation in scamming us.

So, here we go ... we said we wanted the $1,000 Sears/Macy's/Kohl's/JCPenney card, so we choose one and start our NEXT survey

After it "calculated my eligibility" it asked me for my email address. I accidentally hit "Back" then and now it is begging me not to go!

Oh goodie! More prizes! Hey? Wasn't I supposed to be getting $1,000 from JCPenney? I just got a big pay cut for all my hard work here. But that's cool, I shop at WalMart too. I'll take $150 Walmart card, I guess . . . Oh. Actually, our Fiddler tells us that we've swapped systems again...We're now on at www.marktflow.com.

But wait! We ALWAYS read the fine print!

Got that? You must complete 2 silver, 2 gold, and 8 platinum offers ... WITHIN ONE CALENDAR DAY! So, it's 6:00 PM for me now, so I have 6 hours to do all the offers, or I get NOTHING.

In case the website goes down later, here's a local copy of some of the "example offers" that you have to finish TODAY!

OK? Let the Privacy Rape Begin!

Here comes the personal information extract . . . first, we're going to need a PHONE NUMBER, EMAIL, BIRTHDATE, and GENDER. Why? Because $150 Walmart Gift Card, that's why!

OK, you get the point. . . I have 13 more questions to go . . . see the Progress Bar? We are SO CLOSE to getting our gift card! Let's skip through the rest of the questions for now, but ask yourself, "what is likely to happen now that I've told these people that I have a house, a car, I'm planning to move, I like to go on vacation, I have a pet, an active checking account, and at least $15,000 in debt, as well as the next 13 questions . . .

  • Are you currently employed full time?
  • Are you interested in continuing your education?
  • Do you have health insurance?
  • Do you ever pay out of pocket for prescription drugs?
  • Do you smoke?
  • Does anyone at your home suffer from Asthma?
  • Back Pain?
  • Diabetes?
  • Joint Pain?
  • Sleep Apnea?
  • Anxiety or Depression?
  • Have you had a colonoscopy?
Remember. This guy has your email address and your telephone number. Whew! At least our 20 questions are done, right?

And then we start getting all the pop-up offers!

Wait! My home address? My birthday? Oh yeah, I forgot...they have to ship me my Gift Card, so of COURSE they need my home address! Duh!

Just in case though, it might be worth noting in Fiddler that we are no longer talking to MarktFlow. Through T.AffTrackr.com (passing along the credit so the right scammers keep getting paid) we are now seeing offers from "www.offersfromqh.com" associated with "www.qualityhealth.com".

FINALLY! All I have to do is confirm my Email Address (I gave them a valid email: privacyrape@gmail.com wonder if it will start getting spam?) and now I will have my card! It says right there this is the Last Step, right?

Not quite. "YOU MUST INSTALL TO CONTINUE?" What am I installing?

My favorite part there, see the part where it says "I want to earn points for searching the web?" Make ShopAtHome.com my Default Search Provider. Make ShopAtHome.com my Default New Tab. (So, every time your browser opens a new tab, you reload the SearchAtHome.com website. How convenient!)

NOW, All I have to do it complete those 2 Silver, 2 Gold and 8 Platinum offers!

So, I have to EITHER buy a set of Santoku Cooking Knives, (which I can return and keep one $100 knife for FREE!) or sign up for CreditReport.com. I already have a Credit Report service, so I guess I'll buy the knives. That's one down!

Now I can either get Vitamins (don't believe in them), Dr. Seuss Book Club (don't have kids at home), Amora Coffee (I drink Starbucks and already have a local roaster's coffee delivered to the house), a Hunting Knife (I don't hunt), Disney Movie Club (no kids at home), or M-Go Movie Rentals (I already have NetFlix AND Hulu). Hmmm. $150 Walmart Gift Card though ... Shoot. I guess I'll buy some Dr. Seuss books for my nieces.

Wait ... The Gold Offers are mostly the Silver offers I didn't want! And I have to buy TWO of them! I can choose from M-Go movie rentals, a Non-stick ceramic skillet (only $79.95), Dr. Seuss book club sign-up, Disney Movie Club sign up, Sedona Beauty products sign up, or Amora Coffee sign up. Well, I don't have kids at home, and already have NetFlix, I'm already beautiful, and I already have coffee delivered to the house, so I guess I go for the Ceramic Skillet. Cool! It comes with free scissors! ($79.95 plus shipping) and . . . shoot I guess you can never have too much coffee!

Wait. I have to do EIGHT Platinum Offers?? Hmmm... I already bought the knives as my Silver, so I guess I buy the MuscleXLerator, because $150 Walmart Gift Card, and . . .

Oh heck. I'll take the Free Hunting Knife, Sign up from Freester.com, Get ProtectMyID by Experian (don't you wonder if these companies know so many of their referrals are from criminals? I wonder if they care?) Pimsleur Language Learning, because my Rosetta Stone has been on my shelf for two full years and I still can't speak Mandarin, (speaking of heavily spam-advertised products! Pimsleur! Shame on you!) How many is that . . . Shoot. I still need three more.

Well? I guess I'll get ActionProWhite teeth Whitener so I can have that inhuman glow in the dark smile, Join the Disney Movie Club (I can cancel at any time) and well, I do have a lot of wrinkles around my eyes, but that's because I smile so much. Come on Sedona Beauty Secrets!

NOW THAT, Ladies and Gentlemen, is How you get a Free $1000 Target Gift Card, except they actually plan to give me a $150 WalMart gift card instead . . . *IF* I complete 2 Silver, 2 Gold, and 8 Platinum tasks.

$1000 Target Gift Card? Tell the Spammers No Thank You!