Fake FBI Warning Carries Virus
Posted by in Industry News on January 7, 2004 at 10:44 PM

A Windows executable file, attached to an email that purports to come from the FBI, is the latest social engineering trick being used in an attempt to spread malware (programs designed specifically to damage or disrupt a system).

The email has the subject: Your IP was logged

It reads as under:

Ladies and Gentlemen,

Downloading of Movies, MP3s and Software is illegal and punishable by law.

We hereby inform you that your computer was scanned under the IP 172.112.119.57 . The contents of your computer were confiscated as an evidence, and you will be indicated. You get the charge in writing, in the next days. In the Reference code: #39395, are all files, that we found on your computer.

The sender address of this mail was masked, to fend off mail bombs.

You get more detailed information by the Federal Bureau of Investigation
-FBI-
Department for "Illegal Internet Downloads", Room 7350
935 Pennsylvania Avenue
Washington, DC 20535, USA
(202) 324-3000
1. [Application: refcode39395.cmd] (101KB)

Well-known IT security consultant Richard Forno, who received one of these emails, said that while security professionals and most educated persons would recognise this as a scam, the average user was likely to cringe in fear at the mere hint that the FBI had targeted them for a "criminal case."

"Note the .cmd attachment to this email message - a Windows executable file (eg, malware) - cleverly disguised as the "Reference Code" to trick the recipient into opening it," he said.

He also noted that downloading of movies, MP3s, and software was not illegal - downloading unlicensed or pirated copies of such items was against US law.

"It's clear the spammer is exploiting public ignorance of this policy issue, especially in light of the news-making and controversial RIAA lawsuits last year," he said.

Full article at The Age web site

Another Version at The Register.

Printed from http://www.boycott-riaa.com/article/9782