Wednesday, October 12, 2011

Inbox - SCAM ALERT "ACH Payment 5230656 Canceled" using a Yahoo account!


if you live in Britain you are request to send your copy of this scam email to the NFA

National Fraud Authority | Home Office

www.homeoffice.gov.uk/agencies-public.../nfa/
2 days ago – The National Fraud Authority (NFA) works with the counter-fraud community to make fraud more difficult to commit in and against the UK.
.
-----Mensaje original-----
De: ach sdfdsf [mailto:ach.sdfdsf@yahoo.com]
Enviado el: Wednesday, August 03, 2011 7:26 AM
Para: webmaster@itccommunications.net
Asunto: ACH Payment 5230656 Canceled


Payment Notification #67856549

The ACH transaction (ID:67856549 ), recently initiated from your checking account (by you or any other person), was canceled by the other financial institution.
Rejected transaction
Transaction ID: 67856549 

Do not click link (see article below)
Reason for rejection: See details
http://nacha.org/report/67856549/detailis.php?n=3676  


There are a lot of things you can do with Project Gutenbergtm electronic works if you follow the terms of this agreement and help preserve free future access to Project Gutenbergtm electronic works.Where are the ethos of humanism now, you were very fond of them when we were in the University!If any disclaimer or limitation set forth in this agreement violates the law of the state applicable to this agreement, the agreement shall be interpreted to make the maximum disclaimer or limitation permitted by the applicable state law.Spring the trap to see if it _was_ a trap.All of his muscles were hard with the restrained energy of an animal crouching to leap.It exists because of the efforts of hundreds of volunteers and donations from people in all walks of life.WILLIAM REEVES 83 CHARING CROSS ROAD, BOOKSELLER LIMITED.If it is accurately done, application of the kfactor equations is almost mechanical.
________________________________

7074 Sunrise Valley Drive, Suite 100 Herndon, VA 20171 (703)561-1100 2011 NACHA - The Electronic Payment Association

Warning
A new wave of spam emails are targeting business users and attempt to infect them with a variant of the ZeuS banking trojan by posing as ACH transfer failure notifications.

According to researchers from antivirus vendor Trend Micro who analyzed the campaign, the emails purport to come from NACHA – The Electronic Payments Association, the regulatory agency for the Automated Clearing House (ACH) network.

The ACH network is commonly used by companies to process large volumes of credit and debit transactions, such as payroll or vendor payments, in batches.

According to Gary Warner, director of research in Computer Forensics at the University of Alabama at Birmingham (UAB), the emails have subjects like "ACH transaction cancelled", "ACH Transfer rejected", "Your ACH transaction" and other such variations.

The body message is always the same and reads: "The ACH transaction , recently initiated from your bank account (by you or any other person), was rejected by the Electronic Payments Association. Please click here to view details."

The link takes recipients to a website pushing a fake Java update that is actually a variant of the infamous ZeuS (Zbot) information stealing trojan.

One of the more interesting aspects of this attack is the large number of domains with ACH in their name registered particularly for this spam run.

At the moment, malware distributors prefer using compromised legit websites because they are cheeper and easier to replace when they lose control over them.

Registering so many domains for a single campaign is somewhat of an excess and suggests the people behind this attack don't lack financial resources and the return on investment they expect justifies the costs.

Another trick used by these spammers is the forging of headers to appears as if the emails originate from thousands IP addresses, when in fact they come from just a few. Also, there are clear indications they are being sent from compromised Gmail accounts.

No comments: