Wednesday, April 15, 2020

Be cautious of Fake “Your Income Tax Reminder”

If you receive an email with the subject line  "Tax Refund available",or "Your Income Tax Reminder" it's fake do not click on it. 

If you have received an email that looks like this, it's fake do not fill it or click on it

You are eligible to receive a refund of 520.00 CAD.

You have tax returns for period ending 15 Apr 2019, due 15 Apr 2020, now available for refund!

Remember: We tried to send it to you automatically but were unable to do so as we don't have your details on file.

Ready to refund it now?

 

  • Have your credit/debit card ready.
     
  • Open the application form below in your browser and login to your myIR account.
     
  • Follow the instructions on your screen.
Remember, If you are not the intended recipient of this email, please reply to inform us that you have received this email in error and then delete it without retaining any copy.

Note: Make sure all your income, benefits and family details are up to date in myIR, this will help make sure you're getting the right entitlements.

If you click on the link it will send you to a landing page that will extract your information and steal your Personal Identifiable Information PII.

Again above is not the real CRA PAGE. 

Friday, September 1, 2017

Fake Phishing CRA Canada revenue agency e-mail

as per last blog this is a yet another fake e-mail looking to take your PII  https://canadacyber.blogspot.ca/2016/08/phishing-spam-e-mail-that-harvests.html this is another fake CRA e-mail.

You receive an e-mail that is a Phishing e-mail claiming to be form CRA Canada. The e-mail looks very real as the attacked had bought a domain name https://cra.arc-cg.com that looks very much like the old domain name that was used by CRA before they moved to the one Canada.ca domain.
See pic below.




When you click on here it send you to a page that looks like a forum submission page that is from CRA. That hacker/attacker was also smart enough to use a CloudFlare to hidethe page by encrypting it using a valid certificate from them so you even get a Green bar.  The average user that was always told to look for the green lock will think this is a real legit site. BUT IT IS NOT.
The page also is asking for PII data that should never be given away.
See image below.






Let’s say you dumb enough to fill in your PII info and click submit then you are redirected to 2nd page that asks for your Credit Card info.  See image below.





At the end when you do submit the page redirects you to the real CRA page. So a normal person think they just did the correct thing. 

Below are screen shoots of other IOC's first is the e-mail path and source servers.




This IOC is of the hosting provider, as you can see the attacker was smart enough to hide his domain name behind private registration to make it harder for take downs.


Saturday, January 21, 2017

DDoS protection and mitigation methods, CanadaCyber approches



CanadaCyber: DDoS protection & mitigation methods.
 
People come to us and are always say we can’t protect against DDoS, we always say to them yes you can with the proper network implementations. 

Let’s say you own www.coolpage.com and that is pointing to server that is located within your DMZ at Ip address 11.22.33.11. 

In your DNS and name server you have listed www.coolpage.com to point to the server @ 11.22.33.11 using A record with a certain time to Live ( TTL ) lets say 1 week.

All a hacker (Attacker) has to do is target that IP or Domain name. 

We have 2 types of attackers that will try to target you, ones that will target the IP 11.22.33.11, knowing that this is your main server. And the less informed hacker that will target your domain name www.coopage.com

This is how CanadaCyber mitigates this threat. First of all you should never use A record pointing to your core server. What you should have is a series of proxies that will balance the traffic.  By doing this you have 2 advantages, first caching your content and 2nd dislocating your core server from your domain name via redirection. 

So the way you achieve this at a very basic level is by buying a numbers of servers that will just redirect your traffic to your Core IP, and then you program these IPs as the A record holder. 

When you do get attacked you can easily change the A record. the other thing is within your a record insure your TTL is setup for a very small number, as this will allow you the ability to move A records allocations on the fly to different IPs, that will then redirect to your main server IP.

Proxy servers are very cheap if setup by educated staff internally, as you can buy an amazon EC2 or Linode server for less than 15$ a month that can do this job. It can be a full fledge proxy or just a basic IPTABLES DNAT table. 

For the Geek at heart, you can also setup your own name server or have access to name servers that you can use for DNS resolution. Adding this with the above information you will have a robust DDoS mitigation plan, which will insure you have continuation of services. So if your IP, Domain name or name servers are attacked you can still deliver services.

Sunday, August 28, 2016

Phishing spam e-mail that harvests Hotmail users e-mail account using Canada Revenue Agency e-mail INTERAC deposit as a lure (Canada Revenue Agency sent you $214.17 (CAD) ). CYBER



CanadaCyber has identified a recent e-mail phishing attacks, targeting Canadian Hotmail users.
The e-mail comes in titled as:

You received INTERAC e-Transfer  Or You received a tax refund
The email looks like this on a phone then a laptop. 





The e-mail is simple you get message that looks like a standard email money transfer via INTERAC something that many Canadians are accustomed to. The amount of $214.17 is also a number that a lot of families in Canada are used to receiving from their federal government from GST to Child money.
When you click on the Deposit your money link it fwds you to a page that is asking you for your password. When you place your password it collects your password then it moves you to the next stage of the attack.
At this stage you think all is good as you see the normal government of Canada web site. You then go on and place more information like your PII Personally identifiable information and banking information. After that you are thanked, at this stage the BAD Guy has all of your info. Then you are redirected to the real government of Canada revenue agency website.   So now they have your passwords and all of your information.

The e-mail it self has a embedded png file ejuiceejuice.com/image/data/etransfer2 the interesting thing is the server used to host this image is diff than the landing page.this could be due to the attacker just linking to the file directly or using different servers for different jobs. this way it would be much harder to talk him down. as you have to contact 3 diff providers.    

the above screen shows the landing page for the first stage it send you http://support.cra.interac.taxid-423.redapp244.com/secure/index.php?em=somename@hotmail.com, we can see this is not hotmail or outlook.com from the URL. if  we do a dns lookup on the URL we do see it from217.160.0.192 belonging to 1& 1 shared hosting account that is hosting almost 1500 websites. this means any of these website could been exploited to do this but it is likley redapp244.com was compromised and the attacker created a subdomain with the name support.cra.interac.taxid-. On a mobile device this would fool most users as it does look like it is CRA.
 


On the 2nd stage we see the attacker is trying to mimic/clone a real  CRA page. they even change the title header to look so. in both 2nd stage and 1 stage the attacker used the landing page server for the links redirection and content.


Now we analyze the e-mail by looking at it source:


We see it came from a shaw.ca cable IP address 24.70.214.97 in Calgary; this could be the attacker or a compromised workstation working on his behalf. We then see it doing to the smtp-out-so.shaw.ca @ 64.59.136.138, also in Calgary. We suspect this server is allowing mail forwarding from trusted IP’s as the source IP is from the SHOW.ca network. 



This is the first mistake SHAW.ca did, it trusted its internal users IP range. Shaw.ca also did not confirm the email sender X-SID-PRA was notif482@grs.trustwave.com this is clearly not a shaw domain name or a show e-mail sub-domain. This is even more dangerous as the average user looking up this www.trustwave.com gets to see a legitimate security business, something that will later on help in convincing the victim to click on the link that will later on harvest his password.

Again this is due to Shaw not confirming the sender e-mail address so the mail severs they use just fwd the e-mail even if the email sender is forged. 

The e-mail is crafted to gain your trust first after it collects the most valuable item your PASSWORD it then moves on as it knows you might even give away more info like your PII, address, name banking info. Anything they need to fully steal your identity.

Canada Cyber had also submitted the url to virus-total and only google safe browsing identified it as bad.  https://www.virustotal.com/en-gb/url/26ae24d8a6e5bdad3cdf9bf8bbf8c78dbe89b4d4df96fb058f526a7bde680be1/analysis/1472437103/


This new attack is similar to this: http://globalnews.ca/news/1900959/canada-revenue-agency-warns-of-recent-scam-involving-money-transfers/


CanadaCyber