#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity
|
|
I was dealing with customer escalations the other day and came across this interesting sample. If you believe the filename install_wrar380.exe it would install WinRar on your system, for some reason I didn’t believe it
.
Upon execution, the installer displays a EULA. I have copied and pasted some of the detail below:
“THE COST OF EACH SMS FROM THE USER’S MOBILE PHONE IS TWO POUNDS. UNLESS OTHERWISE SPECIFIED, THE DOWNLOAD COST SHALL BE FOUR SMS.
Please read these USAGE CONDITIONS carefully and, if appropriate, use the download service which shall imply the express and complete acceptance of each and every one of these USAGE CONDITIONS. Otherwise, please close this website.
Netlink Network Corp. offers a PREMIUM high speed download service that is efficient and virus free. In exchange, the user shall first send two SMS under the conditions specified in clause 2.2 that defines the commercial conditions of the service”
These two sections really caught my eye. From what I understood I was going to be charged £8 in the form of 4 SMS text messages so that I can download WinRar. Alarm bells started to ring.
I clicked ‘I agree’ and was prompted for a code. To get this code, I would have to send 2 SMS text messages to 78*** (Number has been blanked out for security reasons) with the text body ‘CD’ and I would be charged £3 for each text message. This was different to what the EULA said, but as it was cheaper I wasn’t going to argue. Also note how the text is almost the same color as the background to make it difficult to see.

As I was interested to find out if it really would install WinRar, I went to my local mobile phone store and bought a mobile phone, put £10 on it and sent a text message to the number. To my surprise, I received a text back saying:
“SMS 1/3. Price per SMS: 3 Pounds. Total cost: 9 Pounds.”
It now cost me £9 instead of £6 to download some free software. This was also more than the £8 the EULA said it would cost me. I received a further 2 text messages and the final one was labelled 2/3 even though it was the 3rd. I guess they don’t have QA. You can see the text messages I received below:
I entered the code and clicked on the ‘Install’ button. The software downloaded WinRar and went on to install it for me.

I found the website which the sample came from and it displayed the following text at the bottom of the page:
“This website does not belong to any member´s program. This program should be used based on rules of intellectual property. You may obtain this program for free from the official homepage. Using or applying cracks, serials or keygens is strictly forbidden. This portal will not be held accountable for inappropriate use of the program. Your query has been sent succesfully. You will receive an answer shortly. Thank you for using our services. Due to technical issues, your query could not be sent. We apologize for the inconvenience”.
So they admit that you can download this software for free from its official homepage. They are clearly trying to trick the unsuspecting user to pay for free software.
I thought perhaps they have done this with other free software, I did some investigating and found several other websites which are registered to the same company and they offer several other pieces of free software for the small price of £6 or £9 as I found out.
I found installers for Messenger Plus! Live, WinZip, WinAce, 7Zip and several others. All of these can be downloaded for free from their official sites.

The websites are aimed at English, French and Spanish users. Luckily for our European friends, they can pay for the free software in Euro’s.
While navigating these sites, two different company names kept popping up. Netlink Network Corp and Soletto Group, S.A., I did some quick searching but couldn’t find any details on these companies.
Some of the domains had been registered as recently as late last month, so I believe we are likely to see more pop up.
I pulled all the executables I could find on the websites and added detection as SMSFraud.
Please be on the lookout for these in the future as you don’t want to pay for something which is already free.
|
|
Tags: freeware, mobile phone, mobiles, scam, sms, SMSFraud, text message
Same happened to me when trying to upgrade Windows Moviemaker !! Thought it was automatically linking to Windows endorsed site so was to be trusted. They texted me the cost that they had just taken from my phone but no unlock code has ever arrived. Have contacted support 4 times now and surprise surprise….no response!
Why can’t people just put their energy into something productive. Mobile users really have to watch it.
It’s a Nokia N83 mobile?
Hehe, you actually bought a mobile phone to test it? That shows dedication ;P
pretty sneaky bastards…
the probably charge you for the bandwidth used… (ah, who am I kidding) =)
I doubt they have license to distribute this software. So in fact it must be officially considered an scam as they claim they would give you a service they know they can’t.
Hi,
I remember this post i made some time ago (in french, sorry) :
http://msmvps.com/blogs/docxp/archive/2008/04/20/1596496.aspx
Submit your own comments / message for this post