Monday, December 31, 2007

Trojan delivers pay-by-phone extortion

After infection by this Trojan, you’re completely locked out of the system.

You get this screen –– it takes over your entire desktop:


Hijack_900_number


Click on “Click to activate new license”, you get this screen:


Hijack_900_number2


Turns out it’s coming from a website, which I’ve posted the same screens, below:


Securitycenter1324812388


Different countries have different numbers. For example, here is the UK:


Securitycenter1324812388ab


And here is France:


Securitycenter1324812388ac


Incidentally, a search on the US 900 number shows the first link as passwordtwoenter com, which shares an IP with a number of other similar sites:


p2e com
chargemybill com
chargemyphonebill com
password2enter com
passwordtoenter com
passwordtwoenter com
phonetoenter com
pin2enter com
pintoenter com
pintwoenter com
ptwoe com


Apparently, this is a payment processor that’s now being used for malware, whether they know it or not.


Alex Eckelberry
(thanks Adam Thomas and Patrick Jordan)

Update: Pay-by-phone processor cancels account. More here.