Scam, Virus, Phishing alert!
Looks like there is a variant of the Better Business Bureau scam is circulating now but seemingly from the Internal Revenue Service, and I was a recipient of one of the emails. It came in with a title of: “Complaint Case Number ###### against User Name” from, supposedly “fraud.dep@irs.gov”. The body itself looked somewhat legit and there was a Rich Text Format (RTF) document attached called “COMPLAINT.rft”.
Update: 05.30.07@6:03pm PST: Security sites are finally picking this up.
It’s my job to be paranoid so I saved the file and ran a virus scan against it. Surprisingly it came up clean (from a Norton Anti-Virus scan). I didn’t believe that so I decided to do a Google search for “complaint.rtf irs” and it produced no results (which means that nobody has posted or I didn’t have enough terms to search). So I took a different approach and searched for “You have received a complaint in regards to your business services .The complaint was filled” which was the first line in the email. That produced a lot of results. After reading the first result, I knew that I was on to a variant. One clue that I had was the formatting of the date: mm/dd/yyyy/ (note the trailing slash). Why is it that these phishers and scammers always do something that is “not quite correct?” Is it a consciously made decision to drop a hint? Also, from reading the linked article above, the attachment contains a trojan downloader that will install a keylogger which supposedly posts back to an IP. Anyway…
So, for everyone’s benefit, I have posted what I received in hopes that people will spread this warning and the other Security sites will pick this up. DIGG this post to be sure to spread the word!
See text below as well as the screen shot I took; note that I replaced my name and company with generic terms but left everything else as I received it: [click to continue…]
{ 13 comments }














