D-Mart Voucher Scam !
An
Advt talking about free vouchers worth Rs 2500 from D-Mart is going viral.
How
many of you have come across this?
PLEASE
DO NOT fall a victim to this scam and absolutely do not fill in your details.
Here
is the truth…
This
is a new phishing scam, which has zeroed in on its origins. Created by the
Homoglyph Attack Generator (out of Character), the link of the scam Advt is
very smartly created to cheat the domain.
Scam site :
http://www.dmartındia.com/
original Site:
http://www.dmartindia.com
Can you spot the difference , yes it is "i" in india.
Scam site :
http://www.dmartındia.com/
original Site:
http://www.dmartindia.com
Can you spot the difference , yes it is "i" in india.
Homoglyph Attack:
A
homograph attack is a method of deception wherein a threat actor leverages on
the similarities of character scripts to create and register phony domains of
existing ones to fool users and lure them into visiting. This attack has some
known aliases: homoglyph attack, script spoofing, and homograph domain name
spoofing. Characters—i.e., letters and numbers—that look alike are called
homoglyphs or homographs, thus the name of the attack. Examples of such are the
Latin small letter O (U+006F) and the Digit zero (U+0030). Hypothetically, one
might register bl00mberg.com or g00gle.com and get away with it. Nevertheless,
in this day and age, such simple character swaps could be easily detected.
In
an internationalized domain name (IDN) homograph attack, a threat actor creates
and registers one or several fake domains using at least one look-alike
character from a different language. Again, hypothetically, one might register
gοοgle.com, but not before swapping the Latin small letter O (U+006F) with the
Greek small letter Omicron (U+03BF).
Table 1: We used Segoe UI, Microsoft’s system-wide typeface, here.
To
the human eye, these Cyrillic glyphs can easily be confused with their Latin
counterparts. Computers, however, read these confusables differently, as we can
see from the different hex codes assigned to them.
Table 2: We used San Francisco, Apple’s system-wide typeface, here. It’s worth
noting that OSX distinguishes the Cyrillic small letter Palochka from the Latin
small letter L; however, it cannot show the difference between the Latin small
letter L with the Latin capital letter I, as per the text “Cyrillic small
letter Ie”.
According
to this bug report, it seems that even the system-wide font for Linux doesn’t
distinguish confusable characters either.
The
use of all-Cyrillic glyphs—or any other non-Latin characters for this
matter—for domain names isn’t the problem. IDN has made it possible for
internet users around the globe to create and access domains using their native
language scripts. The problem is when these glyphs are misused to deceive
internet users.
Is this a new form
of online threat?
Homograph attacks have been around for years.
Below are other examples of homographed domains and
how they were used:
·
To raise awareness, a security consultant
highlighted the common misconception that sometimes a Latin capital letter I
(U+0049) looks similar to a Latin small letter L (U+006C) by registering a fake
Lloyds Bank website and adding an SSL certificate to it to make it look as
legitimate as the real one.
·
A security researcher from NTT Security shared his
experience about a friend of his who received several Google Analytics spam
containing the domain, secret[DOT]É¢oogle[DOT]com.
The “É¢”
there wasn’t the Latin capital letter G (U+0047) but a Latin letter small
capital G (U+0262).
·
A security researcher from NewSky Security found an
impersonated Adobe website serving the Betabot malware, pretending to be an
Adobe Flash Player installer file. The threat actor used the Latin small letter
B with Dot below (U+1E05) to replace the Latin small letter B (U+0062) in
“adobe.com”.
Are all homograph
attacks just phishing attacks?
Not necessarily. Although homograph attacks usually
involve phishing, threat actors could create fake yet believable websites for
other fraudulent purposes or to introduce malware onto user systems, as is the
case of the bogus Adobe website we mentioned earlier.
In this in-depth report about IDN homograph attacks, our friends at
Symantec have noted that several homographed domains they found were either
part of a malvertising network, hosting exploit kits and malicious mobile apps,
or generated by botnets.
If
you have already opened such URL, then it would be better to change your
passwords.

Comments
Post a Comment