January 13, 2008 12:36 PM PST

Scamming non-profit organizations leads to Google gripe

Warning of a new scam targeting non-profits comes from Alex Eckelberry of Sunbelt Software, the company behind the anti-Spyware program CounterSpy.

The scam starts out with an email message that seems to be from Barbara Moratek Vice President, Director of Grant Programs at Ivete Foundation. The come-on in the body of the message is:

"Would you have additional information for prospective donors or volunteers other than what is on your website? Thank you in advance."

I've said before, you can never trust the FROM address of an email message. According to the email header from one of the messages, it originated in Brazil, in the city of Curitiba from a computer with a name of virtua-cwbas189-4-7-26ctb.virtua.com.br.

But, there is a new twist to this scam, the bad guys have set up traps for someone doing a Google search for "Barbara Moratek". Alex provides a screen shot of this Google search from Thursday January 10th showing "... a bunch of links pushing fake codec Trojans and other junk sites (many on Blogger)." So, the process of checking whether the email is legitimate can result in your computer getting infested with malicious software. Fortunately this scam has gotten enough attention that the top links on Google are now warnings about Barbara Moratek.

Yet another wrinkle to this scam is that the malicious web pages Google offered up were from sites that are not obviously suspicious. For example, Digg and Lycos both served up phony Barbara Moratek web pages as did Blogspot and Celebrity-pictures-gossip.com. User contributed content has to always be consumed with a grain of salt.

One thing strikes me as inexcusable. The alert about this first went up on January 10th, Brian Krebs picked up on it and wrote about it at WashingtonPost.com on the 11th. Both the Sunbelt blog and Brian's Security Fix column are well known and popular, which begs the question:

Why are there still malicious Barbara Moratek web pages showing up in Google?

As I write this on January 13th, three of the scam Barbara Moratek pages still show up on the first page of search results at Google. Is anyone minding the store? Yahoo's search is clean, the first two pages of results of a search for "Barbara Moratek" turn up nothing but warnings about the scam. No actual malicious pages are shown. Google should do better, it can't be a big deal for them to remove known malicious web pages from their database.

For more on deciding whether an email message is on the level see a couple earlier postings of mine:

-- Defending against a phishing email message October 27, 2007

-- Is that e-mail message legit? How a computer nerd analyzes it November 11, 2007

Always be skeptical on the Internet.


Update: You can report a web site that you suspect contains malicious software to Google at google.com/safebrowsing/report_badware/. The trailing slash is required. January 14, 2008.

See a summary of all my Defensive Computing postings.

Recent posts from Defensive Computing
The main problem with Windows Vista
Foxit PDF reader v2.3 updated with bug fixes
Cringely's iPhone Gripes
A warning about IE8 and Windows XP SP3
Be safer than NASA: Disable autorun
Add a Comment (Log in or register) 1 comment
by RicABlair January 13, 2008 10:46 PM PST
Just as in terrorist attacks where the aid (eg ambulances) can be secondary booby traps, the seemingly safe pages warning of the scam can themselves be malware infested too (and created by the original scammer).
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

About Defensive Computing

Michael Horowitz is an independent computer consultant and the author of several classes on Defensive Computing. He views Defensive Computing as taking steps, when things are running well, to avoid or minimize the inevitable problems down the road. It's about educating yourself to the level where you can make your own intelligent decisions about keeping your computers and data happy and healthy. If you depend on computers, yet are on your own, without an IT department or nearby nerd, this blog's for you. His personal web site is michaelhorowitz.com.

He is a member of the CNET Blog Network and is not an employee of CNET.

Disclosure.

Add this feed to your online news reader

Defensive Computing topics

Featured blogs

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Creating a 'Facebook for spies'

    The CIA, FBI, and National Security Agency are reportedly testing a social-networking site designed for use by analysts within the 16 U.S. intelligence agencies.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.