Wednesday, April 21, 2021

US DMV Information Comes From China

Fake DMV Links to Chinese Phishing Company

By Dominic Alvieri
April 21, 2021

DMV Scams

GEICO has just reported a data breach. Customer drivers license numbers stolen from a bug for unemployment and other nefarious end goals according to Zack Whittaker. A similar DL breach was reported last month. 

This is data theft 101. Every state has victims of identity theft.


It doesn't matter where you live your data is available online. The simple annoying scam of it all.

The stolen data often gets resold after original criminals get what they can from them.


DMV Scams from China


The stolen lists often trickle down to these types of cyber criminals.

Drivers from California to New York are dealing with a variety of DMV spoofs. The Division of Motor Vehicles doesn't send out refunds or rebates.

That would be nice.


DMV refunds?


If it sounds to good to be true...



New domain info.


...it usually is.




China based scam group.


The same scam group runs a myriad of Amazon, Apple, Netflix and others phishing scams run on a daily basis.

The problem is that all of these scams are coming from the same malicious group in China. Scam after scam all coming from the same building location. A phishing company. The 21st century fishermen.


Amazon fake delivery notices.



Same DMV IP address


Same DMV IP address.

IP Geolocation


Malicious IP geolocation


Avoiding the plebian effort goes without saying but in this case the cybersecurity ears go up.

Direct spoofs are always annoying coming from a stolen data list and resold countless times over to different scammers on the DarkWeb. 

I can pinpoint the physical address and even pick it up on satellite. Official agencies have to follow up and apprehend the guilty party. This isn't as advanced as the GEICO bug breach but those lists wind up in these spoofing hands.




The Cyber Show on Google Blogger
by Dominic Alvieri




Thursday, April 8, 2021

The Masters of Spoof

 Can anyone compete with Chinese spoofs?




The Cyber Show on Blogger

What makes a good spoof?


The Cyber Show on Blogger


Chinese imported counterfeit goods have been around as long as time itself. Reproducing an item as close to the original as possible. Logo color and style. 

For the cyber criminal the goal is the same, just replicate and add urgency.


Amazon spoofs



Amazon is a global target.
The links are difficult to replicate but they they try.



The Chinese gangs use the same MO: NameCheap registers, Alibaba hosts and anything that can be will be spoofed. Amazon, Apple, Hulu, Netflix, USPS. The online version of the knock off brand.

NameCheap often surfaces with these new short link scam domains. The Chinese aren't the only ones playing this game but with years of experience they are ahead of the pack.

Often targeting the largest companies Amazon, Apple and Netflix to name a few.


Often rerunning the same campaigns with great success.


The Netflix scam
2020 Netflix scam resurfaces again.

The devil is in the details. Examine all links with great care. Or you can just not answer any email, text or call. Warranty anyone? 

Some are easier to spot. Best Buy and spot gold.






You can always go back to a landline, otherwise examine all links and go directly to the company.
The above spoofs are all pedestrian, at best. The better spoofs have been withheld to avoid duplication.

The email spoof is still the number one entry for a cyber criminal to gain access to your system.
Stay safe online and off.



The Cyber Show
by Dominic Alvieri
Twitter, @AlvieriD



Tuesday, March 16, 2021

What the Spoof

All Spoofs All the Time. 

By Dominic Alvieri, @AlvieriD
March 10th 2021



The Cyber Show by Dominic Alvieri



Everyone wants something for free.



Free Netflix and Hulu for a year?


Free Netflix and Hulu for a year to help us stay home? 

Forget about that the BMW lottery came in, and some alert in France? 







All of the following offers are coming from China. 



Spoofed SMS texts


Fake USPS delivery notices continue.




Fake USPS delivery notice.

Fake USPS SMS spoofs coming from China.


------.py


Free Netflix for a year to help you stay home.



This is a Netflix spoof.


Free Hulu for a year to help you stay home?

Is it Netflix or Hulu?





The new short domain attack continues.



                                  DO NOT

                               [click here] 









Spoofed emails have been around since the beginning of the internet. Spoofed SMS texts have been proliferating in the past few years. Knowing the domain endings is critical. Newly created short domains have been popping up with the same group. 

Technological reverse psychology if you will by tracking the bad guys back. The building below is from a Google Earth trace address of the malicious links geolocation. 



Geolocation of malicious SMS texts.
Geolocation of malicious SMS text links.


Time to harden your network security. Use VPNs and encrypted communication like Signal to minimize your surface. Use MFA and tokenized apps like Google or Microsoft Authenticator over SMS. Incognito mode is not optimal security for your browser. Tor is acceptable but slow. Nothing is full proof. Check your home network and make sure to disable port forwarding and also disable the plug n play otherwise you are leaving a back door open.

IoT devices should be secured. Check for open standards, basic passwords and check for any and all updates and patches. Patch often and early. Do not hesitate. Within 12 hours of the server exchange hack Russian bad actors were scanning for the vulnerability according to Bad Packets, a malicious scanning alert firm. 

Security minimums are no longer effective. Update to longer more difficult passwords and do not click on any suspicious link. Or avoid all links. Not realistic but you get the point. 

This IP with "no site" is the USPS spoofed SMS malicious text link above in this report.



IP address of SMS text malicious links.
Courtesy of DomainTools.



The enemies are at the gates, computers, networks, phones...








The Cyber Show on Google Blogger
by Dominic Alvieri


Twitter @AlvieriD

Friday, February 12, 2021

New edX Course Links to the Chinese Chief Information Office

 Redirected Link is Now Direct Link

 By Dominic Alvieri

Twitter @AlvieriD


January 23rd, 2021


Redirected link on edX is now a direct link.
Redirected link on edX.

The second largest online educational platform edX created by Harvard and MIT has been breached. Or has it?

A new Rochester Institute of Technology online advanced cybersecurity course on edX was redirected last week to the Chinese Government Chief Information Office in Wanchai, Hong Kong China.

Now the US InfoSec portion links directly to InfoSec China


Redirected edX link to China.
Redirected link last week.

The link above leads to the Chinese Government Chief Information Office in Wanchai, Hong Kong.


Link leads to Chinese Government Information Office.
Link leads to Chinese Government Chief Information Office.


Well how did that get there?

Rochester Institute of Technology and the Chinese professor were unavailable for comment. The redirected link in week one now have direct links to the Chinese government Chief Information Office.

The US InfoSec link now leads directly to the Chinese Chief Information Officer. That is not a typo.

It is still unclear if that is the destined source for the course information. After weeks of question still no answers to why they are still there.


US InfoSec page leads to InfoSec China


Unknown joint educational operation?



Redirected page is now direct.
Redirected page is now directly linked.


US Institutions of higher learning have been probed during the pandemic and warned by the FBI for collaborating with communist groups. The persistent picture painting and data collection by the communist government is under investigation and will update the information is confirmed.

I highly doubt this is the intended educational path for US Cybersecurity masters students but things may have changed in a year, besides the Presidency. 

Update pending with comments due some time in February, 2021.



The Cyber Show


Dominic Alvieri
Twitter @AlvieriD
The Cyber Show
The CyberSecurity Show on
Google Blogger and Medium.

Thursday, January 14, 2021

Caught in The Capitol Building

 

CNN Live Stream and Posted Video Allows 

Researcher to Find Man Carrying Fire 

Extinguisher in The US Capitol


This is a Person of Interest



By Dominic Alvieri, Twitter @AlvieriD

Reporter for The Cyber Show

January 14th, 2021




Caught in The Capitol. Breaking Exclusive.



The two men pictured below are part of an extreme group that came to cause havoc. The man with the stars and stripes bandana around his neck has hidden items under his jacket. Both are wearing bullet proof vests and appear to have weapons.


Capitol riot video exclusive.
This man is caught with a fire extinguisher in the Capitol.

US Capitol Police Officer Sicknick was struck in the head and killed with a fire extinguisher 


New video research from the CNN live stream of the deadly riots at the US Capitol is being released today seeking public assistance to identify the individuals responsible for the deadly attack.

Police officer Brian D. Sicknick was killed last week after being struck in the head with a fire extinguisher according to witnesses. After hearing this I remembered the event that unfolded live before I was able to record some of the events. This rioter with a fire extinguisher at the Capitol. 

Once CNN posted the video the rest was easy to tie together with other footage and angles. Now we have to identify this person of interest. 

Caught with a Fire Extinguisher



Do you know this person?
Do you know this person?


This man quickly places down the fire extinguisher once he 

notices there might be a camera recording. 


Man placing fire extinguisher down in Capitol during riot.


Snapshot of man placing down fire extinguisher in the Capitol Building.

What was this going to be used for?


The following snapshots were taken from the live video that was steamed by CNN on January 6th at the US Capitol. During the live steam I noticed several events before I was able to record. The sound that was made by the person who kicked the fire extinguisher after it was placed on the Capitol floor was unmistakable.  

 Luckily CNN made the video available for research and I found it.

Vests, tactical gear and weapons are not required for a peaceful demonstration.



Caught with a fire extinguisher


This person came with a plan


Contact the FBI if you have any information regarding the identity of this person.
The person circled meets up with friends.

The video actually shows several other people of interest. One man is seen wearing tan pants and a cheap black leather jacket scurrying past others. He was carrying a small black messenger bag briskly bypassing others around the roped pathway to enter deeper restricted areas.  

No phone recording, no selfie for this person. He looked and acted like a spy rushing to get in.

Both suspects appear to be wearing bullet proof vests.



People of interest in the Capitol Riots


This exclusive video research is from CNN live footage of the Capitol riots on January 6th, 2021.

I saw it as it happened and thought he either used it on a door, window or person. The Federal Bureau of Investigation has been forwarded the information.

Once again, please help law enforcement with the rioters who entered our Capitol. That was not a peaceful protest and many still have a price to pay for their actions on that fateful, hateful day incited by the President of the United States of America. 





The Cyber Show by @AlvieriD

Dominic Alvieri, Twitter @AlvieriD
Analyst, Independent Researcher, Tracker, Hacker, American. Reporter for The Cyber Show and
The CyberSecurity Show 


The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...