This scam is orchestrated a bit differently than what we've seen before

Oct 10, 2011 08:45 GMT  ·  By

A new attempt of spreading malware has been seen in an old Xbox Code Generator scam that tries to dupe unsuspecting users by making it look as real as possible.

Sunbeltblog discovered an add on various video sharing websites which promises internauts an app that will generate a functional cypher.

Unlike other such scams, it doesn't directly spread malware and it doesn't ask for information, instead, this one first redirects the victim to a number of websites which all advertise the download of a piece of software.

Once the alleged code supplier is downloaded and executed, it opens what seems to be a genuine code generator which gives a series of invalid codes. To make everything look more real, at the bottom of the window a message is posted.

It reads "This version uses an outdated formula. The keys generated may not produce correct codes. Upgrade to 1.17"

If the update button is hit, you are taken to a .tk location that now seems to be legit. According to the source, the mastermind behind the operation might have changed the malicious page with a sports-related page in order to prevent the domain from being shut down, but it was too late.

Even though most of the sites related to the malicious operation were shut down, it's always good to know about these things as you never know when they might reappear under a slightly different form.

Remember the basic rules when it comes to downloading or accessing suspicious content:

– always install an up-to-date anti-virus; – never give out sensitive information or account credentials; – make sure to download software only from trusted or verified locations; – watch out for suspicious multiple redirects, especially to .tk locations or to addresses that have nothing to do with what you're trying to find.