BitTorrent users beware: malware tries (and succeeds!) to extort money

The malware installs itself in the usual manner -- an email attachment, an unpatched web browser -- and then pops up a 'Copyright violation alert' (see above). It seems to scan your hard drive for traces of illegal software -- .torrent files, seemingly -- so as to add some credibility to the claim that you've broken the law.
But that's not all! This is the best bit: you are then asked if you want to go to trial to defend your illegal act... or opt for the $400 pre-trial settlement (screenshot after the break):

Frickin' genius!
Suffice it to say, the 'company' behind the malware scam, 'ICCP online' is nothing but a sham! Take a look at their sitethough, and take a closer look at the screenshot at the top of this post -- it really is quite a good scam!
Suffice it to say, the 'company' behind the malware scam, 'ICCP online' is nothing but a sham! Take a look at their sitethough, and take a closer look at the screenshot at the top of this post -- it really is quite a good scam!













Comments
13
Subscribe to comments216Apr 12th 2010 2:53PM
Scammers are getting damn smart these days.
JoshApr 12th 2010 3:14PM
This is quite ingenious. As horrible as scammers are, you do have to give them props for thinking outside the box on how to accomplish their goals.
der_tuxmanApr 12th 2010 3:17PM
There are still BT users?
Sebastian AnthonyApr 12th 2010 7:17PM
*yawn*
der_tuxmanApr 13th 2010 5:47AM
Is that a No?
HelApr 12th 2010 3:22PM
Is this redirecting to localhost for anyone else? How screwed is my company's DNS setup right now?
Drew GreenApr 12th 2010 4:19PM
localhost for me as well
Sebastian AnthonyApr 12th 2010 7:16PM
Sounds like some DNSes have already flagged it as a bad site, or something :) I can still see the site though... and I'm using Google's DNS servers I think...
Alex MApr 12th 2010 4:25PM
icpp-online.com gives me a giant IIS7 splash screen :)
darwinsurvivorApr 12th 2010 6:58PM
Getting 127.0.0.1 from a college DNS and my home (freshly installed linux machine yesterday). A whois lookup shows the account was suspended, so I'm guessing their registrar set their ip to 127.0.0.1 :P
Check out the "Related Websites" at the bottom of http://www.aboutus.org/Icpp-OnLine.com for a good laugh.
RhineTechApr 12th 2010 11:28PM
Thanks for the heads up, good to know if any of my clients call in about it.
trk75520007Apr 12th 2010 8:49PM
i havent had any problems with scammers when i am useing torrents use avast and it will get everything
kevjohnApr 13th 2010 11:11AM
I don't blame scammers/spammers anymore. A snake's going to be a snake, after all. I blame the morons who fall for their crap! $400?!? WHO falls for this?!? I mean seriously, you would think BitTorrent folks would be at least a tiny step above the average computer user in terms of knowledge and "online wisdom", with the average computer user being... grandmothers whose sole purpose is to send mass email FWDs to everyone they know, Dilbert's Pointy-Haired Boss types who spray Windex on their screens to clean their hard drives, and drunk college kids on Facebook.