Cloudflare's SSL certificate is used for phishing

A free SSL certificate from CDN and DNS provider has been used by cybercriminals in a phishing email to increase the level of trust and trick you into clicking on a link.https Cloudflare

At Clodflare's services as announced, 29 September added support for SSL connections. The feature is available free of charge to all its customers, regardless of whether they have subscribed or are registered to its free service.

With this move, the company doubled the number of websites supported by encrypted links.

Ο Jerome Segura of Malwarebytes recently noticed a new email campaign that started from a website and took advantage of Cloudflare's free SSL certificate to deliver malware. The malicious message claimed to be a from LogMeln's cloud-based (provider of remote login services), regarding an alleged problem in extending its service subscription due to insufficient resources.

Η κακόβουλη σύνδεση HTTPS που περιλαμβανόταν στο e-mail έμοιαζε σαν επισήμανση προς ένα τιμολόγιο που θα έδειχνε τις λεπτομέρειες της συναλλαγής. Δεδομένου ότι το link ήταν μια connection, users were more likely to think that the file download was protected and harmless.

CloudFlare-SSL-Certificate-Used-For-Phishing-Scam-1

Fortunately, Cludflare revoked the certificate for that site and the site has now been flagged as malicious by all major web browsers.

CloudFlare-SSL-Certificate-Used-For-Phishing-Scam-2

Right now, the   has a list of 29 of the 56 antivirus engines which correctly identify as a threat the malicious attachment that comes as PIF (program information file).

One thing is for sure, though. That although SSL certificates are a first security key they can not guarantee 100% the integrity of a connection or a website. You should always be careful about what you download and what you run on your computer. After all, the use of SSL for criminal purposes is expected to increase in the near future.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).