March 2010 April 2010 May 2010 June 2010 July 2010
August 2010
September 2010 October 2010
November 2010
December 2010 January 2011 February 2011 March 2011 April 2011 May 2011 June 2011 July 2011 August 2011 September 2011 October 2011 November 2011 December 2011 January 2012 February 2012 March 2012 April 2012 May 2012 June 2012 July 2012 August 2012 September 2012 October 2012 November 2012 December 2012 January 2013 February 2013 March 2013 April 2013 May 2013 June 2013 July 2013 August 2013 September 2013 October 2013 November 2013 December 2013 January 2014 February 2014 March 2014 April 2014 May 2014 June 2014 July 2014 August 2014 September 2014 October 2014 November 2014 December 2014 January 2015 February 2015 March 2015 April 2015 May 2015 June 2015 July 2015 August 2015 September 2015 October 2015 November 2015 December 2015 January 2016 February 2016 March 2016 April 2016 May 2016 June 2016 July 2016 August 2016 September 2016 October 2016 November 2016 December 2016 January 2017 February 2017 March 2017 April 2017 May 2017 June 2017 July 2017 August 2017 September 2017 October 2017 November 2017 December 2017 January 2018 February 2018 March 2018 April 2018 May 2018 June 2018 July 2018 August 2018 September 2018 October 2018 November 2018 December 2018 January 2019 February 2019 March 2019 April 2019 May 2019 June 2019 July 2019 August 2019 September 2019 October 2019 November 2019 December 2019 January 2020 February 2020 March 2020 April 2020 May 2020 June 2020 July 2020 August 2020 September 2020 October 2020 November 2020 December 2020 January 2021 February 2021 March 2021 April 2021 May 2021 June 2021 July 2021 August 2021 September 2021 October 2021 November 2021 December 2021 January 2022 February 2022 March 2022 April 2022 May 2022 June 2022 July 2022 August 2022 September 2022 October 2022 November 2022 December 2022 January 2023 February 2023 March 2023 April 2023 May 2023 June 2023 July 2023 August 2023 September 2023 October 2023 November 2023 December 2023 January 2024 February 2024 March 2024 April 2024 May 2024 June 2024 July 2024 August 2024 September 2024
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
20
21
22
23
24
25
26
27
28
29
30
News Every Day |

Scam ‘Funeral Streaming’ Groups Thrive on Facebook

Scammers are flooding Facebook with groups that purport to offer video streaming of funeral services for the recently deceased. Friends and family who follow the links for the streaming services are then asked to cough up their credit card information. Recently, these scammers have branched out into offering fake streaming services for nearly any kind of event advertised on Facebook. Here’s a closer look at the size of this scheme, and some findings about who may be responsible.

One of the many scam funeral group pages on Facebook. Clicking to view the “live stream” of the funeral takes one to a newly registered website that requests credit card information.

KrebsOnSecurity recently heard from a reader named George who said a friend had just passed away, and he noticed that a Facebook group had been created in that friend’s memory. The page listed the correct time and date of the funeral service, which it claimed could be streamed over the Internet by following a link that led to a page requesting credit card information.

“After I posted about the site, a buddy of mine indicated [the same thing] happened to her when her friend passed away two weeks ago,” George said.

Searching Facebook/Meta for a few simple keywords like “funeral” and “stream” reveals countless funeral group pages on Facebook, some of them for services in the past and others erected for an upcoming funeral.

All of these groups include images of the deceased as their profile photo, and seek to funnel users to a handful of newly-registered video streaming websites that require a credit card payment before one can continue. Even more galling, some of these pages request donations in the name of the deceased.

It’s not clear how many Facebook users fall for this scam, but it’s worth noting that many of these fake funeral groups attract subscribers from at least some of the deceased’s followers, suggesting those users have subscribed to the groups in anticipation of the service being streamed. It’s also unclear how many people end up missing a friend or loved one’s funeral because they mistakenly thought it was being streamed online.

One of many look-alike landing pages for video streaming services linked to scam Facebook funeral groups.

George said their friend’s funeral service page on Facebook included a link to the supposed live-streamed service at livestreamnow[.]xyz, a domain registered in November 2023.

According to DomainTools.com, the organization that registered this domain is called “apkdownloadweb,” is based in Rajshahi, Bangladesh, and uses the DNS servers of a Web hosting company in Bangladesh called webhostbd[.]net.

A search on “apkdownloadweb” in DomainTools shows three domains registered to this entity, including live24sports[.]xyz and onlinestreaming[.]xyz. Both of those domains also used webhostbd[.]net for DNS. Apkdownloadweb has a Facebook page, which shows a number of “live video” teasers for sports events that have already happened, and says its domain is apkdownloadweb[.]com.

Livestreamnow[.]xyz is currently hosted at a Bangladeshi web hosting provider named cloudswebserver[.]com, but historical DNS records show this website also used DNS servers from webhostbd[.]net.

The Internet address of livestreamnow[.]xyz is 148.251.54.196, at the hosting giant Hetzner in Germany. DomainTools shows this same Internet address is home to nearly 6,000 other domains (.CSV), including hundreds that reference video streaming terms, like watchliveon24[.]com and foxsportsplus[.]com.

There are thousands of domains at this IP address that include or end in the letters “bd,” the country code top-level domain for Bangladesh. Although many domains correspond to websites for electronics stores or blogs about IT topics, just as many contain a fair amount of placeholder content (think “lorem ipsum” text on the “contact” page). In other words, the sites appear legitimate at first glance, but upon closer inspection it is clear they are not currently used by active businesses.

The passive DNS records for 148.251.54.196 show a surprising number of results that are basically two domain names mushed together. For example, there is watchliveon24[.]com.playehq4ks[.]com, which displays links to multiple funeral service streaming groups on Facebook.

Another combined domain on the same Internet address — livestreaming24[.]xyz.allsportslivenow[.]com — lists dozens of links to Facebook groups for funerals, but also for virtually all types of events that are announced or posted about by Facebook users, including graduations, concerts, award ceremonies, weddings, and rodeos.

Even community events promoted by state and local police departments on Facebook are fair game for these scammers. A Facebook page maintained by the police force in Plympton, Mass. for a town social event this summer called Plympton Night Out was quickly made into two different Facebook groups that informed visitors they could stream the festivities at either espnstreamlive[.]co or skysports[.]live.

WHO’S BEHIND THE FAKEBOOK FUNERALS?

Recall that the registrant of livestreamnow[.]xyz — the bogus streaming site linked in the Facebook group for George’s late friend — was an organization called “Apkdownloadweb.” That entity’s domain — apkdownloadweb[.]com — is registered to a Mazidul Islam in Rajshahi, Bangladesh (this domain is also using Webhostbd[.]net DNS servers).

Mazidul Islam’s LinkedIn page says he is the organizer of a now defunct IT blog called gadgetsbiz[.]com, which DomainTools finds was registered to a Mehedi Hasan from Rajshahi, Bangladesh.

To bring this full circle, DomainTools finds the domain name for the DNS provider on all of the above-mentioned sites  — webhostbd[.]net — was originally registered to a Md Mehedi, and to the email address webhostbd.net@gmail.com (“MD” is a common abbreviation for Muhammad/Mohammod/Muhammed).

A search on that email address at Constella finds a breached record from the data broker Apollo.io saying its owner’s full name is Mohammod Mehedi Hasan. Unfortunately, this is not a particularly unique name in that region of the world.

But as luck would have it, sometime last year the administrator of apkdownloadweb[.]com managed to infect their Windows PC with password-stealing malware. We know this because the raw logs of data stolen from this administrator’s PC were indexed by the breach tracking service Constella Intelligence [full disclosure: As of this month, Constella is an advertiser on this website].

These so-called “stealer logs” are mostly generated by opportunistic infections from information-stealing trojans that are sold on cybercrime markets. A typical set of logs for a compromised PC will include any usernames and passwords stored in any browser on the system, as well as a list of recent URLs visited and files downloaded.

Malware purveyors will often deploy infostealer malware by bundling it with “cracked” or pirated software titles. Indeed, the stealer logs for the administrator of apkdownloadweb[.]com show this user’s PC became infected immediately after they downloaded a booby-trapped mobile application development toolkit.

Those stolen credentials indicate Apkdownloadweb[.]com is maintained by a 20-something native of Dhaka, Bangladesh named Mohammod Abdullah Khondokar.

The “browser history” folder from the admin of Apkdownloadweb shows Khondokar recently left a comment on the Facebook page of Mohammod Mehedi Hasan, and Khondokar’s Facebook profile says the two are friends.

Neither MD Hasan nor MD Abdullah Khondokar responded to requests for comment. KrebsOnSecurity also sought comment from Meta.

Новости 24 часа

Несостоявшийся дуэт финалиста шоу “Голос” Сергея АРУТЮНОВА и его наставника Басты. Раскрыто имя вокалиста, исполняющего хит “На Заре 2020”

Frustrated Hamilton had to "yank" steering wheel in Azerbaijan GP

New $100M DOJ lawsuit details the 'unseaworthy' condition of the ship behind Baltimore bridge collapse

Types of Bearings and Their Applications: A Look into the Bearing Industry

Premier League clubs showing frustration over secretive Manchester City trial

Ria.city






Read also

Brewers take on the Diamondbacks in first of 4-game series

LinkedIn uses personal data for AI training – here’s how to opt-out

Top senator wants child-free ideology outlawed in Russia

News, articles, comments, with a minute-by-minute update, now on Today24.pro

News Every Day

New $100M DOJ lawsuit details the 'unseaworthy' condition of the ship behind Baltimore bridge collapse

Today24.pro — latest news 24/7. You can add your news instantly now — here


News Every Day

Frustrated Hamilton had to "yank" steering wheel in Azerbaijan GP



Sports today


Новости тенниса
WTA

Кудерметова вышла во второй круг турнира WTA в Сеуле



Спорт в России и мире
Москва

В Ростове определили лучших гимнастов по программам МС и КМС



All sports news today





Sports in Russia today

Москва

Агент Сафонов: Дзюба в «Акроне» может так стрельнуть, что все офигеют!


Новости России

Game News

Эти игры настолько сложны, что доведут вас до безумия


Russian.city


WTA

Касаткина вышла в 1/4 финала турнира WTA в Сеуле


Губернаторы России
Сергей Арутюнов

Несостоявшийся дуэт финалиста шоу “Голос” Сергея АРУТЮНОВА и его наставника Басты. И почему АРУТЮНОВ только сейчас раскрыл, что на самом деле он является исполнителем хита “На Заре 2020”?


ГИБДД Подмосковья обеспечило безопасность автопробега в честь 80-летия Победы

НОПРИЗ и ТАСС подписали соглашение о сотрудничестве

Астроном Кошман назвала дату солнечного затмения в Москве

Главным врагом хорошей улыбки россияне назвали цены у стоматологов


Якутянин Петр Погодаев выпустил кавер и снял небольшой клип к песне Виктора Цоя «В сотый раз»

В Чите открыли III Фестиваль Олега Лундстрема: Праздник джаза - смелой, дерзкой и непредсказуемой музыки

Дети ахнули при виде преобразившегося Филиппа Киркорова

Келли Осборн подростком нелегально получала наркотики от врачей


Касаткина о допинговом деле Синнера: «Я верю, что он невиновен.

Александрова вышла во второй круг турнира WTA в Сеуле

Хромачёва и Данилина выиграли турнир WTA в Гвадалахаре в парном разряде

Евгений Кафельников считает, что российский теннис деградирует



Обновление Winlogon в RooX UIDM: адаптивная многофакторная аутентификация и брендирование

Главным врагом хорошей улыбки россияне назвали цены у стоматологов

«Граф Монте-Кристо» выходит в России при поддержке Relax FM

В Подмосковье сотрудники Росгвардии провели встречу со студентами финансового университета


"Крымчане - все-таки люди особой закваски": Путин пошутил об укреплении "советской власти" в Крыму

Несостоявшийся дуэт финалиста шоу “Голос” Сергея АРУТЮНОВА и его наставника Басты. И почему АРУТЮНОВ только сейчас раскрыл, что на самом деле он является исполнителем хита “На Заре 2020”?

Президент России Владимир Путин поблагодарил Главу Крыма Сергея Аксёнова за проделанную работу  

Росгвардейцы Чувашии стали бронзовыми призерами Чемпионата войск национальной гвардии по мини-футболу


Киев инициировал исключение России и Белоруссии из ассоциации избирательных органов

В Москве задержаны двое мужчин, вымогавшие 200 тыс. рублей у подростка

Лекцию об интернет-мошенниках провели для школьников Мытищ

В аэропортах Москвы с декабря введут проверку иностранцев по фото и отпечаткам



Путин в России и мире






Персональные новости Russian.city
Виктор Цой

Якутянин Петр Погодаев выпустил кавер и снял небольшой клип к песне Виктора Цоя «В сотый раз»



News Every Day

Rangers Star Insists ‘Some Moments’ Have Showed Gers’ Quality




Friends of Today24

Музыкальные новости

Персональные новости