Unreal Playground  

Go Back   Unreal Playground > Unreal Playground > Playground Cafe > News Radio

News Radio All the news that Radio sees fit to print!!!

Reply
 
Thread Tools Rate Thread Display Modes
Old 05-26-2012, 12:05 AM   #1
radio667
I R Happy Goat
 
radio667's Avatar
 
Join Date: May 2002
Posts: 10,755
Downloads: 2

Fake AV scammers dialed the wrong number

from techeye.net ................... Insecurity expert messed with their minds

One of those fake AV scammers who pose as Microsoft agents probably wished they had checked who they were calling when they phoned a security researcher at home.

According to Dark Reading,* they called Sourcefire security researcher Noah Magram and claimed they were working for Microsoft - and that Magram's computer had been sending multiple error messages to the software company and he must have some viruses and malware.

Magram wondered if he could see what their script was and see if he could find what techniques they used.

Magram says the agent on other end of the line was clueless and didn't stray far from his script.

Magram pretended to be pulling up the event viewer on his Windows machine.

When he said he saw a couple of warnings and errors in his event viewer, a new agent came on the phone.

He urged Magram to install a remote administration tool so the agent could get a closer look at the "problem".

So he started up a VMware virtual machine on his Windows PC and he gave them an environment they could play in while every movement could be recorded.

But they seem to had forgotten by that point that they were not Microsoft. The site they told him to visit was not Vole's.

Magram "agreed" to a one-year subscription for a one-time $50 fee, and they pushed him a webpage using a legitimate card processing service. He typed in a test number, which rejected the transaction.

They started disabling all Windows services and said that if Magram did not renew his subscription they couldn't be "held responsible for what happens next".

The agent said that they were disabling malware but it was a list of Windows services.

He started to dismantle the VMware and when asked what that was the engineer, identifying himself as Victor, claimed it was malware.

Victor rebooted the machine under safe mode while the agent on the line warned that there was so much malware on the machine that they wouldn't be responsible for what happened next. Magram knew that Victor's actions would disable the system altogether after a reboot, but the scammers apparently were trying one last-ditch effort to get him to cough up some cash.

When he told the scammers that they were on a VM, and he was a security expert who had been stringing them along, they quickly hung up.

Magram said the approach was "so stone age" and they were using legitimate RAT tools and an unprofessional and shaky script.

Magram was able to root out that their company's physical address, if legit, was in Utah. But he doubted that was where they were calling from.

Why he did not try and counter hack them and find out exactly where they were from we don't know.

There is a video of the whole thing here:

__________________
,


"There is also a river called Helikon [in Pieria]. (...) But, they go on to say, the women who killed Orpheus wished to wash off in it the blood-stains, and thereat the River sank underground, so as not to lend its waters to cleanse manslaughter."

—Pausanias, Description of Greece 9. 30. 8
radio667 is offline   Reply With Quote
Old 05-26-2012, 04:48 AM   #2
DeadMeatGF
Cynical [+]
 
DeadMeatGF's Avatar
 
Join Date: Jun 2003
Location: Aligned to Grid
Posts: 3,056
Downloads: 77

Send a message via MSN to DeadMeatGF
I've had that phone call - wish I'd thought to set up a VM!
__________________

... still here, prowling around ...

Stop/Eject & Wasteland
The next projects ... I'm working on these ones, too!

DeadMeatGF is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Fix the Fake UPS Tracking Number Virus Rebooting Your Machine radio667 Gadgets and Tech 3 01-19-2010 06:39 AM
Wrong Number From a Gamer Leads to His Arrest radio667 News Radio 3 02-21-2008 07:44 PM
Wrong Number Puts Motorists On Sex Chat Lunarbunny News Radio 2 10-14-2005 05:57 AM
Wrong Ashes Scattered In Ocean After Wrong Body Cremated radio667 News Radio 2 01-21-2005 07:12 PM
Dialed in HortonsWho Whatever?!? 7 05-19-2003 08:04 AM


All times are GMT -5. The time now is 06:33 AM.


Powered by: vBulletin Version 3 something...
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Style and Content © 2001-2009 Unreal Playground