Fun with Phishing

Post a reply


This question is a means of preventing automated form submissions by spambots.
Smilies
:smile: :sad: :eek: :shock: :cool: :-x :razz: :oops: :evil: :twisted: :wink: :idea: :arrow: :neutral: :mrgreen:

BBCode is ON
[img] is ON
[url] is ON
Smilies are ON

Topic review
   

Expand view Topic review: Fun with Phishing

Re: Fun with Phishing

by Ice Cream Jonsey » Tue Mar 22, 2022 3:38 pm

And now you're dragging us into it! They will come after us next!

MOOOOOOOOOOOOOOOOOOOOOOM!

Re: Fun with Phishing

by AArdvark » Tue Mar 22, 2022 3:12 pm

People not recognizing them as scams is the sad part. My mom paid a scammer almost a hundred bucks for them to remotely install CC Cleaner because a pop up window said her machine was infected. I wasn't available at the time and she didn't know any better

Re: Fun with Phishing

by pinback » Tue Mar 22, 2022 2:48 pm

Are you sure that's the sad part?

Fun with Phishing

by Casual Observer » Tue Mar 22, 2022 2:25 pm

Anyone else like having fun with scammers?

So the wife freaks out because she gets this text:
fucking phishers wrote:Thanks, the Transaction $252 for "GeekSquad-(Silver Package)" has been successfully processed. Wish to CanceI, Contact us at; 845-307-6419 Thanks
I told her they're either just trying to see if it's a real number or a full blown phishing scam. So I had a few minutes free to call the above 845 number. First indian who answered hung up after I said three times, "is this really the Geek Squad by Best Buy?" click. Next guy I played along, he pretended to look up my "account" using my name and throwaway email address. Next, he "confirmed" that myself (again, wife's phone) or someone else had signed me up for an account and I would need to fill out a "Cancellation Form". I'm like, great, thanks for the help, I'm on the Best Buy website now what do I click?

"no, sir, Mr. Eric, sorry, let me give you the instructions. Do you see the long rectangle at the top of your browser? That's where you will type what I tell you"

He has me type this into my browser, google suggests by the second gg:
gg.gg/nor2022

(.gg is the domain for Bailiwick of Guernsey, btw)

So, switch to my guest account, fire up the VPN and Incognito window, type in gg.etc and it resolves to this beauty:

https://adam90730.wixsite.com/norton

Such a professional website, love that they saved a bit of coin by not paying for the website:

Image

Here's the fun stuff from the whole process. To get the "cancellation

Image

I don't have a sandbox so I don't know if these are ransomware, viruses, or they're just trying to get paid for antivirus downloads.
https://download.aweray.com/awesun/wind ... .34643.exe
https://download.anydesk.com/anydesk.dm ... 1640941370

Image

For the "Cancellation Forms" which he originally dangled in front of me, those links just go to google docs which seem safe although amateurishly made forms. Sure they'll help grab some contact info, they're asking for bank name but no account number so maybe they're going to go cross check againsty the bank numbers from the dark web.

Image
https://docs.google.com/forms/d/e/1FAIp ... A/viewform
https://docs.google.com/forms/d/e/1FAIp ... g/viewform

The sad part of this is my wife probably would have clicked those links if she bothered calling them instead of making me do it.

Top