Fun with Phishing

Video Game Discussions and general topics.

Moderators: AArdvark, Ice Cream Jonsey

Casual Observer
Posts: 3529
Joined: Wed Oct 01, 2003 10:23 pm
Location: Everett, WA, 2 blocks from where the Green River Killer picked them up

Fun with Phishing

Post by Casual Observer »

Anyone else like having fun with scammers?

So the wife freaks out because she gets this text:
fucking phishers wrote:Thanks, the Transaction $252 for "GeekSquad-(Silver Package)" has been successfully processed. Wish to CanceI, Contact us at; 845-307-6419 Thanks
I told her they're either just trying to see if it's a real number or a full blown phishing scam. So I had a few minutes free to call the above 845 number. First indian who answered hung up after I said three times, "is this really the Geek Squad by Best Buy?" click. Next guy I played along, he pretended to look up my "account" using my name and throwaway email address. Next, he "confirmed" that myself (again, wife's phone) or someone else had signed me up for an account and I would need to fill out a "Cancellation Form". I'm like, great, thanks for the help, I'm on the Best Buy website now what do I click?

"no, sir, Mr. Eric, sorry, let me give you the instructions. Do you see the long rectangle at the top of your browser? That's where you will type what I tell you"

He has me type this into my browser, google suggests by the second gg:
gg.gg/nor2022

(.gg is the domain for Bailiwick of Guernsey, btw)

So, switch to my guest account, fire up the VPN and Incognito window, type in gg.etc and it resolves to this beauty:

https://adam90730.wixsite.com/norton

Such a professional website, love that they saved a bit of coin by not paying for the website:

Image

Here's the fun stuff from the whole process. To get the "cancellation

Image

I don't have a sandbox so I don't know if these are ransomware, viruses, or they're just trying to get paid for antivirus downloads.
https://download.aweray.com/awesun/wind ... .34643.exe
https://download.anydesk.com/anydesk.dm ... 1640941370

Image

For the "Cancellation Forms" which he originally dangled in front of me, those links just go to google docs which seem safe although amateurishly made forms. Sure they'll help grab some contact info, they're asking for bank name but no account number so maybe they're going to go cross check againsty the bank numbers from the dark web.

Image
https://docs.google.com/forms/d/e/1FAIp ... A/viewform
https://docs.google.com/forms/d/e/1FAIp ... g/viewform

The sad part of this is my wife probably would have clicked those links if she bothered calling them instead of making me do it.
Last edited by Casual Observer on Tue Mar 22, 2022 3:13 pm, edited 2 times in total.

User avatar
pinback
Posts: 17849
Joined: Sat Apr 27, 2002 3:00 pm
Contact:

Re: Fun with Phishing

Post by pinback »

Are you sure that's the sad part?
Am I a hero? I really can't say. But, yes.

User avatar
AArdvark
Posts: 17734
Joined: Tue May 14, 2002 6:12 pm
Location: Rochester, NY

Re: Fun with Phishing

Post by AArdvark »

People not recognizing them as scams is the sad part. My mom paid a scammer almost a hundred bucks for them to remotely install CC Cleaner because a pop up window said her machine was infected. I wasn't available at the time and she didn't know any better

User avatar
Ice Cream Jonsey
Posts: 30067
Joined: Sat Apr 27, 2002 2:44 pm
Location: Colorado
Contact:

Re: Fun with Phishing

Post by Ice Cream Jonsey »

And now you're dragging us into it! They will come after us next!

MOOOOOOOOOOOOOOOOOOOOOOM!
the dark and gritty...Ice Cream Jonsey!

Post Reply