An open community 
of Macintosh users,
for Macintosh users.

FineTunedMac Dashboard widget now available! Download Here

Previous Thread
Next Thread
Print Thread
robocall malware!
#17078 08/18/11 07:29 PM
Joined: Aug 2009
OP Offline

Joined: Aug 2009
so I'm walking back to my desk when I hear my skype ring and auto answer. it's a robocall from "ONLINE ALERT® - ACTION REQUIRED" (skype id t01.computer.system.notification) telling me in a little snitch type voice that my computer was not protected and I needed to go to www.sospws.com immediately. The recording looped for several minutes and then disconnected. Browsing there out of curiosity, it's a not-too-convincing scareware page.

Well, that's a new angle, huh?


I work for the Department of Redundancy Department
Re: robocall malware!
Virtual1 #17079 08/18/11 09:33 PM
Joined: Aug 2009
Likes: 1
Offline

Joined: Aug 2009
Likes: 1
It is. This is a very interesting twist on the scareware/malware scam; it isn't trying to download computer malware at all.

The payload is at

sospw.com/activate

which runs a fake "virus scan" and then throws up bogus but scary-looking "virus warnings". So far, so typical. However, if you click the Activate button, it doesn't download malware like most of these sites do. Instead, it asks you for your name, address, and email.

I created a bogus email account and put in phony information. What I got was an offer to activate an anti-virus "subscription service" for $19.95 a month, whereby "security experts" would remote into my computer and clean up the "viruses" for me.

The "subscription service" is advertising the URL

https://safeandsecures.com/sasecure.php

which is a redirector to

https://www.liveadmin.com/buy.php?xIkSiifUyhYkndkUfuydyYUbfdyUnUkufduUYTZRbKknNK

which is a redirector to

https://www.click2sell.eu/securepayment/...a6b50497248413d

click2sell.eu is a European company that does affiliate marketing; basically, think of it like eBay, except instead of selling old Care Bears lunch boxes you're selling services. They're the actual point of transaction--where the money changes hands.

It looks to me like sospw.com and safeandsecures.com are front-ends for liveadmin.com. The Web site at liveadmin.com is the actual Web site of the con artists. The other two sites funnel traffic to liveadmin.com in a deniable way; if they get shut down for spam, liveadmin.com keeps on going.

sospw.com and safeandsecures.com are both registered through GoDaddy and hosted on Leaseweb. liveadmin.com is hosted overseas on tiscali.de, a German black-hat Web hosting company preferred by Russian organized crime. (It's not a surprise that the liveadmin.com Web site says that their operators are fluent in Russian and English.)

What it looks like to me is that Russian organized crime, which has long been involved in fake antivirus malware, has decided that getting one-time payments for $19.95 for removing the phony antivirus malware isn't enough; they're looking for recurring sales. I bet if one signs up for this "subscription service," the recurring $19.95 monthly bills on one's credit card are almost impossible to remove.


Photo gallery, all about me, and more: www.xeromag.com/franklin.html
Re: robocall malware!
tacit #17085 08/19/11 07:07 AM
Joined: Aug 2009
Likes: 15
Online

Joined: Aug 2009
Likes: 15
V1's link and your first one are dead ends already.


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire
Re: robocall malware!
tacit #17090 08/19/11 08:45 PM
Joined: Aug 2009
OP Offline

Joined: Aug 2009
I can see "bulletproof hosting" being in Russia, but why does Germany allow that?


I work for the Department of Redundancy Department
Re: robocall malware!
Virtual1 #17101 08/20/11 05:13 AM
Joined: Aug 2009
Likes: 1
Offline

Joined: Aug 2009
Likes: 1
Because it makes money?

Seriously, you see spam-friendly hosting all over the place. I ran into a situation recently where Earthlink tolerated a phish site on their network for quite a long time. Abuse teams not only don't make money for an ISP, they *cost* it money.


Photo gallery, all about me, and more: www.xeromag.com/franklin.html

Moderated by  alternaut, dkmarsh, joemikeb 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.4
(Release build 20200307)
Responsive Width:

PHP: 7.4.33 Page Time: 0.042s Queries: 24 (0.036s) Memory: 0.5901 MB (Peak: 0.6581 MB) Data Comp: Zlib Server Time: 2024-04-19 13:10:16 UTC
Valid HTML 5 and Valid CSS