Customized Support Scam Supported by Typo Squatting

Published: 2014-12-15
Last Updated: 2014-12-15 21:11:59 UTC
by Johannes Ullrich (Version: 1)
7 comment(s)

This attack got it "all", and shows how hard it can be for a non ISC reader to evade some of these tech support scams. The URL used, http://login.microsoftlonine.com is only one letter off from the legit Microsoft Office 365 login page (you noticed the extra letter?).

The content you will get back varies. But here is a screenshot submitted by our reader Daniel:

The user was redirected to warning.netsecurityalerts.com (the site appears down right now), and to bolster the site's credibility, it displays the user's correct ISP (we all know this is an easy whois lookup, but a user confronted with this message is much more likely to fall for it then a recent message).

Calling the 800 number now will lead to a sales system trying to sell you a medial alert button if you are 50 years or older. 

 

 

---
Johannes B. Ullrich, Ph.D.
STI|Twitter|LinkedIn

Keywords:
7 comment(s)

Comments

I had a similar one the other day when I typoed a URL. Only in this case it warned that my computer had malware and sounded some kind of audible alert on the sound system. It had a number to call like this one, but I do not think it was to sell me a medical bracelet.....
Ok, since neither domain is, strictly speaking, serving malware, and thus they aren't listed at malwaredomains.com, where can we get a list of domain names that are purely for hosting social-engineering-enabling garbage like this, so that we can block such sites at a proxy server?
> The URL used, http://login.microsoftlonine.com is only one letter off from the legit Microsoft Office 365 login page

Depends on how you count to "one":

... microsoft <L> on <missing-L> ine.com ...

One letter is out-of-place, but two "edits" are necessary to get to the actual Microsoft site.

The scammer's URL is:

... microsoft <L> on <L> ine.com ...

Don't go there! :-)

IE11 -> Tools -> Internet Options -> Security -> Restricted Sites -> type-'microsoftLonline.com' -> Add -> OK
test
test2
test gpg
Heres two more typo squats for you, but no malware as they are mine :)
http://gogle-analytics.com/cgi-bin/awstats.pl
http://gogleapis.com/cgi-bin/awstats.pl

Both are collecting stats on who loads scripts/css from them.

Diary Archives