Threat Level: green Handler on Duty: Russ McRee

SANS ISC: Microsoft Support Scam (again) - Internet Security | DShield SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Microsoft Support Scam (again)

We have mentioned the "Microsoft Support" scams a few times over the last 6 months or so (http://isc.sans.org/diary.html?storyid=10135), but a recent change in their operations grabbed my interest.  A colleague of mine mentioned that other day that he had been the recipient of the mystical "Microsoft Support" call to inform him that they had received an alert from his computer.  It was the usual scenario, with a twist. 

In previous iterations of this scam the person on the phone would get you to click through to the event viewer to "find something red". Strangely enough there is usually something red in most people's event log log.  However, do not despair if you don't have anything red, yellow is just as bad.  Once the problem (well any problem) was identified your support would have expired and they redirect you to a web site where you can part with your money and download some version of malware. 

The new iteration of the scam goes one step further.  Rather than get the victim to look, they get you to install teamviewer (although no doubt other similar tools are likely used). They take control of your machine and start moving the files across. Manually infecting, sorry fixing, your machine.  In this particular instance they noticed they were in a VM and promptly started removing the files they had moved, before the link was dropped and the phone call terminated.

The scam is obviously still working.  It seems they have figured out that users can't be trusted to click a link, but installing remote control software and getting you to install the malware for them is ok.

If you've received one of these calls and taken them to the point where they have started installing things and you still have those files, please let us know.  If they have used things other than teamviewer I'd be interested as well.  In the mean time remember to teach mums, dads, aunts, uncles, etc that it will be a cold day in, you know where, when Microsoft will call you out of the blue to help you fix  problem with your computer.  

-Mark H-

Thanks for the comments all. 

We had a few additional snippets of information.  Some have had a similar interaction with someone pretending to be Skype. Others have unfortunately been scammed out of a significant amount of money and left with a PC that does nothing much. (http://www.thetechherald.com/article.php/201121/7188/Cold-calling-scams-return-with-a-twist )

As for disguising VM, good question. We'll have to work on that.

 

Mark

391 Posts
ISC Handler
In my case they directed me to go to logmein123.com, rather than teamviewer, as I didn't have a VM ready to go, and I has strung them along for a good 20 minutes by this stage, I ruined the game by telling them there was no way in the world I was going to continue. With any luck if they call again I'll be quick enough to whip out my laptop and fire up a VM to capture the files.
Anonymous
Thanks JFH. Make sure you have the VM disguised. i.e. change the usual telltale elements.

M
Mark

391 Posts
ISC Handler
Things will only get better after the first scammer is lowered into a vat of boiling oil on live TV.
Mark
7 Posts
Now there is an idea for a deterrent :)

Is there a good article or how to to read on how to disguise vm's?

Thank you.
Anonymous
One big clue would be Microsoft asking you to use LogMeIn, TeamViewer or another 3rd party solution to access your machine.
Dean

135 Posts
I've been receiving these calls for the past week. They've been calling from the following numbers:

Numbers calling from: 305-760-4144, 305-760-4153
Call Back Number: 855-243-6800

They are directing me to the following site to install a tool similar to teamviewer/etc.: www.ammyy.com

Unfortunately they have the worst timing as I'm never in front of a machine where I can install the tools and get the files. They do seem very intent on getting me to do this, though, as the same guy has actually called me back a few times and seems convinced that I'm going to be falling for it.
Dean
1 Posts
How do you go about disguising? I am assuming drivers for one but am curious. I use Virtual Box for my virtual needs.
Lee

13 Posts
Re: Disguising a VM

What does a person use to discover you are running a VM?

Your MAC address, the presence of any "helper tools", the type of NIC, maybe the type of disk controller.

So change those that you can and use non-standard of those that you can.

I haven't seen an official guide on obfuscating a VM, but that would be handy, I agree.
Jasey

93 Posts
Here is a paper on how malware detects VMs and debuggers.

www.eecs.umich.edu/~zmao/Papers/DCCS-xu-chen.pdf

I can't vouch for it. I just found it, but it seems interesting.
Jasey

93 Posts
@Jason, good tips - however with a human on the phone browsing through your computer I think it will be hard to prevent VM detection..

I hope they call someone that has a physical machine they can send to the frontlines!

If not, try telling them that you are REALLY glad they called - as they must have detected problems on your gold image that you have to release shortly for your VDI deployment! If they hang up you just saved some time...
dotBATman

63 Posts
i've got a machine sitting right here on its very own network...just waiting....now, how to get them to call ME lol!
Blagarswinth

23 Posts
I received several calls thru Skype from a user * D I A G N O S T I C S * I answered one call and it was a pre-recorded message stating to visit the website listed above. If I would have known about this article I would have assisted but this call came thru on my tablet while I was AFK.
Blagarswinth
2 Posts
The actual Skype screenname is: dradiagnostics but shows as invisible even while they are calling you.
Blagarswinth
2 Posts
Yep, I recently got one of these calls. Documented the fun experience here: http://darranboyd.wordpress.com/2011/05/21/windows-live-support-scam/
Blagarswinth
1 Posts
I just received a call from these scammers about 30 minutes ago. There number was 844-620-1714. Thanks you for all your posts, it seemed like a scam and while they were pressuring me to do as they said I saw all your posts! Thank you! I did call them back and they answered.
Blagarswinth
1 Posts

Sign Up for Free or Log In to start participating in the conversation!