You are here

How I got tech support scammers infected with Locky

ivan's picture
tech support scam webpage

A few days ago, I received a panicked call from my parents who had somehow managed to land on a (now defunct) web page (snapshot here) claiming they had been infected by Zeus. This horrible HTML aggregate had it all: audio message with autoplay, endless JavaScript alerts, a blue background with cryptic file names throwing us back to Windows' BSoD days, and yet somehow it displayed a random IP address instead of the visitor's one.

First call:

After everyone had a good laugh on Twitter, I decided I would give them a call to know more about what they hoped to accomplish. So I fire up an old Windows XP VM, and get in touch with the "tech support". I am greeted with a pre-recorded message, then Patricia is kind enough to anwser my call. I immediately try to get her hopes up by telling her that I'm a businessman working on an important, high-figure contract, and that time is of the essence. Sadly, it turns out that her French is quite poor so going off-script is a no-no. She guides me through the steps needed to download some kind of remote-assistance client: Windows+R, type in iexplore remote.join360.net, jump through a few more hoops and run whatever executable is offered to you. From what I gather, this is actually a legitimate tech-support program, it being digitally signed and all.

The fun starts now. Patricia fires off cmd.exe after failing to recognize OllyDbg and IDA's icons on the desktop. In what I can only assume is a ploy to establish her technical expertise, she runs dir /s and tells me that the dates match my logins on this system and the files are all the documents I accessed. I feign amazement. Meanwhile, I stealthily send a CTRL+C into the terminal so we can go on with our lives. Patricia then types "1452 virus found", then "ip hacked", and asks me which antivirus software I'm using. None, I reply: they're too expensive and @taviso keeps breaking them anyway. The reference is lost on her but she chastises me nonetheless. Then something weird happens. She tells me that I'm at the end of my 15 minutes of free support and that she's calling me back so I don't have to pay. A few minutes later, I do indeed receive a call from a phone number in Pennsylvania (+1-267-460-7257). She goes back to berating me about my apparent disregard for basic computer hygiene. In the end, she reaches the following conclusion: my computer has been infected, and now it needs to be cleaned up. I'm encouraged to buy either ANTI SPY or ANTI TROJAN, for the measly sum of $189.90. Before I have the opportunity to get my credit card, she goes back to the terminal, runs netstat and tells me that there's someone connected to my machine at this very moment.


"Look! In the terminal! 1452 viruses found! Command not found also indicates that your machine is infected!"
By the way, I believe 115.115.67.53 to be their real IP address.

— Isn't that you? I ask. This says it's someone from Delhi.
An awkward pause follows. She tells me that she's actually the "localhost" line, because localhost means secure connexion. I fight back:
— Are you sure? I thought localhost meant the local machine.
She mumbles a little then proceeds to read me that whole section of her script again, asserting once again that this other IP belongs to a some who lives in Delhi like her but is a totally different person - a malicious hacker. I am not kidding you. We go back to the software she's trying to push.
— All right, I'll buy it, I say. Where can I purchase it in Paris?
Now she sounds quite annoyed.
— I don't know if you can find it in Paris, she replies with her choppy French accent. This is an exclusive software distributed only through Microsoft's premium partners and Microsoft's secure channels.
— Oh, so I just have to get it from microsoft.com then?
— ...Yes.
— Okay then.
— Okay.
— ...
— Did you have any other questions ? No ? Bye then.

Second call:

I assume that this is not how you scam people. She must have been a scammer trainee or something. At this point I realize that some of the screenshots I had taken were no good, so I wait half an hour or so and I call again. I was expecting to talk to the same person and tell her that I couldn't find anything on Microsoft's website, but it's someone new (Dileep) and I have to sit through the whole procedure once more. Dileep seems much more familiar with his script, and he adds some nice details such as showing me that my machine has a lot of stopped services which is "totally not normal". He goes on to tell me that my machine is infected as well, that he just cleaned it for free but he recommends that I purchase a Tech Protection subscription so I don't get viruses ever again. This package costs €299.99 which is way more expensive than Patricia's, but I assume that's because he sounds more experienced. I agree to purchase his package and find test credit card numbers as fast as I can. For obvious reasons, the payment processor rejects the transaction and we try again four or five times. In the end, I suggest using my second credit card and give him another random yet valid (as far as the Luhn algorithm is concerned) number. Dileep makes me repeat both payment details at least ten times and I play dumb. He calls his superior in the hopes of figuring out why the payment isn't going through. In the meantime, I hear other operators in the background repeating credit card numbers and CVVs aloud. I'm assuming they're not PCI-DSS compliant. That's when I'm hit by a stroke of genius. I open my "junk" e-mail folder where I find many samples of the latest Locky campaign - those .zip files containing a JS script which downloads ransomware. I grab one at random, drag it into the VM. The remote-assistance client I installed has a feature allowing me to send files to the operator. I upload him the archive and say:
— I took a photo of my credit card, why don't you input the numbers yourself? Maybe that'll work.
At first, Dileep ignores me. He makes me type in my information a few more times (he's persistent, I'll give him that), until I put my foot down:
— Look, Dileep, I'm old and my sight is not so good. It's starting to hurt, having to squint to read those tiny numbers. Also, we've established I'm no good with computers, how about you give me a hand here?
He says nothing for a short while, and then:
— I tried opening your photo, nothing happens.
I do my best not to burst out laughing.
— Are you sure? Sometimes my pictures have a problem opening on MacOS, are you on Windows?
— Yes, he replies. Your pictures are corrupted because your computer is infected. This is why we need to take care of this.

And while a background process quietly encrypts his files, we try paying a couple more times with those random CC numbers and he finally gives up, suggesting that I contact my bank and promising to call me back next Monday.

In conclusion, whenever one stumbles on an obvious scam, the civic thing to do is to act like you buy it. Rationale: scammers don't have the time to separate legitimate mugus from the ones who just pretend. Their business model relies on the fact that only gullible people will reply. Now were they spammed back, their workload would increase so much that scamming wouldn't be a profitable activity anymore. So if you're a French speaker, you should definitely take 15 minutes of your time, call them at +339 75 18 77 63 and try to social engineer them into doing something funny.

Comments

Interesting that they're using Bomgar - that is NOT a cheap remote support tool. But more importantly - wasting their time aside -

Have you contacted their ISP's abuse address? Their webhost's abuse address?

Have you contacted various authorities regarding the company EasyTechy (Techvedic)?

ivan's picture

I'm in the process of doing all of this.
At the moment, my ADSL connection is suffering from all the traffic coming from Reddit, so I'm having a hard time getting things done!

The Reddit 'Hug of Death'!!

Here are their company details including owner and director information https://www.zaubacorp.com/company/TECHVEDIC-TECHNOLOGIES-PRIVATE-LIMITED...

You can file a complaint with the Delhi Cyber Cell - details are at - http://www.secureindia.in/?page_id=942

It's likely they're on a trial of Bomgar, or they signed up for the service with scammed credit card info.

I previously worked for a different remote access provider, and we'd kick these guys off our service 2 or 3 times a month. It got to the point where we basically had to disallow all web purchases from that region, and set up all accounts through sales directly. Fortunately, they were pretty transparent when they had to actually talk to us.

i would guess they use bomgar because its really easy to get connected and doesnt require a lot of plugins. their users probably would struggle with something like webex. im surprised they can afford it though because youre right, its not cheap

Scamming is more profitable than you can imagine.
The online black market economy is in the range of billions of dollars per year. Even a small piece of the pie is in the millions.

Hello i'am so grateful and happy to speak of this wonderful doctor call Okoh. I'm Chad Hernandez and want to speak of how God use doctor Okoh to cure me with his natural Remedy. I saw peoples writing articles of testimonies here online of how doctor Okoh have been helping them to cure their various illness, disease and health problems because of all this i became convince and i decided to give this doctor a trail, I contact the doctor with the contact information drop by the testifier. I use to be Herpes type-1 positive before i came in contact with doctor Okoh and use his remedy terrible virus and i want you to know that i meet doctor doctor Okoh this year through the help of a friend online who has benefited positively from the doctor cure, she gave me the doctors contact, i contacted him and after acting according to his prescription for some days i observed positive change in my body so i decided to go for check up; when result came out i notice that i was Herpes negative and i became so happy and so grateful that very day so decided to let the world know what has happen to me through the help of doctor okoh, you can contact the doctor through E-mail if you need help to cure or if you are having any problem with your health and be happy again because i evidence that doctor really can cure herpes. here is doctor contact to reach him doctor Okoh,
WHATS APP MESSAGING: +2348153089532
HIS EMAIL: DROKOHSPELHOME@GMAIL.COM

Hello i'am so grateful and happy to speak of this wonderful doctor call Okoh. I'm Chad Hernandez and want to speak of how God use doctor Okoh to cure me with his natural Remedy. I saw peoples writing articles of testimonies here online of how doctor Okoh have been helping them to cure their various illness, disease and health problems because of all this i became convince and i decided to give this doctor a trail, I contact the doctor with the contact information drop by the testifier. I use to be Herpes type-1 positive before i came in contact with doctor Okoh and use his remedy terrible virus and i want you to know that i meet doctor doctor Okoh this year through the help of a friend online who has benefited positively from the doctor cure, she gave me the doctors contact, i contacted him and after acting according to his prescription for some days i observed positive change in my body so i decided to go for check up; when result came out i notice that i was Herpes negative and i became so happy and so grateful that very day so decided to let the world know what has happen to me through the help of doctor okoh, you can contact the doctor through E-mail if you need help to cure or if you are having any problem with your health and be happy again because i evidence that doctor really can cure herpes. here is doctor contact to reach him doctor Okoh,
HIS EMAIL: DROKOHSPELHOME@GMAIL.COM
WHATS APP MESSAGING: +2348153089532

THAT IS AWESOME - HELL YA!

I urge you to check out 419eater.com this is an excellent strategy to shut down the scammers. You are doing the world a great service!

All i have to say is that... this is amazing genius! i hope that there machine have been affected by the ransomware! if i get any similar calls i shall do the same.

Hats off to you, Sir!
Well done!

*ROTFL*

That website is operated by South African scammers and has been for years.

What? Can you elaborate?

Nice try, nigerian prince.

One of my wife's dearest friends fell victim to this scam. She is not computer savvy. She is really good and trusting person. I've been rather angry about it ever since. Afterwards, she got concerned and called me. I explained how the support scam worked to her in layman's terms. I've been hoping for a call myself. I have a nice BeEF-ed up website I could use their assistance with.

I sent one of the scammers fake wire transfer documents. When I got tired of stringing him along I ask him to go take a hike. The poor fool kept checking his bank.

I wonder if that really worked. A ransomware my neighbor encoutered was intercepted by Windows 10 within days of the email receive date.

I did something similar. Wrote a batch script that launched 5 instances of IE that went to the top 5 known sites with the drive-by variant. Compiled it into a .exe, changed icon to the Wells Fargo emblem and renamed My Digital Locker. Now we wait...

Bravo, excellente et instructive manoeuvre!

lol, did you call back ?

Well done ! As a techie yours is my favourite scam revenge story .

As the owner of a call center business in India in my past life , I feel sorry for the call center agentthat you called as well.
The agents actually talking would just be reading from a script without ever questioning the legality of the whole process.

When I used to search for call center work for my company back in the day , there were many clients like these which used to want to give us work. Offcourse if we agreed to do a 30 day free trial for them before they start paying us.

Being a techie , I knew not to trust them ever and would ignore them . However a new eager business whose owner might not be tech savvy , you could easily get duped. Worst possibly commit a crime.

That being said a business owner who falls for such clients probably deserves every bit of what you did , probably more.

This is brilliant. And thanks for the link to the card number generating site. I can't wait for them to call. Now, if I just had one of those Locky scripts...

I salute the OP, very well done!

Agree, waste as much of these scumbags time so in essence, the more time they are dealing with you the less time they are taking advantage of someone who would fall for these scams.

Scambaiting is a fun game to play for those who are tech savvy.

'Its Lenny' is another great tool to waste these scammers time if you don't have the time, patience or tech to screw around with them.

Hi Ivan, i read from your OP around the parent-story in a austrian newspaper - Congratulations, i`m 57 years old and working longer time in IT. Happy, that this ass-holes can`t rubbery your parents.
Many regards from Vienna - Austria

Yes Your Story in News Portals Bro Good Work

ivan's picture

I knew of their project as well. I think it's awesome!

This is gold. "I'm old and my sight is not so good" - too funny.

The trouble is if they now connect to remote computers ogfgenuinely gullible people, those other people may get the locky infection.

I was expecting something like reverse shell to those bastards. anywayz, nice tips.

ivan's picture

It was quite difficult to set up a C&C during the phone call!

Hello:
If only everyone could do this!
Could you provide details so that the average person could revenge these scammers?
Your methods of dealing with these scammers are great, but somewhat hard to follow.
I'm not an IT person, but am adept at 'fixing' most all of my PC issues (I've never had to take a PC to a shop),
but your methods are still beyond me.
Could you provide a script or other instructions so that I could follow your method of scamming the scammers,
without infecting my computer?
Thank You!

ivan's picture

Absolutely not! I'm definitely not giving out tools to perform easy infections, for obvious reasons. If you're not comfortable handling malware, you should stay away from it and devise your own creative way to mess with people.

Nice story.
The samples of Locky I also received were embedded in .doc files.
I don't understand what was inside your .zip file you sent: a .js script and a .png file?
or is this possible to embed a script inside a picture?

ivan's picture

There was no PNG file in the archive. Just a single JS script that was supposed to pass as the photo.

What happened to the scammer before he realised you just sent him the locky ransomware? Did the call drop or did he start screaming? Ahah

Greetings to the general public, i want to tell about how i was cured of HIV/AIDS disease by a Doctor called Dr Edoror. I was browsing through the Internet searching for remedy on HIV and i saw comment of people talking about how Doctor Edoror cured them. I Was scared because i never believed in the Internet but i was convince to give him a try because i having no hope of been cured of HIV/AIDS so i decided to contact him with his email that was listed on the comment Dredororcurecenter@gmail.com when i contacted him he gave me hope and send a Herbal medicine to me that i took and it seriously worked for me, am a free person now without problem, my HIV result came out negative. I pray for you Dr Edoror God will give you everlasting life, you shall not die before your time for being a sincere and great men. Am so happy, you can also contact him if you have any problem like you want to get your ex back and pregnancy herbal medicine E-mail him on Dredororcurecenter@gmail.com

Am Lisa by name, i was diagnosed with Herpes for 3years ago i lived in pain with the knowledge that i wasn't going to ever be well again i contacted so many herbal doctors on this issue and wasted a large sum of money but my condition never got better i was determined to get my life back so one day i saw mr Brown post on how Dr Aba saved him from the VIRUS with herbal medicine i contacted Dr Aba on his email address dr.abaherbalhome@gmail.com we spoke on the issue i told him all that i went through and he told me not to worry that everything will be fine again so he prepared the medicine and send it to me through courier service and told me how to use it,after 14days of usage I went to see the doctor for test ,then the result was negative,am the happiest woman on earth now. this testimony is real.thanks to Dr Aba God bless you. you can also reach him on his whatsApp number +2348107155060

God bless Dr White for his marvelous work in my life, I was diagnosed of HERPES since 2013 and I was taking my medications, I wasn't satisfied i needed to get the HERPES out of my system, I searched about some possible cure for HERPES i saw a comment about Dr White how he cured HERPES with his herbal medicine, I contacted him and he guided me. I asked for solutions, he started the remedy for my health, he sent me the medicine through UPS SPEED POST. I took the medicine as prescribed by him and 14 days later i was cured from HERPES, Dr.White truly you are great, do you need his help also? Why don't you contact him through: (drallwhite666@gmail.com) or you can also reach him on phone: +2348058832454 OR 08066246077 thank you
DOCTOR WHITE CAN AS WELL CURE THE FOLLOWING DISEASE:-
HIV/AIDS
HERPES
CANCER
AND BRING BACK YOUR LOVE ONCE TO YOU .

Hello friend, I want to let you all kknow that I never believed i would be healed someday and regain my health back to normal because i was digonise of HIV since 2014 . I have been taking treatment from my doctor here in united states and there was no solution to it, So few weeks ago i came on search on the internet if i could get any information concerning the prevention of this disease, on my search i saw a testimony of someone who has been cured from HIV and another man testify he was healed from Herpes by this Man called DR OKOSUN and another person also testify how DR OKOSUN also cured him of Diabetes and he also gave the email address of DR OKOSUN and advise we should contact him for any sickness that he would be of help, so i wrote to dr. OKOSUN telling him about my (HIV Virus) he told me not to worry that i was going to be cured!! hmm i never believed it,, well after all the procedures and medicine he sent to me through DHL courier company few weeks later i started experiencing changes all over me,after some time i went to my Dr to confirmed if i have be finally healed behold it was TRUE, So friends my advise is if you have such sickness or any other at all you can email dr.OKOSUN on:(drokosunherbalcure@gmail.com )or call/whatsapp him on:(+2349030938174)

Hello, everyone! I,m here to explore blogs and forum about the wonderful and most safe cure for HERPES SIMPLEX VIRUS (HSV).
I was positive to the deadly virus called HERPES and i lost hope because i was out casted and rejected even by my closet friends.
i searched on-line to know and enquirer about cure for HERPES and i read someone testimony on how he was cured from HSV-2 so i decided to contact the same herbalist because i know that nature has the power to heal everything.
i contacted him to know how he can help me and he told me never to worry that he will hel me with the natural herbs from God!
after 2 days of contacting him, he told me that the cure has been ready and he sent it to me via DHL and it got to me after 3 days!
i used the med as he instructed me (MORNING and EVENING) and i was cured! its really like a dream but i am so happy!thats the reason i decided to also add more comment of Him so that more can be saved just like me!
and if you need his help, you can email him on dr.eroherbalhome@gmail.com or call him via his phone number:+2349063370233

Hello, everyone! I,m here to explore blogs and forum about the wonderful and most safe cure for HERPES SIMPLEX VIRUS (HSV).
I was positive to the deadly virus called HERPES and i lost hope because i was out casted and rejected even by my closet friends.
i searched on-line to know and enquirer about cure for HERPES and i read someone testimony on how he was cured from HSV-2 so i decided to contact the same herbalist because i know that nature has the power to heal everything.
i contacted him to know how he can help me and he told me never to worry that he will hel me with the natural herbs from God!
after 2 days of contacting him, he told me that the cure has been ready and he sent it to me via DHL and it got to me after 3 days!
i used the med as he instructed me (MORNING and EVENING) and i was cured! its really like a dream but i am so happy!thats the reason i decided to also add more comment of Him so that more can be saved just like me!
and if you need his help, you can email him on dr.eroherbalhome@gmail.com or call him via his phone number:+2349063370233

The superb work done by dr. wakina that brought back my husband encouraged me to wright this testimony, to motivate anybody out there fighting to sustain his or her relationship that there is still hope and ways to get back your lover because letting go will never heal a wounded heart, but finding the total cure does. I am happy woman today because of the right decisions and steps I took to fight for the man I wants to spend my entire life with and also the father of my child.
I had hope when I came across information and testimonies online by people writing on how their partner returned to them after a love spell from dr. wakina via his email dr.wakinalovetemple@gmail.com.
Before the love spell, I keep wondering how my husband moved from being a loving and caring father to a vile and nasty person overnight without reasons, unlike him. I searched myself to the ground and did not see the wrong I have done that made him pick up a bag of his cloths to his friends basement just five days to our eleventh anniversary without saying a word. I love him with every breath in me and I can do anything to make him love me gain. The testimonies and information I got about dr. wakina became my only hope after several failed attempt to get him back after he was gone for two weeks.

The superb work done by dr. wakina that brought back my husband encouraged me to wright this testimony, to motivate anybody out there fighting to sustain his or her relationship that there is still hope and ways to get back your lover because letting go will never heal a wounded heart, but finding the total cure does. I am happy woman today because of the right decisions and steps I took to fight for the man I wants to spend my entire life with and also the father of my child.
I had hope when I came across information and testimonies online by people writing on how their partner returned to them after a love spell from dr. wakina via his email dr.wakinalovetemple@gmail.com.
Before the love spell, I keep wondering how my husband moved from being a loving and caring father to a vile and nasty person overnight without reasons, unlike him. I searched myself to the ground and did not see the wrong I have done that made him pick up a bag of his cloths to his friends basement just five days to our eleventh anniversary without saying a word. I love him with every breath in me and I can do anything to make him love me gain. The testimonies and information I got about dr. wakina became my only hope after several failed attempt to get him back after he was gone for two weeks.

I am so Happy to be writing this article in here, i am here to explore blogs forum about the wonderful and most safe cure for HERPES SIMPLEX VIRUS . I was positive to the deadly Virus called HERPES and i lost hope becaand use i was rejected even by my closet friends. i searched online to know and inquire about cure for HERPES and i saw Dr OMOYE testimony online on how he was cured so many persons from Herpes Disease so i decided to contact the great herbalist because i know that nature has the power to heal everything. i contacted him to know how he can help me and he told me never to worry that he will help me with the natural herbs from God! after 2 days of contacting him, he told me that the cure has been ready and he sent it to me via DHL and it got to me after 14 days! i used the medicine as he instructed me (MORNING and EVENING) and i was cured! its really like a dream but i'm so happy! that’s the reason i decided to also add more comment of Him so that more can be saved just like me! and if you need his help,contact his Email now (dromoyespellcastertemple@gmail.com) or him on whatsApp number:+2349034412845 ..

THEY SAID THE PHYSICIANS SAY NO CURE FOR CANCER & HIV? I AM TELLING YOU TODAY THAT DR AGUGU CURE CANCER,
WITH HIS HERBAL MEDICINE AND ONCE YOU GET CURED YOU ARE FOREVER CURED IT IS NEVER REVERSIBLE.
MY NAME IS FEDISON JEO FROM THE UNITED STATE OF AMERICA,I AM USING THIS GREAT OPPORTUNITY TO SAVE LIFE
BY SHARING MY TESTIMONY THAT THERE IS A CURE FOR CANCER BECAUSE I AM A LIVING TESTIMONY,I SUFFERED and he send to me a herbal medicine and told me to drink and bath with the herbal medicine for one month but to my greatest surprises, i went for a medical test after two weeks and my status was negative till today i can’t keep sharing this testimony please brothers and sisters there is a cure to

.CANCER
.HIV/AIDS
. KIDNEY FAILURE
.Arthritis
.Diabetes
.STROKE
.HEPATITIS
.GONORRHEA
EPILEPSY.
.HIRE BLOOD PRESSURES
.LIVER DISORDER
.EX BACK
.MAKE YOUR DICK BIG
.YOU NEED A CHILD
.YOU WANT TO TIE YOUR HUSBAND/WIFE, TO BE YOURS FOREVER
.YOU ARE UNABLE TO SATISFY YOUR WIFE OR GIRLFRIEND SEX DESIRE DUE TO LOW ERR ACTION
.

contact this man for whatever you are going through, whatever sickness you are suffering from, Contact him with his email via, agugumagagatemple2222@gmail.com or phone,+201092372359

Hello i'am so grateful and happy to speak of this wonderful doctor call Okoh. I'm Chad Hernandez and want to speak of how God use doctor Okoh to cure me with his natural Remedy. I saw peoples writing articles of testimonies here online of how doctor Okoh have been helping them to cure their various illness, disease and health problems because of all this i became convince and i decided to give this doctor a trail, I contact the doctor with the contact information drop by the testifier. I use to be Herpes type-1 positive before i came in contact with doctor Okoh and use his remedy terrible virus and i want you to know that i meet doctor doctor Okoh this year through the help of a friend online who has benefited positively from the doctor cure, she gave me the doctors contact, i contacted him and after acting according to his prescription for some days i observed positive change in my body so i decided to go for check up; when result came out i notice that i was Herpes negative and i became so happy and so grateful that very day so decided to let the world know what has happen to me through the help of doctor okoh, you can contact the doctor through E-mail if you need help to cure or if you are having any problem with your health and be happy again because i evidence that doctor really can cure herpes. here is doctor contact to reach him doctor Okoh,
WHATS APP MESSAGING: +2348153089532
HIS EMAIL: DROKOHSPELHOME@GMAIL.COM

Pages

Add new comment

(If you're a human, don't change the following field)
Your first name.
(If you're a human, don't change the following field)
Your first name.
(If you're a human, don't change the following field)
Your first name.

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
To prevent automated spam submissions leave this field empty.
CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
5 + 1 =
Solve this simple math problem and enter the result. E.g. for 1+3, enter 4.