This attack got it "all", and shows how hard it can be for a non ISC reader to evade some of these tech support scams. The URL used, http://login.microsoftlonine.com is only one letter off from the legit Microsoft Office 365 login page (you noticed the extra letter?). The content you will get back varies. But here is a screenshot submitted by our reader Daniel: The user was redirected to warning.netsecurityalerts.com (the site appears down right now), and to bolster the site's credibility, it displays the user's correct ISP (we all know this is an easy whois lookup, but a user confronted with this message is much more likely to fall for it then a recent message). Calling the 800 number now will lead to a sales system trying to sell you a medial alert button if you are 50 years or older.
--- |
Johannes 4074 Posts ISC Handler Dec 15th 2014 |
Thread locked Subscribe |
Dec 15th 2014 6 years ago |
I had a similar one the other day when I typoed a URL. Only in this case it warned that my computer had malware and sounded some kind of audible alert on the sound system. It had a number to call like this one, but I do not think it was to sell me a medical bracelet.....
|
KBR 63 Posts |
Quote |
Dec 15th 2014 6 years ago |
Ok, since neither domain is, strictly speaking, serving malware, and thus they aren't listed at malwaredomains.com, where can we get a list of domain names that are purely for hosting social-engineering-enabling garbage like this, so that we can block such sites at a proxy server?
|
John Hardin 62 Posts |
Quote |
Dec 16th 2014 6 years ago |
> The URL used, http://login.microsoftlonine.com is only one letter off from the legit Microsoft Office 365 login page
Depends on how you count to "one": ... microsoft <L> on <missing-L> ine.com ... One letter is out-of-place, but two "edits" are necessary to get to the actual Microsoft site. The scammer's URL is: ... microsoft <L> on <L> ine.com ... Don't go there! ![]() IE11 -> Tools -> Internet Options -> Security -> Restricted Sites -> type-'microsoftLonline.com' -> Add -> OK |
Anonymous |
Quote |
Dec 16th 2014 6 years ago |
test
|
Johannes 4074 Posts ISC Handler |
Quote |
Dec 16th 2014 6 years ago |
test2
|
Johannes 4074 Posts ISC Handler |
Quote |
Dec 16th 2014 6 years ago |
test gpg
|
Johannes 4074 Posts ISC Handler |
Quote |
Dec 16th 2014 6 years ago |
Heres two more typo squats for you, but no malware as they are mine :)
http://gogle-analytics.com/cgi-bin/awstats.pl http://gogleapis.com/cgi-bin/awstats.pl Both are collecting stats on who loads scripts/css from them. |
en4rab 1 Posts |
Quote |
Dec 17th 2014 6 years ago |
Sign Up for Free or Log In to start participating in the conversation!