Tech Support scammers rip big brand security software with fake warnings

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Just when we thought we had seen it all, scammers come out with an elaborate and clever scheme to trick users into calling for bogus tech support. If you are looking to download one of the popular antivirus or anti-malware product on the market, watch out before you click.

Lookalike pages
Fraudsters have set up fake download pages that look incredibly like the authentic ones. Judge for yourself:

MBAM.png


There is even a fake page for our own Malwarebytes: Except for the toll-free number (which is not ours), the page is pretty much the same as the real one.

Hijacked software
Each page links to a download, which of course is not the actual software but certainly looks like it:



The guys behind this went to such lengths that they actually piggy-backed on the real programs and inserted their own piece of code half way through the installation procedure:

install7.png


Have a look at how well done it is with this fake Malwarebytes Anti-Malware installer:

install4.png


Call to action
The purpose of these fake programs is to trick people into thinking something is wrong with their computers:



Rather clever, isn’t it? You probably know where this is going. The phone number directs you to a tech support company located in India ready to take your money once they have run their ‘diagnostic’.

Here is the video recording of the interaction with the technician:



Behind the scenes
The fake pages are hosted here:

hzzzp://onlineinstanthelp.com/antivirus-download.html
hzzzp://onlineinstanthelp.com/norton-us/download.html
hzzzp://onlineinstanthelp.com/mcafee-us/download.html
hzzzp://onlineinstanthelp.com/avg-us/download.html
hzzzp://onlineinstanthelp.com/malwarebytes-us/download.html
hzzzp://onlineinstanthelp.com/winzip-us/download.html
hzzzp://onlineinstanthelp.com/lavasoft-us/download.html


Read more: https://blog.malwarebytes.org/fraud...g-brand-security-software-with-fake-warnings/
 

kiric96

Level 19
Verified
Well-known
Jul 10, 2014
917
:( yeah they are very smart.... is incredible the way they copy the things. well at least norton DNS block this domain
 

Attachments

  • Captura de pantalla (135).png
    Captura de pantalla (135).png
    199 KB · Views: 369
  • Captura de pantalla (136).png
    Captura de pantalla (136).png
    174.4 KB · Views: 376
  • Like
Reactions: Petrovic and Jack

Petrovic

Level 64
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
Code:
hzzzp://onlineinstanthelp.com/antivirus-download.html
hzzzp://onlineinstanthelp.com/norton-us/download.html
hzzzp://onlineinstanthelp.com/mcafee-us/download.html
hzzzp://onlineinstanthelp.com/avg-us/download.html
hzzzp://onlineinstanthelp.com/malwarebytes-us/download.html
hzzzp://onlineinstanthelp.com/winzip-us/download.html
hzzzp://onlineinstanthelp.com/lavasoft-us/download.html
Adguard: SUD
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top