2017-05-30 - TECH SUPPORT SCAM FROM EITEST CAMPAIGNS

NOTICE:

ASSOCIATED FILES:

  • 2017-05-29-EITest-script-for-tech-scam-after-amormariano_com_br-UK-based-traffic.pcap   (472,332 bytes)
  • 2017-05-30-EITest-script-for-tech-scam-after-amormariano_com_br-US-based-traffic-1st-run.pcap   (898,744 bytes)
  • 2017-05-30-EITest-script-for-tech-scam-after-amormariano_com_br-US-based-traffic-2nd-run.pcap   (883,541 bytes)
  • 2017-05-29-page-from-amormariano_com_br-with-injected-EITest-script-for-tech-support-scam-UK.txt   (237,041 bytes)
  • 2017-05-29-tech-support-scam-page-UK.mp3   (164,773 bytes)
  • 2017-05-29-tech-support-scam-page-UK.txt   (45,831 bytes)
  • 2017-05-30-page-from-amormariano_com.br-with-injected-EITest-script-for-tech-support-scam-US-1st-run.txt   (237,019 bytes)
  • 2017-05-30-page-from-amormariano_com_br-with-injected-EITest-script-for-tech-support-scam-US-2nd-run.txt   (237,018 bytes)
  • 2017-05-30-tech-support-scam-page-US.mp3   (589,824 bytes)
  • 2017-05-30-tech-support-scam-page-US.txt   (4,978 bytes)

 

CHECKING AN EITEST-COMPROMISED SITE FROM A LOCATION IN THE UNITED STATES (US)


Shown above:  Example of injected script in a page from the compromised website.  The highlighted URL leads to a tech support scam page.

 



Shown above:  Examples of the traffic filtered in Wireshark.

 


Shown above:  Screenshot of the tech support scam page (US style).  New phone number today.

 


Shown above:  Screenshot of the tech support scam page with the notification pop-up (US style).

 

CHECKING AN EITEST-COMPROMISED SITE FROM A LOCATION IN THE UNITED KINGDOM (UK)


Shown above:  Injected script in a page from the compromised website.  The highlighted URL leads to a tech support scam page.

 


Shown above:  Traffic filtered in Wireshark.  NOTE: As before, I had to manually copy and paste the gio.aquastring[.]bid
URL into a browser.  It did not happen automatically.

 


Shown above:  The gio.zenoricher[.]bid URL redirects to an HTTPS URL.

 


Shown above:  Screenshot of the tech support scam page (UK style).

 


Shown above:  Screenshot of the tech support scam page with the notification pop-up (UK style).

 

INDICATORS

The following are indicators associated with this activity.

 

Click here to return to the main page.