{"id":17341,"date":"2020-01-03T12:10:04","date_gmt":"2020-01-03T20:10:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/01\/03\/news-11077\/"},"modified":"2020-01-03T12:10:04","modified_gmt":"2020-01-03T20:10:04","slug":"news-11077","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/01\/03\/news-11077\/","title":{"rendered":"How not to buy drugs on the Internet"},"content":{"rendered":"<p><strong>Credit to Author: William Tsing| Date: Fri, 03 Jan 2020 18:52:07 +0000<\/strong><\/p>\n<p><em>Disclaimer: This post is satirical in nature and meant to educate on the proliferation of scams, misinformation, and traps set up to trick those engaging in illicit or illegal activities online. Malwarebytes does not condone buying drugs on the Internet.<\/em><\/p>\n<p>Perhaps you&#8217;re sitting at work one day when suddenly the thought crosses your mind: You&#8217;re going to shift careers to become a drug lord so powerful, it will put Scarface to shame. Given that you&#8217;re not currently connected to a network of cocaine suppliers, distributors, and money launderers, you naturally turn to the Internet.  <\/p>\n<p>But users beware: Those get-rich-quick schemes almost never work out, and that includes cashing in your good citizen chips to sell drugs. And, surprise, surprise, not all websites promising kilos of cocaine with quick shipping are being 100 percent honest with you. Let&#8217;s set out and see what we find.<\/p>\n<h3> Searching for suppliers<\/h3>\n<p>As aspiring drug lords, our first search is &#8220;buy cocaine online,&#8221; which yields hxxp:\/\/buycocaineonline.us.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-attachment-id=\"41469\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/attachment\/cocaine\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/cocaine.png\" data-orig-size=\"985,647\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"cocaine\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/cocaine-300x197.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/cocaine-600x394.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/cocaine-600x394.png\" alt=\"\" class=\"wp-image-41469\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/cocaine-600x394.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/cocaine-300x197.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/cocaine.png 985w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure>\n<p>Naturally, to take advantage of the free shipping, we&#8217;ll want to buy in bulk:<\/p>\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"41470\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/attachment\/screen-shot-2019-12-05-at-12-27-30-pm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.27.30-PM.png\" data-orig-size=\"736,948\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Screen Shot 2019-12-05 at 12.27.30 PM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.27.30-PM-233x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.27.30-PM-466x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.27.30-PM-466x600.png\" alt=\"\" class=\"wp-image-41470\" width=\"350\" height=\"450\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.27.30-PM-466x600.png 466w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.27.30-PM-233x300.png 233w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.27.30-PM.png 736w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><\/figure>\n<p>There are a few red flags though, mainly in that the site owners purport to take PayPal. Like most scams, you can spot the con by looking at what sort of <a rel=\"noreferrer noopener\" aria-label=\"payment they accept (opens in a new tab)\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/tech-support-scammers-and-their-banking-woes\/\" target=\"_blank\">payment they accept<\/a>. PayPal leaves a digital trail that is trackable, and PayPal as a company frequently turns data over to all levels of law enforcement. So perhaps not the greatest method of getting our hands on an illicit product.  <\/p>\n<p>But there&#8217;s a WhatsApp number listed, so we can search on 1 (502) 509 5319. That yields the following:<\/p>\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"41471\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/attachment\/screen-shot-2019-12-05-at-12-35-57-pm\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.35.57-PM.png\" data-orig-size=\"512,314\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Screen Shot 2019-12-05 at 12.35.57 PM\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.35.57-PM-300x184.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.35.57-PM.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.35.57-PM.png\" alt=\"\" class=\"wp-image-41471\" width=\"256\" height=\"157\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.35.57-PM.png 512w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/Screen-Shot-2019-12-05-at-12.35.57-PM-300x184.png 300w\" sizes=\"auto, (max-width: 256px) 100vw, 256px\" \/><\/figure>\n<p>This is more promising, as Chinese pharma manufacturers have been known to sell online to western consumers, both via clearnet and dark net markets. Also, there&#8217;s a <a rel=\"noreferrer noopener\" aria-label=\"Wickr (opens in a new tab)\" href=\"https:\/\/en.wikipedia.org\/wiki\/Wickr\" target=\"_blank\">Wickr<\/a> ID. While use of an encrypted messenger service certainly doesn&#8217;t eliminate the possibility of a scam, drugs are brokered with the service, sometimes in person. Searching further on the Wickr ID:<\/p>\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"41807\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/attachment\/drugs-pic\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/drugs-pic.png\" data-orig-size=\"591,986\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"drugs pic\" data-image-description=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/drugs-pic-180x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/drugs-pic-360x600.png\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/drugs-pic-360x600.png\" alt=\"\" class=\"wp-image-41807\" width=\"273\" height=\"455\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/drugs-pic-360x600.png 360w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/drugs-pic-180x300.png 180w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/drugs-pic.png 591w\" sizes=\"auto, (max-width: 273px) 100vw, 273px\" \/><\/figure>\n<p>No cocaine, but a significant amount of heavy pharmaceuticals with a shipping location listed as Shanghai, China. Dropping our drug lord aspirations for a moment, <a rel=\"noreferrer noopener\" aria-label=\"Chinese fentanyl (opens in a new tab)\" href=\"https:\/\/www.nytimes.com\/2019\/12\/01\/world\/asia\/china-fentanyl-crackdown.html\" target=\"_blank\">Chinese fentanyl<\/a> and carfentanil are commonly seen as a huge contributing factor to a surge in opioid overdoses and deaths in the US. While this particular listing may or may not be a scam, acquiring real, deadly opiates via clearnet and mail is generally <a rel=\"noreferrer noopener\" aria-label=\"very easy (opens in a new tab)\" href=\"https:\/\/www.theatlantic.com\/health\/archive\/2019\/08\/chinese-company-helping-fuel-opioid-epidemic\/596254\/\" target=\"_blank\">way too easy<\/a>.  <\/p>\n<p>The Cnchemex handle appears on a site (now down) using an Indian name server, as well as a classified ad site targeting the overseas Indian community, suggesting the actor might be misrepresenting their location.  That said, real sellers doing real harm use similar methods to push product overseas.<\/p>\n<h3>Why is this so easy?<\/h3>\n<h4>Bargain hosting<\/h4>\n<p>hxxp:\/\/Buycocaineonline.us is hosted by Namecheap, a well-known, low cost host. Bargain hosts have a tendency to make their profits on volume, creating a business incentive toward taking all comers as fast as possible, with as little friction as possible. Great for reducing barriers of entry for low-resource users. Less great for keeping scams and malware out, as well as tracking bad actors.  <\/p>\n<p>Most low-cost hosts do not keep blacklists for prior bad acts, and some don&#8217;t even consider certain scams malicious if they don&#8217;t damage the user&#8217;s machine. As a result, scammers who take lots of money for &#8220;drugs&#8221; and never deliver can trivially move from one site to another without incurring significant infrastructure costs, or any significant fear of being permanently banned.<\/p>\n<h3>Lessons learned<\/h3>\n<p>The site above and those like it are pretty obvious scams 99 percent of the time. It&#8217;s easy to mock scams when they take advantage of users looking for illegal activities. But scammers like to diversify their income streams and will often use similar tactics and infrastructure for more harmful activities.  <\/p>\n<p>Ultimately, these scams are merely symptomatic of poorly-designed monitoring systems and underfunded security teams that allow both petty scams and destructive malware to slip through the net. Less fraud and a better Internet depend on addressing the systems failures that generate these vectors, as well as users who exercise a bit of critical thinking when presented with something too good to be true. And that includes becoming a drug lord via Internet search. <\/p>\n<p>Stay vigilant and stay safe.<\/p>\n<p><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/\">How not to buy drugs on the Internet<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: William Tsing| Date: Fri, 03 Jan 2020 18:52:07 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/' title='How not to buy drugs on the Internet'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2020\/01\/shutterstock_1427105327.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Most get-rich-quick schemes on the Internet prove to be scams in disguise\u2014and that includes buying drugs. Learn how scammers take advantage of users looking for illegal activities online.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/scams\/\" rel=\"category tag\">Scams<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/clearnet\/\" rel=\"tag\">clearnet<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/dark-net\/\" rel=\"tag\">dark net<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/drug-scams\/\" rel=\"tag\">drug scams<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/drugs\/\" rel=\"tag\">drugs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fraud\/\" rel=\"tag\">fraud<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/internet-crime\/\" rel=\"tag\">Internet crime<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/online-crime\/\" rel=\"tag\">online crime<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/online-drug-scams\/\" rel=\"tag\">online drug scams<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/scams\/\" rel=\"tag\">scams<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/' title='How not to buy drugs on the Internet'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2020\/01\/how-not-to-buy-drugs-on-the-internet\/\">How not to buy drugs on the Internet<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[16470,13601,23846,431,9751,23847,16451,23848,10574],"class_list":["post-17341","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-clearnet","tag-dark-net","tag-drug-scams","tag-drugs","tag-fraud","tag-internet-crime","tag-online-crime","tag-online-drug-scams","tag-scams"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17341"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17341\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17341"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}