{"id":19308,"date":"2022-06-10T08:10:04","date_gmt":"2022-06-10T16:10:04","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/06\/10\/news-13041\/"},"modified":"2022-06-10T08:10:04","modified_gmt":"2022-06-10T16:10:04","slug":"news-13041","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/06\/10\/news-13041\/","title":{"rendered":"WhatsApp spam offers up &#8220;B&#038;Q Father&#8217;s Day Contest 2022&#8221;"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 10 Jun 2022 15:49:40 +0000<\/strong><\/p>\n<p>Father&#8217;s Day in the UK (June 19) is almost upon us, and scammers are taking advantage of it\u2014and the fractional possibility of some nice weather\u2014using a barbeque-themed lure.<\/p>\n<h2>A mysterious WhatsApp message<\/h2>\n<p>The barbeque bait arrives out of the blue, from a somebody who has your number, as a random message bringing word of a supposed &#8220;B&amp;Q Father&#8217;s Day Contest&#8221; with what looks like a very nice barbeque set up for grabs. What could go wrong? (B&amp;Q is a <a href=\"https:\/\/en.wikipedia.org\/wiki\/B%26Q\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">British multinational DIY \/ home improvement company<\/a> and exactly the kind of place someone in the UK might buy a nice barbeque set from.)<\/p>\n<p>The message is plausible, and the only clue that something is amiss, other than it being unsolicited, is the Russian <code>.ru<\/code> domain name.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"57377\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/06\/whatsapp-spam-offers-up-bq-fathers-day-contest-2022\/attachment\/whatsapp-bbq-scam-message\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/whatsapp-bbq-scam-message.png\" data-orig-size=\"464,224\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"WhatsApp BBQ message\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/whatsapp-bbq-scam-message-300x145.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/whatsapp-bbq-scam-message.png\" width=\"464\" height=\"224\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/whatsapp-bbq-scam-message.png\" alt=\"WhatsApp BBQ message\" class=\"wp-image-57377\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/whatsapp-bbq-scam-message.png 464w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/whatsapp-bbq-scam-message-300x145.png 300w\" sizes=\"auto, (max-width: 464px) 100vw, 464px\" \/><figcaption>Would you spot the .ru domain?<\/figcaption><\/figure>\n<\/div>\n<p>Regular readers would know to steer clear of this missive, perhaps even ask the sender via other means if they <em>meant<\/em> to send the message. The problem with this one is that they probably <em>did<\/em> intend to send it (you&#8217;ll see why later).<\/p>\n<h2>If your name&#8217;s not down, you&#8217;re not coming in<\/h2>\n<p>The linked site really does <em>not<\/em> like you visiting from anything other than a mobile browser. Try to access from a desktop, and you&#8217;ll be told &#8220;Access Denied&#8221;. Firing up VPNs or Tor Browser, designed to help keep your online activities anonymous, seem to have a similar end result. All they want you to do is click the original link from your mobile.<\/p>\n<p>As it happens, there <em>is<\/em> a reason for this. It wouldn&#8217;t be cost-effective for promotions to allow non-mobile visitors onto a mobile themed offering. This is because said mobile offerings want to take advantage of something your desktop won&#8217;t have. It could be a feature specific to Android or iPhone, or perhaps they have a certain app in their sights.<\/p>\n<p>Click the link on your mobile from the correct geographic region and you&#8217;ll make it to the landing page. If not, you&#8217;ll probably be turned away.<\/p>\n<h2>The Father&#8217;s Day Contest landing page<\/h2>\n<p>Visitors are greeted by what appears to be a B&amp;Q-themed page.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" data-attachment-id=\"57362\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/06\/whatsapp-spam-offers-up-bq-fathers-day-contest-2022\/attachment\/bnq-offers-site\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-offers-site.png\" data-orig-size=\"536,849\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"bnq-offers-site\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-offers-site-189x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-offers-site-379x600.png\" loading=\"lazy\" width=\"536\" height=\"849\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-offers-site.png\" alt=\"\" class=\"wp-image-57362\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-offers-site.png 536w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-offers-site-189x300.png 189w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-offers-site-379x600.png 379w\" sizes=\"auto, (max-width: 536px) 100vw, 536px\" \/><figcaption>The &#8220;B&amp;Q Father&#8217;s Day Contest&#8221;<\/figcaption><\/figure>\n<\/div>\n<p>The site says<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>Welcome to the B&amp;Q Father&#8217;s Day Contest!<\/p>\n<p>Take the quiz, find the hidden prize and win the new Weber gas barbeque<\/p>\n<\/blockquote>\n<p>The Weber is a <a href=\"https:\/\/www.weber.com\/GB\/en\/barbecues\/gas-barbecues\/spirit-series-\/46512574.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">fancy bit of kit<\/a>, retailing for around $1,200. Small wonder that people would be happy to take the quiz. The quiz itself is a collection of 4 questions including:<\/p>\n<ul>\n<li>Do you know of B&amp;Q?<\/li>\n<li>How old are you?<\/li>\n<li>How would you rate B&amp;Q?<\/li>\n<\/ul>\n<p>With these out of the way, it&#8217;s competition time.<\/p>\n<h2>Best out of 3?<\/h2>\n<p>Visitors are presented with 9 gift boxes, and have 3 chances to select the correct one. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" data-attachment-id=\"57365\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/06\/whatsapp-spam-offers-up-bq-fathers-day-contest-2022\/attachment\/bnq-box-selection-quiz\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-box-selection-quiz.png\" data-orig-size=\"430,512\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"bnq-box-selection-quiz\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-box-selection-quiz-252x300.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-box-selection-quiz.png\" loading=\"lazy\" width=\"430\" height=\"512\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-box-selection-quiz.png\" alt=\"\" class=\"wp-image-57365\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-box-selection-quiz.png 430w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/bnq-box-selection-quiz-252x300.png 252w\" sizes=\"auto, (max-width: 430px) 100vw, 430px\" \/><figcaption>Oops!<\/figcaption><\/figure>\n<\/div>\n<p>Sadly I failed on my first box opening, but hit the barbeque-shaped jackpot on my second attempt. Do I get my barbeque set? Not yet:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" data-attachment-id=\"57367\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/06\/whatsapp-spam-offers-up-bq-fathers-day-contest-2022\/attachment\/share-on-whatsapp\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/share-on-whatsapp.png\" data-orig-size=\"1440,1336\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"share-on-whatsapp\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/share-on-whatsapp-300x278.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/share-on-whatsapp-600x557.png\" loading=\"lazy\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/share-on-whatsapp.png\" alt=\"\" class=\"wp-image-57367\" width=\"360\" height=\"334\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/share-on-whatsapp.png 1440w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/share-on-whatsapp-300x278.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/share-on-whatsapp-600x557.png 600w\" sizes=\"auto, (max-width: 360px) 100vw, 360px\" \/><figcaption>&#8220;Tap continue and claim your gift&#8221;<\/figcaption><\/figure>\n<\/div>\n<p>First, the scammers tell you to &#8220;share with 5 groups \/ 20 friends on WhatsApp&#8221; to claim your gift, with the offer only being valid for 500 seconds. This is why you get the message from a friend, and this is how it spreads.<\/p>\n<p>Try as I might, the site wouldn&#8217;t let me progress past this stage. If you refresh the page, the number of gifts resets to the original amount of 250 and then stops at a low number. Just enough to make you think there&#8217;s a few left. Does anybody <em>really<\/em> think they&#8217;re giving away around $300,000 of barbeque equipment every few minutes?<\/p>\n<p>There&#8217;s also multiple Facebook-style comments at the bottom of the page, complete with inactive Like and Reply options underneath each one of the other supposed winners.<\/p>\n<p>Based on how these things usually go, you probably have to hand over personal information to an advertiser. There&#8217;s no FAQ, EULA, competition rules, or privacy policy on the landing page; merely a copyright notice at the bottom listed as &#8220;Advertorial&#8221;.<\/p>\n<p>As tempting an offer as this sounds, we&#8217;d advise anyone looking for a gift this Father&#8217;s Day to keep shopping around.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/06\/whatsapp-spam-offers-up-bq-fathers-day-contest-2022\/\">WhatsApp spam offers up &#8220;B&amp;Q Father&#8217;s Day Contest 2022&#8221;<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/06\/whatsapp-spam-offers-up-bq-fathers-day-contest-2022\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 10 Jun 2022 15:49:40 +0000<\/strong><\/p>\n<p>We take a look at a scam barbeque quiz that asks &#8220;winners&#8221; to send a lot of WhatsApp messages to qualify.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/06\/whatsapp-spam-offers-up-bq-fathers-day-contest-2022\/\">WhatsApp spam offers up &#8220;B&amp;Q Father&#8217;s Day Contest 2022&#8221;<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[26494,26495,12968,11553,10447,10574,10518,26496,10440],"class_list":["post-19308","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-bq","tag-barbeque","tag-messages","tag-messaging","tag-quiz","tag-scams","tag-spam","tag-weber-gas-barbeque","tag-whatsapp"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19308"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19308\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19308"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}