{"id":7926,"date":"2017-06-13T07:10:31","date_gmt":"2017-06-13T15:10:31","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/06\/13\/news-1707\/"},"modified":"2017-06-13T07:10:31","modified_gmt":"2017-06-13T15:10:31","slug":"news-1707","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/06\/13\/news-1707\/","title":{"rendered":"The numeric Tech Support Scam campaign"},"content":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Tue, 13 Jun 2017 14:00:21 +0000<\/strong><\/p>\n<p>There are many\u00a0different tech support scam (TSS) campaigns active at any given moment, the majority of them are\u00a0fueled by malicious adverts (the browser lockers), or bundled software (the screen lockers).<\/p>\n<p>Something interesting happened recently, where legitimate &#8211; but hacked &#8211; websites would redirect to a tech support scam page, not only via malvertising but also from hacked websites bearing the mark of a popular website infection.<\/p>\n<p>What was particularly striking was the fact that visitors from the US (and some other locations), running Internet Explorer, were being targeted and redirected to the scam page instead of what we would normally expect: an exploit kit landing page.<\/p>\n<p>In this blog, we will focus on the US campaign that is pushed both via malvertising and\u00a0compromised sites and recognizable by its use of numeric domain names.<\/p>\n<h3>Numeric TSS<\/h3>\n<p>This latest tech support scam scheme can be identified by the use of only digits within its domain name. While they may look odd at first, numeric domains &#8211; as they are known &#8211;\u00a0work just like any other domain names.<\/p>\n<p>They can be quite expensive if kept short as they can represent a brand or have special meanings (i.e. containing the number 8, popular in <a href=\"https:\/\/en.wikipedia.org\/wiki\/Chinese_Numerology#Eight\" target=\"_blank\" rel=\"noopener noreferrer\">Chinese culture<\/a>), but are otherwise a cheap commodity.<\/p>\n<p>In fact, each domain we encountered as part of this attack was registered for a mere $0.88 and\u00a0came with free WhoisGuard protection for anonymity:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/register.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18199\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/register.png\" alt=\"\" width=\"937\" height=\"231\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/register.png 937w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/register-300x74.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/register-600x148.png 600w\" sizes=\"auto, (max-width: 937px) 100vw, 937px\" \/><\/a><\/p>\n<p>The numeric TSS has been around since at least early April based on this urlQuery <a href=\"http:\/\/urlquery.net\/report.php?id=1491251823442\" target=\"_blank\" rel=\"noopener noreferrer\">report<\/a>, with some of those domains registered at the end of March.<\/p>\n<pre>Domain name Creation date  6473819564947657419.win 2017-03-31  7598437654236982.win 2017-03-31<\/pre>\n<h3>Browser lockers<\/h3>\n<p>Almost all browsers fail to mitigate the fake alert used by the numeric TSS, by not allowing you to normally close the page and instead of leaving little choice other than resorting to using the Task Manager to kill the offending process.<\/p>\n<h4><strong>Internet Explorer<\/strong><\/h4>\n<p>For Internet Explorer, the crooks are using mouse events to load the dialog message. Each time the mouse moves over a certain area, the same popup will reappear. You can close the page using keyboard shortcuts only (provided you do not move your cursor) but this is not something most users would be aware of.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_TSS.png\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18204\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_TSS.png\" alt=\"\" width=\"1157\" height=\"685\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_TSS.png 1157w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_TSS-300x178.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_TSS-600x355.png 600w\" sizes=\"auto, (max-width: 1157px) 100vw, 1157px\" \/><\/a><\/p>\n<p>Code:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_code.png\" data-rel=\"lightbox-2\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18215\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_code.png\" alt=\"\" width=\"564\" height=\"402\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_code.png 564w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/IE_code-300x214.png 300w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/a><\/p>\n<h4><strong>Google Chrome<\/strong><\/h4>\n<p>The Google Chrome version of this campaign still uses the <em>history.pushState()<\/em> trick we <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/social-engineering-cybercrime\/2016\/11\/tech-support-scammers-abuse-bug-in-html5-feature-to-freeze-computers\/\" target=\"_blank\" rel=\"noopener noreferrer\">reported<\/a> back in Nov. 2016 to freeze the browser by maxing out the CPU. This affects Chrome on Windows and Mac and is by far the most disruptive experience across various browsers.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/TSS_CPU.png\" data-rel=\"lightbox-3\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18200\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/TSS_CPU.png\" alt=\"\" width=\"1351\" height=\"745\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/TSS_CPU.png 1351w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/TSS_CPU-300x165.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/TSS_CPU-600x331.png 600w\" sizes=\"auto, (max-width: 1351px) 100vw, 1351px\" \/><\/a><\/p>\n<p>Code:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Chrome_code.png\" data-rel=\"lightbox-4\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18216\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Chrome_code.png\" alt=\"\" width=\"570\" height=\"543\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Chrome_code.png 570w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Chrome_code-300x286.png 300w\" sizes=\"auto, (max-width: 570px) 100vw, 570px\" \/><\/a><\/p>\n<h4><strong>Firefox<\/strong><\/h4>\n<p>Firefox visitors are prompted with a username and password when the page is shown, which abuses <a href=\"https:\/\/en.wikipedia.org\/wiki\/Basic_access_authentication\" target=\"_blank\" rel=\"noopener noreferrer\">HTTP basic access authentication<\/a> to lock the browser by reloading that\u00a0authentication dialog repeatedly.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_lock.png\" data-rel=\"lightbox-5\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18223\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_lock.png\" alt=\"\" width=\"1272\" height=\"705\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_lock.png 1272w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_lock-300x166.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_lock-600x333.png 600w\" sizes=\"auto, (max-width: 1272px) 100vw, 1272px\" \/><\/a><\/p>\n<p>Code:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_code.png\" data-rel=\"lightbox-6\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18225\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_code.png\" alt=\"\" width=\"532\" height=\"81\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_code.png 532w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/FF_code-300x46.png 300w\" sizes=\"auto, (max-width: 532px) 100vw, 532px\" \/><\/a><\/p>\n<h4><strong>Edge<\/strong><\/h4>\n<p>Edge is actually the only browser that lets you close the page &#8216;cleanly&#8217; without resorting to Task Manager or other quick shortcut combinations.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_lock.png\" data-rel=\"lightbox-7\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18224\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_lock.png\" alt=\"\" width=\"1272\" height=\"741\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_lock.png 1272w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_lock-300x175.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_lock-600x350.png 600w\" sizes=\"auto, (max-width: 1272px) 100vw, 1272px\" \/><\/a><\/p>\n<p>Code:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_code.png\" data-rel=\"lightbox-8\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18221\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_code.png\" alt=\"\" width=\"424\" height=\"384\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_code.png 424w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/Edge_code-300x272.png 300w\" sizes=\"auto, (max-width: 424px) 100vw, 424px\" \/><\/a><\/p>\n<h3>Distribution part 1: Malvertising<\/h3>\n<p>We caught a few malvertising chains\u00a0involved in the numeric TSS but the most notable one was served from the AdsTerra ad network. One interesting thing is that we expected to see\u00a0a different TSS campaign here (one that is hosted on\u00a0Amazon S3).<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/malvertising_infection_chain.png\" data-rel=\"lightbox-9\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18264\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/malvertising_infection_chain.png\" alt=\"\" width=\"701\" height=\"1485\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/malvertising_infection_chain.png 701w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/malvertising_infection_chain-142x300.png 142w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/malvertising_infection_chain-283x600.png 283w\" sizes=\"auto, (max-width: 701px) 100vw, 701px\" \/><\/a><\/p>\n<h3>Distribution part 2: Compromised websites<\/h3>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2014\/10\/exposing-the-flash-eitest-malware-campaign\/\" target=\"_blank\" rel=\"noopener noreferrer\">EITest<\/a> is one of several campaigns that leverages compromised sites to monetize traffic via malicious redirections, typically to exploit kits such as RIG EK. It is also one of the few that is not only <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2015\/11\/catching-up-with-the-eitest-compromise-a-year-later\/\" target=\"_blank\" rel=\"noopener noreferrer\">longstanding<\/a> but has diversified itself with social engineering schemes already, such as <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/04\/a-story-of-fonts-by-the-eitest-hoeflertext-campaign\/\" target=\"_blank\" rel=\"noopener noreferrer\">the fake font trick<\/a>.<\/p>\n<p>In late May,\u00a0<a class=\"menu_link\" href=\"https:\/\/twitter.com\/nao_sec\" target=\"_blank\" rel=\"noopener noreferrer\">@nao_sec<\/a>\u00a0<a href=\"http:\/\/www.nao-sec.org\/2017\/05\/new-eitests-cloaking.html\" target=\"_blank\" rel=\"noopener noreferrer\">blogged<\/a> about some cloaking with EITest, in particular for certain geolocations. It quickly became clear that the multi-purpose EITest had yet another trick up its sleeve which was <a href=\"http:\/\/malware-traffic-analysis.net\/2017\/05\/25\/index3.html\" target=\"_blank\" rel=\"noopener noreferrer\">observed<\/a> by others, such as <a href=\"https:\/\/twitter.com\/malware_traffic\" target=\"_blank\" rel=\"noopener noreferrer\">Brad Duncan<\/a>.<\/p>\n<p>A large blurb is injected into compromised sites\u00a0right before the <em>&lt;\/body&gt;<\/em> tag with a URL to the numeric TSS page. What is quite noteworthy is that the URL could have been for an ad network or even one of the gates we mentioned earlier. But instead, EITest generates the right URL directly, suggesting some kind of access to the same API used in the malvertising campaigns.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/EITest_TSS.png\" data-rel=\"lightbox-10\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18297\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/EITest_TSS.png\" alt=\"\" width=\"788\" height=\"665\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/EITest_TSS.png 788w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/EITest_TSS-300x253.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/EITest_TSS-600x506.png 600w\" sizes=\"auto, (max-width: 788px) 100vw, 788px\" \/><\/a><\/p>\n<p>There are times when the API fails (perhaps because of takedowns) and we caught this happening:<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/missingdomain.png\" data-rel=\"lightbox-11\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18229\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/missingdomain.png\" alt=\"\" width=\"480\" height=\"117\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/missingdomain.png 480w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/missingdomain-300x73.png 300w\" sizes=\"auto, (max-width: 480px) 100vw, 480px\" \/><\/a><\/p>\n<p>Brad Duncan also <a href=\"http:\/\/malware-traffic-analysis.net\/2017\/05\/30\/2017-05-30-EITest-tech-support-scam-image-12.jpg\" target=\"_blank\" rel=\"noopener noreferrer\" data-rel=\"lightbox-12\" title=\"\">captured<\/a> a similar case\u00a0via EITest, where the injected coded had a blank numeric domain but also a link to a RIG EK landing page (bug, A\/B testing?).<\/p>\n<h3>Tech support scam<\/h3>\n<p>This campaign seems to fuel various call centers in India, with phone numbers generated on-the-fly and based on geolocation. While the fake alerts are an easy lead-in to scam unsuspected users for hundreds of dollars, we noticed some differences in how the scam goes down. Some call centers are outright fraudulent and go straight for the money, but others still take the time to walk you through a &#8216;diagnostic&#8217;.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18246\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/invoice_.png\" alt=\"\" width=\"1092\" height=\"752\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/invoice_.png 1092w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/invoice_-300x207.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/invoice_-600x413.png 600w\" sizes=\"auto, (max-width: 1092px) 100vw, 1092px\" \/><\/p>\n<p>Regardless, Microsoft would never use such ways\u00a0to contact people that may be infected so you can rest assured that any phone number that appears out of the blue on your machine is not to be trusted.<\/p>\n<h3>Mitigation<\/h3>\n<p>The easiest way to get rid of a browser locker (AKA browlock) is to terminate (&#8216;End task&#8217;) the associated browser process using the Task Manager. There are various ways to launch it depending on your operating system, but typically you can type it in the search bar (bottom left near Windows logo in Windows 10, or inside the Start Menu in Windows 7).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18265\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/taskmanager.png\" alt=\"\" width=\"299\" height=\"204\" \/><\/p>\n<p>This does not damage your computer but you will lose\u00a0websites you had opened. Having said that, the browser lock doesn&#8217;t give you much chance either to recover those anyway. After forcefully killing the browser process, you may be asked if you want to recover the pages from the &#8216;crash&#8217;. You are better off saying &#8216;no&#8217;, or else you will be back to square one dealing with the locker once again.<\/p>\n<h3>Conclusion<\/h3>\n<p>The delivery of tech support scams via compromised websites is\u00a0worrisome because ad-blockers will be ineffective here, since there is no middle man (advertiser) involved to be blocked.\u00a0This is why browsers play such a big role, but also where they fall short. Maintaining a blacklist of such sites is almost counter productive as the rogue domains rotate so quickly. There could be improvements on how to defeat browser lockers to give users a way out, but also perhaps to flag such pages as potentially malicious, simply based on their behaviour.<\/p>\n<p>The growing number of social engineering schemes from malware campaigns is\u00a0a sign that exploit kits are failing to generate enough victims these days, mainly due to their reliance on older vulnerabilities that have long been patched. Another factor is Google Chrome&#8217;s market share (<a href=\"https:\/\/www.netmarketshare.com\/browser-market-share.aspx?qprid=0&amp;qpcustomd=0\" target=\"_blank\" rel=\"noopener noreferrer\">c<\/a><a href=\"https:\/\/www.netmarketshare.com\/browser-market-share.aspx?qprid=0&amp;qpcustomd=0\" target=\"_blank\" rel=\"noopener noreferrer\">lose to 60%<\/a>) while most current exploits are still very much Internet Explorer-centric.<\/p>\n<p>Until\u00a0attackers can get their hands on newer exploits, they will continue to design creative lures and adapt them to specific targets\u00a0for the most impact.<\/p>\n<blockquote data-secret=\"WGxX90IEqF\" class=\"wp-embedded-content\">\n<p><a href=\"https:\/\/blog.malwarebytes.com\/tech-support-scams\/\">Tech Support Scams &#8211; Help &amp; Resource Page<\/a><\/p>\n<\/blockquote>\n<p><iframe loading=\"lazy\"  src=\"https:\/\/blog.malwarebytes.com\/tech-support-scams\/embed\/#?secret=WGxX90IEqF\" width=\"100%\" height=\"420\" frameborder=\"0\" ><\/iframe> <\/p>\n<p>Some examples of numeric TSS domain names:<\/p>\n<pre>6473819564947657419.win  7598437654236982.win  75894326984785657.win  089808456012319849851.win  28769437645567160.review  1367465423548945466.win  36546876516465456.win  15467448788975.win  1652546334798534.win  42165448125463151.win  544789942631624685.win  1317587423345278789.win  462781647864529375896239.win  547566458877948786467.win  14567996453586879.review  1894063121084890231894080.win  212655432897895349795160.win  45610897897984561087802.site  0789085614050105453286405572454.win  1987561230989456165016547084564189075132104897789415128287129.win  236846723674238468.site  712653651726438762364523546823.site  068923772895474564121755216.review  <\/pre>\n<p>Text message:<\/p>\n<pre>Windows Defender Alert : Zeus Virus Detected In Your Computer !! Please Do Not Shut Down or Reset Your Computer. The following data will be compromised if you continue:  1. Passwords  2. Browser History  3. Credit Card Information  4.Local Hard Disk Files.  This virus is well known for complete identity and credit card theft. Further action through this computer or any computer on the network will reveal private information and involve serious risks. &lt;\/br&gt;&lt;\/br&gt;Call Microsoft Technical Department: (888)<\/pre>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/06\/the-numeric-tech-support-scam-campaign\/\">The numeric Tech Support Scam campaign<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/06\/the-numeric-tech-support-scam-campaign\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: J\u00e9r\u00f4me Segura| Date: Tue, 13 Jun 2017 14:00:21 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/06\/the-numeric-tech-support-scam-campaign\/' title='The numeric Tech Support Scam campaign'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/06\/shutterstock_272922134.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>A new tech support scam campaign is being pushed in lieu of exploit kits. We take a look at its distribution method and how it is able to bring browsers to their knees.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/threat-analysis\/social-engineering-threat-analysis\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/threat-analysis\/\" rel=\"category tag\">Threat analysis<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/eitest\/\" rel=\"tag\">eitest<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/exploit-kit\/\" rel=\"tag\">exploit kit<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/malvertising\/\" rel=\"tag\">malvertising<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/scam\/\" rel=\"tag\">scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/social-engineering\/\" rel=\"tag\">Social Engineering<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tech-support\/\" rel=\"tag\">tech support<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tech-support-scam\/\" rel=\"tag\">tech support scam<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/tss\/\" rel=\"tag\">TSS<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/06\/the-numeric-tech-support-scam-campaign\/' title='The numeric Tech Support Scam campaign'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/2017\/06\/the-numeric-tech-support-scam-campaign\/\">The numeric Tech Support Scam campaign<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11158,10534,10531,3985,10510,10536,10544,10494,10545],"class_list":["post-7926","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-eitest","tag-exploit-kit","tag-malvertising","tag-scam","tag-social-engineering","tag-tech-support","tag-tech-support-scam","tag-threat-analysis","tag-tss"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7926"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7926\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}