{"id":869,"date":"2012-06-21T07:04:02","date_gmt":"2012-06-21T14:04:02","guid":{"rendered":"http:\/\/www.nadynerichmond.com\/blog\/?p=869"},"modified":"2012-06-25T15:23:41","modified_gmt":"2012-06-25T22:23:41","slug":"using-vmware-workstation-to-thwart-a-fake-antivirus-scammer","status":"publish","type":"post","link":"https:\/\/www.nadynerichmond.com\/blog\/2012\/06\/21\/using-vmware-workstation-to-thwart-a-fake-antivirus-scammer\/","title":{"rendered":"using VMware Workstation to thwart a fake antivirus scammer"},"content":{"rendered":"<p>I&#8217;ve gotten a bunch of fake antivirus\/malware scammers calling my home lately. \u00a0Like others, sometimes I take delight in stringing them along, playing dumb while they try to get access to my machine. \u00a0Sometimes, I&#8217;ll ask them, &#8220;What&#8217;s Windows?&#8221;, waiting for them to figure out that I&#8217;m not actually a Windows users at all. \u00a0Or sometimes, when they tell me that they&#8217;re from Microsoft, I&#8217;ll use my old Microsoft credentials and say, &#8220;wow, I wasn&#8217;t aware that we were being more proactive about this, I&#8217;m so glad that our company has decided to do more to eradicate malware&#8221;. \u00a0Once they realize that they have someone technically adept on the call, they hang up instantly.<\/p>\n<p>But I&#8217;ve never strung them along like this. \u00a0A couple of weeks ago, one of these scammers cold-called a security researcher from <a href=\"http:\/\/www.sourcefire.com\/\">Sourcefire<\/a>. \u00a0The security researcher immediately knew that it was a scam, but he decided to take it a step further: he quickly set up a virtual machine for them in VMware Workstation, and let the scammer go to town: &#8220;I realized I could give them an environment to bang around in&#8221;. \u00a0 \u00a0So the scammer installed LogMeIn, and then he watched (and, yes, captured video) while the scammer disabled Windows Services and VMware services (but not actually realizing that this means that he&#8217;s in a VM!), all the while insisting that he&#8217;s removing malware. Then they force a reboot under Safe Mode, which (given that they&#8217;ve disabled everything) won&#8217;t work properly. \u00a0This is how they try to get the victim of their scam to freak out and give them their credit card details, and likely will leave the victim with a computer that won&#8217;t work at all unless they can find someone else who can figure out that it&#8217;s simply that Windows Services have been disabled.<\/p>\n<p>Dark Reading has a good breakdown of the <a title=\"Security Expert Fools, Records Fake Antivirus Scammers\" href=\"http:\/\/www.darkreading.com\/threat-intelligence\/167901121\/security\/client-security\/240001025\/security-expert-fools-records-fake-antivirus-scammers.html\">security researcher&#8217;s call<\/a>, and a shortened version of the call is available on YouTube.<br \/>\n<iframe loading=\"lazy\" src=\"http:\/\/www.youtube.com\/embed\/jb69H7l0vJA\" frameborder=\"0\" width=\"560\" height=\"315\"><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve gotten a bunch of fake antivirus\/malware scammers calling my home lately. \u00a0Like others, sometimes I take delight in stringing them along, playing dumb while they try to get access to my machine. \u00a0Sometimes, I&#8217;ll ask them, &#8220;What&#8217;s Windows?&#8221;, waiting for them to figure out that I&#8217;m not actually a Windows users at all. \u00a0Or &hellip; <a href=\"https:\/\/www.nadynerichmond.com\/blog\/2012\/06\/21\/using-vmware-workstation-to-thwart-a-fake-antivirus-scammer\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">using VMware Workstation to thwart a fake antivirus scammer<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,40],"tags":[],"class_list":["post-869","post","type-post","status-publish","format-standard","hentry","category-software","category-workstation"],"_links":{"self":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts\/869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/comments?post=869"}],"version-history":[{"count":3,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts\/869\/revisions"}],"predecessor-version":[{"id":871,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/posts\/869\/revisions\/871"}],"wp:attachment":[{"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/media?parent=869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/categories?post=869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nadynerichmond.com\/blog\/wp-json\/wp\/v2\/tags?post=869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}