By Hook or by Crook: Exposing the Diverse Abuse Tactics of Technical Support Scammers

نویسندگان

  • Bharat Srinivasan
  • Athanasios Kountouras
  • Najmeh Miramirkhani
  • Monjur Alam
  • Nick Nikiforakis
  • Manos Antonakakis
  • Mustaque Ahamad
چکیده

Technical Support Scams (TSS), which combine online abuse with social engineering over the phone channel, have persisted despite several law enforcement actions. The tactics used by these scammers have evolved over time and they have targeted an ever increasing number of technology brands. Although recent research has provided important insights into TSS, these scams have now evolved to exploit ubiquitously used online services such as search and sponsored advertisements served in response to search queries. We use a data-driven approach to understand search-and-ad abuse by TSS to gain visibility into the online infrastructure that facilitates it. By carefully formulating tech support queries with multiple search engines, we collect data about both the support infrastructure and the websites to which TSS victims are directed when they search online for tech support resources. We augment this with a DNS-based amplification technique to further enhance visibility into this abuse infrastructure. By analyzing the collected data, we provide new insights into search-and-ad abuse by TSS and reinforce some of the findings of earlier research. Further, we demonstrate that tech support scammers are (1) successful in getting major as well as custom search engines to return links to websites controlled by them, and (2) they are able to get ad networks to serve malicious advertisements that lead to scam pages. Our study period of approximately eight months uncovered over 9,000 TSS domains, of both passive and aggressive types, with minimal overlap between sets that are reached via organic search results and sponsored ads. Also, we found over 2,400 support domains which aid the TSS domains in manipulating organic search results. Moreover, to our surprise, we found very little overlap with domains that are reached via abuse of domain parking and URL-shortening services which was investigated previously. Thus, investigation of search-and-ad abuse provides new insights into TSS tactics and helps detect previously unknown abuse infrastructure that facilitates these scams.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Dial One for Scam: Analyzing and Detecting Technical Support Scams

In technical support scams, cybercriminals attempt to convince users that their machines are infected with malware and are in need of their technical support. In this process, the victims are asked to provide scammers with remote access to their machines, who will then “diagnose the problem”, before offering their support services which typically cost hundreds of dollars. Despite their conceptu...

متن کامل

Dial One for Scam: A Large-Scale Analysis of Technical Support Scams

In technical support scams, cybercriminals attempt to convince users that their machines are infected with malware and are in need of their technical support. In this process, the victims are asked to provide scammers with remote access to their machines, who will then “diagnose the problem”, before offering their support services which typically cost hundreds of dollars. Despite their conceptu...

متن کامل

دانش‌آموزان دیرآموز: ارزیابی پویا، ویژگی‌ها، شناسایی، شیوه‌های تدریس و بهبود ظرفیت یادگیری

   A slow learner (SL) student is one who has the ability to learn necessary academic skills but at a learning rate and depth is below average of the same age peers. A very big problem that teachers faces is the difficulty to interaction with the SL students. It is a challenging task for the teachers to tackle SL students and to make them learn the academic subjects. Handling them in ...

متن کامل

The Prevalence of Unanticipated Hamate Hook Abnormalities in Computed Tomography Scans: A Retrospective Study

 Background:It is possible that some hamate hook fractures are not diagnosed or treated, thereby affecting the study of their natural history. Study of the prevalence of incidental hamate hook fractures, nonunions, and other abnormalities on computed tomography (CT) ordered for another reason could document a subset of undiagnosed and untreated hamate hook fractures which might change our under...

متن کامل

Breastfeeding: Negligence or Extreme Support? A Case Report of Child Abuse by a ‎Negligent Heroin-Dependent Mother

Background: Breastfeeding is one of the best ways to promote, develop, and secure the health of infants. Child abuse is one of the most common and most important problems in the world, and one of the factors that increase its incidence is substance dependency of the parents. Breastfeeding beyond the normal age range can be harmful to the health of the mother and baby, and may represent a pathol...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • CoRR

دوره abs/1709.08331  شماره 

صفحات  -

تاریخ انتشار 2017