Live data from Hacker News

Anatomy of a Rental Phishing Scam

jeffreyladish.com

71–80 of 153 posts

Re: Anatomy of a Rental Phishing Scam

#71
post #38

Earlier quoted context omitted.

Copying photos and the body text of a legitimate ad would certainly be a lot less time and effort on the part of a scammer than writing new custom scam ads every time.

Oh boy, story time. I encountered the opposite scam. I was selling a house myself. I took photos, paid to have it listed, posted a sign out front, and posted ads in various places including CL. Someone contacted me to say they responded to an ad on CL for a rental house. The prospective renter was told by the scammer he was out of town and that they could go to the house and look around the property. He would transac…

I’m currently shopping for a house and have noticed tons of listing pictures are now watermarked with “not for rent”. Now I finally understand why. Thanks :)

Re: Anatomy of a Rental Phishing Scam

#72
post #69

From the screenshot, the scam is actually pretty easy to spot if you know what to look for. Here's some clues: 1. All accomodations are available (w/d in unit, pets ok, wheelchair accessible, furnished!) - eliminating listings with all of these checked will nearly eliminate the scam listings. 2. The description doesn't include any information about who's the renter. Usually the landlord or property manager will menti…

> $4.5k will get you a 1 BR in the Bay Area

Average one-bedroom rent in San Francisco is $3,520, and two bedrooms is $4,550. It's much cheaper elsewhere in the Bay Area. In Oakland, average one-bedroom rent is $2,470, and two bedrooms is $3,050. $4,300 is very plausible in Oakland.

Source: https://www.zumper.com/blog/2020/02/zumper-national-rent-rep...

Re: Anatomy of a Rental Phishing Scam

#73
post #69

From the screenshot, the scam is actually pretty easy to spot if you know what to look for. Here's some clues: 1. All accomodations are available (w/d in unit, pets ok, wheelchair accessible, furnished!) - eliminating listings with all of these checked will nearly eliminate the scam listings. 2. The description doesn't include any information about who's the renter. Usually the landlord or property manager will menti…

> $4.5k will get you a 1 BR in the Bay Area Average one-bedroom rent in San Francisco is $3,520, and two bedrooms is $4,550. It's much cheaper elsewhere in the Bay Area. In Oakland, average one-bedroom rent is $2,470, and two bedrooms is $3,050. $4,300 is very plausible in Oakland. Source: https://www.zumper.com/blog/2020/02/zumper-national-rent-rep...

My numbers are a bit off since I last looked, and yes I was mostly looking in SF. Thanks for mentioning- I'll edit it. It definitely won't get you a furnished 3 BR with a decent interior like this place.

Re: Anatomy of a Rental Phishing Scam

#74
post #69

From the screenshot, the scam is actually pretty easy to spot if you know what to look for. Here's some clues: 1. All accomodations are available (w/d in unit, pets ok, wheelchair accessible, furnished!) - eliminating listings with all of these checked will nearly eliminate the scam listings. 2. The description doesn't include any information about who's the renter. Usually the landlord or property manager will menti…

Zillow also has lot of such scams, when I reported them unfortunately Zillow did nothing!

Anyhow, the single most significant indicator of all rental scam is that the perpetuator is not going to show you the apartment in person.

Re: Anatomy of a Rental Phishing Scam

#76
post #69

From the screenshot, the scam is actually pretty easy to spot if you know what to look for. Here's some clues: 1. All accomodations are available (w/d in unit, pets ok, wheelchair accessible, furnished!) - eliminating listings with all of these checked will nearly eliminate the scam listings. 2. The description doesn't include any information about who's the renter. Usually the landlord or property manager will menti…

> $4.5k will get you a 1 BR in the Bay Area Average one-bedroom rent in San Francisco is $3,520, and two bedrooms is $4,550. It's much cheaper elsewhere in the Bay Area. In Oakland, average one-bedroom rent is $2,470, and two bedrooms is $3,050. $4,300 is very plausible in Oakland. Source: https://www.zumper.com/blog/2020/02/zumper-national-rent-rep...

In this case the scam claims to be a house in North Berkeley (almost Albany), which I believe is more expensive than Oakland.

Re: Anatomy of a Rental Phishing Scam

#77
post #38

Earlier quoted context omitted.

Oh boy, story time. I encountered the opposite scam. I was selling a house myself. I took photos, paid to have it listed, posted a sign out front, and posted ads in various places including CL. Someone contacted me to say they responded to an ad on CL for a rental house. The prospective renter was told by the scammer he was out of town and that they could go to the house and look around the property. He would transac…

VoIP can be “backtracked”. Takes a bit of effort, but the DOJ got providers to do it for the fake IRS/SSA/INS calls. There’s a standardized process for it. Might lead to a deader-end, but “it’s VoIP so we can’t do anything” is a cop-out.

It's pretty strong to assert that it is universally possible. From a technical perspective, yes, you can determine the origin of all VoIP calls in exactly the same way as you can determine the origin of all IP packets. This is to say, yes in theory, but in practice, no in many situations, not even necessarily when the origin has intentionally been obscured.

Cold-call spam may in many cases originate from corporate PBXs or VoIP setups which were compromised by an attacker. I'm not sure how common this is but know it happens as I have been involved in the response/cleanup on two different occasions. This is perhaps the most difficult to track case as it becomes a matter of forensics on the compromised PBX setup. This is less likely for inbound though because it's not a very stable arrangement. It is also not unheard of for non-VoIP telecom providers, generally overseas, to be themselves corrupt and involved in facilitating malicious uses of the telephone system (e.g. international calling termination rate scams).

On the other hand, there are a huge number of VoIP providers which may operate overseas, may not be very responsive to complaints and requests, and even unintentionally may not retain logs that allow them to identify customers. This means that when law enforcement determines that a call originated with a VoIP provider (via phone provide records), there is a high chance that getting information about that provider could require costly legal proceedings and even then result in a dead end.

I personally use a VoIP provider right now for completely non-malicious purposes that would probably be very difficult for law enforcement to identify me from because I know the provider to be overseas, small, and to have generally poor operational practices. This isn't even a provider which markets explicitly to criminal uses (which very much exist!), it's just an extremely cheap one.

Yes, law enforcement are certainly not doing everything which is possible. But it's far from a cop-out - law enforcement has limited resources and the way things are right now VoIP providers can easily become a very frustrating dead-end.

Re: Anatomy of a Rental Phishing Scam

#78

There should be simple highlighter on the domain name in the browser so you can easily see: airbnb.com.rooms-040349.town vs airbnb.com Or some kind of script that can recognize likely b.s. for common domains. Now that I say it, it probably already exists.

That seems like a great idea! Why doesn't the url bar highlight the domain? Given how security-critical it is compared to the rest of the URL, why is it not bold and obvious? It seems so easy for browser vendors to implement...

I think you may be saying this sarcastically, but in response to the comment you replied to, at least my browser (Firefox) does do this. On this page, "ycombinator.com" is highlighted in white.

Re: Anatomy of a Rental Phishing Scam

#79
post #67

In the reply, I'd probably include 1x1 pixel hidden tracker image or maybe a legit looking logo below signature and get the client ip of the scammer's computer when it does http GET on it. The ip can tell more about where they're located.

Doesn't any half-decent webmail proxy such requests nowadays?

Re: Anatomy of a Rental Phishing Scam

#80

The scammer almost immediately sending a bunch of photos of 'himself' is very interesting to me. I've noticed the same technique on dating apps. 9/10 times if the person you're talking to is not real they'll send a 'casual' looking photo after 3-4 back and forth messages, completely unsolicited. Like the author of this article it seems to be a misguided attempt to prove that they're real somehow and immediately gives…

I had that happen and I pointed out that the website already had her photos up, and I had mine up. But she was really insistent that she send me a pic anyway so she could prove she was real. Any time someone tells you they're a real person without you asking if they're a real person is a bit fishy.
Post reply on HN