Live data from Hacker News

Disassembling the Woolworths Facebook scam

troyhunt.com

1–10 of 28 posts

Re: Disassembling the Woolworths Facebook scam

#3
What confuses me is the (relative) sophistication of some of these scams juxtaposed with some really shoddy website designs that scream "scam" to me.

When scammers and phishers learn to put together a semi respectable design or even simply copy the designs they are trying to imitate more precisely they would be far more successful.

Re: Disassembling the Woolworths Facebook scam

#5
I'm glad to see this blogged about as it was on my todo list. I have numerous previous examples of this scam as well if people want to compare and contrast (free sunglasses [Oakleys], free headphones [Beats by Dr Dre], etc).

What annoys me most about this is the scam is only spread through exploiting human nature and not advanced technology. The code is literally almost exactly the same each time yet nothing has been done by Facebook to prevent it. Fingerprinting this is certainly not impossible (every example I've seen is formulaic and even starts the counter at 973) and I'm surprised Facebook doesn't have an advanced spam fighting arsenal that's effective against it.

Does anyone know what tools they use to combat this sort of thing? Machine learning would work really well here considering numerous past examples and the fact you're only interested in links that are spreading virally. Even if you needed a human being for final confirmation before blocking the site, you'd knock out a link once and it'd positively impact tens of thousands of people. I'd be shocked if using bit.ly and a few other obvious spammy redirects was all you needed to trick Facebook...

Re: Disassembling the Woolworths Facebook scam

#6

What confuses me is the (relative) sophistication of some of these scams juxtaposed with some really shoddy website designs that scream "scam" to me. When scammers and phishers learn to put together a semi respectable design or even simply copy the designs they are trying to imitate more precisely they would be far more successful.

Or perhaps it is a worst is better type of thing and the crappier designs convert better for their purposes. Hmm.

Re: Disassembling the Woolworths Facebook scam

#7

What confuses me is the (relative) sophistication of some of these scams juxtaposed with some really shoddy website designs that scream "scam" to me. When scammers and phishers learn to put together a semi respectable design or even simply copy the designs they are trying to imitate more precisely they would be far more successful.

I've always been curious about that as well.

Although it doesn't entirely answer your question, you might find this paper to be interesting: "Why do Nigerian Scammers Say They are from Nigeria?" http://research.microsoft.com/pubs/167719/whyfromnigeria.pdf

Re: Disassembling the Woolworths Facebook scam

#8
post #2

Presumably the 'AL' country code test was included so the Albanian "John Smith" could/can examine the live website without being directed straight to Google.

Correct. The Woolworths one had checks for "IN" || "AU" else it would redirect to Google. That domain was registered to an Indian address.

Re: Disassembling the Woolworths Facebook scam

#9
The whois record:

Administrative Contact: James Smith Lagja e vjeter --- the name of the neighborhoo: old neighborhood tek pallati cope cope --- name of the building Elbasan, Albania n/a --- city Albania ilovefbinfo@gmail.com +355 692207020 --- some poor guys number

Its odd to find Albanian scammers, usually they suck at programming. The number should be working.

Spamming is a problem here in Albania. By checking my submission history you will find that i currently talked to a spammer even reported him but nothing was done (not a response even from the host).

He was telling me it is effective and you should do the same if you can.

Post reply on HN