Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

101–110 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#102
post #94

I feel sad that what I think of as the obvious solution, companies using subdomains like internal.microsoft.com instead of making a million different domains, is so far from happening that no one here on HN has even brought it up.

[dead]

Re: Scammers are abusing an internal Microsoft account to send spam links

#103

Earlier quoted context omitted.

In my experience they're security calls. UK has good opt out marketing rules for legit companies. But the usual security call is exactly like a spam call, no authentication from their end, immediately requesting id verification "answer these security questions", and refusing to go off script. People have been asking for years to be able to lodge a security challenge code on their profile that can add confidence in th…

In the UK, banks like Starling, Monzo and Revolut (and building societies such as Nationwide) have added a call status feature in their apps [0][1][2] that tells you if they are actually the ones calling. [0] https://www.starlingbank.com/news/starling-bank-launches-in-... [1] https://monzo.com/help/monzo-fraud-category/monzo-call-statu... [2] https://www.bbc.co.uk/articles/c1mj02vr0emo

Yeah, this is a no brainer (and I think most banks let you verify via the app rather than personal info) to avoid the annoying uncertainty (but note my mother would not be able to handle that I expect)

Re: Scammers are abusing an internal Microsoft account to send spam links

#104

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate".

Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by pressing this button. By the way we will never call you to ask an auth code or to do a wire"

Re: Scammers are abusing an internal Microsoft account to send spam links

#105

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Remember those indian microsoft support centers and that strange correlation of you being called by a indian microsoft scammer the next day after you called there. Not implying causation.. just..

Re: Scammers are abusing an internal Microsoft account to send spam links

#107

I'm receiving daily about 20 to 30 spam mails from google servers. I'm sorting them into a separate SPAM folder for the "fun" of it. Who to contact? How to make Google stop? Where to report the abuse of their services? I can't find out. The whole service is basically a big off and "we don't want any contact." Maybe I also need to publish some article, so it can be published here on HN? Maybe that could give it some t…

You can try: https://support.google.com/mail/contact/abuse?hl=en I submitted an account that sent phishing emails last week, but I’m told it’s basically a black hole and to not expect anything anything to happen.

It's not gmail accounts, but "services" (?) hosted on Google's cloud. Basically I see X.X.X.X.bc.googleusercontent.com addresses in the "Received" header fields, e.g. "22.185.141.34.bc.googleusercontent.com"

When doing a WHOIS on that IP we'll get a contact address for abuse reports: "google-cloud-compliance@google.com", but sending anything there, returns an error that the user doesn't exists.

Re: Scammers are abusing an internal Microsoft account to send spam links

#108

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

I simultaneously don’t believe this and fully believe this is something they would do. Do you have any sources on this?

Re: Scammers are abusing an internal Microsoft account to send spam links

#109

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

I'm struggling to find information about this and it's extremely interesting.

Would you please explain more?

Re: Scammers are abusing an internal Microsoft account to send spam links

#110

Earlier quoted context omitted.

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

I simultaneously don’t believe this and fully believe this is something they would do. Do you have any sources on this?

It's amazing how little information has survived: the only reference I can find right away is https://www.experts-exchange.com/questions/22812691/What-is-...

I was working in anti-spam at the time, so I was eyeballing a lot of raw email dumps and writing analysis scripts for "anomalous" urls, so it popped up fairly frequently.

Post reply on HN