1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Windows Slightly different eventvwr scammer angle...

Discussion in 'Software' started by boiled_elephant, 12 Aug 2021.

  1. boiled_elephant

    boiled_elephant Merom Celeron 4 lyfe

    Joined:
    14 Jul 2004
    Posts:
    7,026
    Likes Received:
    1,317
    Weird one. Customer just had a remote access support scam, cold call, the usual. She didn't grant them remote control, her common sense kicked in. But - when they did the eventvwr bit, they had her scroll to the bottom of one of eventvwr's views and there was, at the bottom of the list, an entry with what was clearly some of their scam flavour text on it.

    As an added detail to lend credence to the scam, this impressed me, but on a technical level, I'm not sure how it was achieved. Can a browser popup generate an event log with tailored text? Or does it mean that they did, in fact, access her machine in some other way? She's adamant they never took control, and they had to talk her through the eventvwr steps, as usual.
     
  2. theshadow2001

    theshadow2001 [DELETE] means [DELETE]

    Joined:
    3 May 2012
    Posts:
    5,284
    Likes Received:
    183
    My understanding is its difficult to do os stuff from executing javascript in the browser. Maybe they ran something that could force an error in the browser itself, rather than the javascript engine(unpatched bug / vulnerability) which in turn could trigger an error event that ends up in event viewer. It seems unlikely though.

    Nothing is impossible I suppose, but scammers tend not to be that sophisticated and it's more likely your customer ran something to cause the event
     
    Last edited: 13 Aug 2021
  3. boiled_elephant

    boiled_elephant Merom Celeron 4 lyfe

    Joined:
    14 Jul 2004
    Posts:
    7,026
    Likes Received:
    1,317
    As usual, turns out the customer was simply mistaken. She did let them take control.

    Pity, thought I'd found something exotic and interesting.

    Speaking of scammers not being very sophisticated, they installed some Russian freeware called "lock my pc", which is so ancient the unlock code is readily available in search results. Classy.
     
    souper82 likes this.

Share This Page