The Curious Case of the $15,000 Spam: My Unexpected Investigation

Last Friday started off like any typical day—I was busy with my work in my office when I stumbled upon a suspicious message.

My instincts told me it was spam, but my curiosity got the best of me. I clicked the link, and that’s when the adventure beg…


This content originally appeared on DEV Community and was authored by Boopathi

Last Friday started off like any typical day—I was busy with my work in my office when I stumbled upon a suspicious message.

SMS

My instincts told me it was spam, but my curiosity got the best of me. I clicked the link, and that’s when the adventure began!

The Bait: A Tempting Offer

The link led me to a flashy website claiming, “Register and Get Up to $15,000 Free Cash Prize Bonus.”

OTP

It even auto-filled my mobile number, which immediately raised my suspicions, but I decided to keep going. I clicked "Confirm" and soon received an OTP (One-Time Password).After entering the OTP, I was greeted with a bunch of gift boxes, prompting me to pick one.

website

When I clicked "Activate Now," I was redirected to a well-known Indian gambling app's installation page. The scam was starting to come together.

Time to Investigate

With my developer hat on, I knew I had to dig deeper. I revisited the website and inspected the code, and here’s where it got interesting the code looked like it was generated by ChatGPT! They hadn’t even removed the comments.

website source code

Even more shocking? The OTP was hardcoded as 456398, which was the exact number I received. They were sending the same OTP to everyone!

Behind the Curtain

Next, I checked where the site was hosted and found it was on AWS. Then, I took a look at the network requests to see how they were triggering the OTP. The request payload looked like this:

 {
    "number": mobile number,
    "sms": "1"
}

Chasing the Money Trail

Curious about how they planned to make money, I researched the gambling app I was redirected to and discovered they had an affiliate program. This means the scammers earn money every time someone installs and plays the game using their referral link. A classic exploitation tactic!

A Bit of Payback

With all this information in hand, I couldn’t just let it go. I noticed they had an endpoint that allowed sending OTP to any phone number, which sparked an idea. I figured I could send random valid phone numbers to their service—maybe even overload their system a bit. which defently going to cause some amount of money for them

So, I opened up ChatGPT (not my code editor!) and asked it to help me write a script that would send requests with randomly generated phone numbers. I capped it at around 5,000 requests to keep things manageable. It felt like just the right amount of payback without going overboard.


This content originally appeared on DEV Community and was authored by Boopathi


Print Share Comment Cite Upload Translate Updates
APA

Boopathi | Sciencx (2024-11-02T00:10:49+00:00) The Curious Case of the $15,000 Spam: My Unexpected Investigation. Retrieved from https://www.scien.cx/2024/11/02/the-curious-case-of-the-15000-spam-my-unexpected-investigation/

MLA
" » The Curious Case of the $15,000 Spam: My Unexpected Investigation." Boopathi | Sciencx - Saturday November 2, 2024, https://www.scien.cx/2024/11/02/the-curious-case-of-the-15000-spam-my-unexpected-investigation/
HARVARD
Boopathi | Sciencx Saturday November 2, 2024 » The Curious Case of the $15,000 Spam: My Unexpected Investigation., viewed ,<https://www.scien.cx/2024/11/02/the-curious-case-of-the-15000-spam-my-unexpected-investigation/>
VANCOUVER
Boopathi | Sciencx - » The Curious Case of the $15,000 Spam: My Unexpected Investigation. [Internet]. [Accessed ]. Available from: https://www.scien.cx/2024/11/02/the-curious-case-of-the-15000-spam-my-unexpected-investigation/
CHICAGO
" » The Curious Case of the $15,000 Spam: My Unexpected Investigation." Boopathi | Sciencx - Accessed . https://www.scien.cx/2024/11/02/the-curious-case-of-the-15000-spam-my-unexpected-investigation/
IEEE
" » The Curious Case of the $15,000 Spam: My Unexpected Investigation." Boopathi | Sciencx [Online]. Available: https://www.scien.cx/2024/11/02/the-curious-case-of-the-15000-spam-my-unexpected-investigation/. [Accessed: ]
rf:citation
» The Curious Case of the $15,000 Spam: My Unexpected Investigation | Boopathi | Sciencx | https://www.scien.cx/2024/11/02/the-curious-case-of-the-15000-spam-my-unexpected-investigation/ |

Please log in to upload a file.




There are no updates yet.
Click the Upload button above to add an update.

You must be logged in to translate posts. Please log in or register.