What is kind of page is trackztoolz[.]com?
While looking through rogue websites, our researchers discovered the trackztoolz[.]com page. When we inspected this webpage, it ran a phishing scam. Under the guise of a delivery service chat, the scam attempts to extract personally identifiable and financial information.
It is noteworthy that the behavior of rogue webpages (i.e., what they host/promote) might vary depending on the visitor's IP address/ geolocation. When we visited trackztoolz[.]com, it ran a scam presented as a chat for a package delivery service vaguely titled "EXPRESS SERVICE".
The fake chat claims that a parcel sent to the visiting user has been damaged, and the shipping details are indiscernible. Hence, the user is asked to provide the missing information and pay an additional $1-5 fee for storage until the package can be reshipped.
While at the time of research, the phishing page (into which users are to provide their data) did not work - that does not mean that it will continue to be nonfunctional. We can surmise that this scam targets personally identifiable information such as names, addresses, telephone numbers, and email addresses.
Additionally, this scam requests payment - which could be a ploy to extract banking data (e.g., bank account details, log-in credentials, credit card numbers, etc.) through a dubious payment gateway. Therefore, victims can experience a more significant financial loss than the fee requested by this fake delivery service, as the scammers may use the exposed data to make fraudulent monetary transactions and/or online purchases.
Furthermore, trackztoolz[.]com asked visitors to allow it to deliver browser notifications. These notifications/ads are used to endorse online scams, unreliable/harmful sites and applications, and even malware.
To summarize, by trusting scams like the one promoted on trackztoolz[.]com - users can experience severe privacy issues, financial losses, and even identity theft.
|Name||trackztoolz.com scam website|
|Threat Type||Phishing, Scam, Social Engineering, Fraud|
|Fake Claim||Users' packages have been damaged and the shipping information is unreadable.|
|Detection Names||Seclookup (Malicious), Sophos (Spam), Full List Of Detections (VirusTotal)|
|Serving IP Address||18.104.22.168|
|Distribution methods||Compromised websites, rogue online pop-up ads, potentially unwanted applications.|
|Damage||Loss of sensitive private information, monetary loss, identity theft, possible malware infections.|
|Malware Removal (Windows)||
To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.
Online scams in general
The Internet is full of deceptive and malicious content. Online scams use various disguises and models, ranging from hoax giveaways to fake virus alerts.
Scams aim to trick victims into performing certain actions, e.g., disclosing private data, making monetary transactions, calling illegitimate support lines, downloading/installing and/or purchasing software, and so forth.
We have analyzed thousands of online scams; "Windows Firewall Has Detected That Your Windows Is Damaged And Irrelevant", "Win SAMSUNG GALAXY S22", "McAfee - Act Now To Keep Your Computer Protected", "Loyalty Program", and "ARK Invest Crypto Giveaway" are just some of our latest finds.
How did I open a scam website?
Scam sites can be accessed through webpages using rogue advertising networks, which can force-open the former upon entry or when hosted content is interacted with (e.g., clicking buttons, links, adverts, etc.). Misspelling a website's domain (URL) can also result in a redirect to (or redirection chain landing on) a deceptive page.
How to avoid visiting scam websites?
Deceptive websites are primarily accessed via redirects caused by sites using rogue advertising networks, mistyped URLs, spam browser notifications, intrusive advertisements, or installed adware.
We strongly recommend caution when browsing since fraudulent and malicious content usually appears legitimate. We advise against using websites that offer pirated material or other questionable services (e.g., Torrenting, illegal streaming/downloading, etc.) since they usually employ rogue advertising networks.
Additionally, always pay attention to URLs and be careful when typing them. To avoid receiving undesirable browser notifications, do not permit suspicious webpages to deliver them (i.e., do not click "Allow", "Allow Notifications", etc.). Instead, ignore or deny notification requests (i.e., select "Block", "Block Notifications", etc.).
Furthermore, always download from official and verified sources. When installing, we advise reading terms, inspecting possible options, using the "Custom/Advanced" settings, and opting-out of all bundled content - to prevent harmful software from infiltrating the system. If your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate all threats.
Text presented in the scam promoted on trackztoolz[.]com website:
Welcome to the interactive parcel management system.
I'm your virtual guise Suzy and I'll be helping you today.
First, I need you to confirm that you are not a robot. Please answer this question: What is 7+5?
12 | 3
Thank you for confirming !
We have a parcel with you as a recipient, but the label was damaged - attached is a picture of your parcel.
Please indicate if we should deliver this parcel to a private or a business address?
Private address | Business address
Thank you . In order to deliver your parcel, we need to get your details, as we currently only have your name and phone-number/email-address on record. The rest of the label is not readable.
I will redirect you to a form where you can fill in your delivery details.
As the details of the sender also are not readable on the label, we have to charge you for the manual handling of the package, as we cannot bill it back to an unknown sender. The insurance and transport costs have already been paid. There is only a small amount under $1-5 left to be paid by you for the storage until final delivery.
Schedule delivery and pay delivery fee
The appearance of trackztoolz[.]com website (GIF):
Instant automatic malware removal:
Manual threat removal might be a lengthy and complicated process that requires advanced computer skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:
- What is trackztoolz.com scam website?
- How to identify a pop-up scam?
- How do pop-up scams work?
- How to remove fake pop-ups?
- How to prevent fake pop-ups?
- What to do if you fell for a pop-up scam?
How to identify a pop-up scam?
Pop-up windows with various fake messages are a common type of lures cybercriminals use. They collect sensitive personal data, trick Internet users into calling fake tech support numbers, subscribe to useless online services, invest in shady cryptocurrency schemes, etc.
While in the majority of cases these pop-ups don't infect users' devices with malware, they can cause direct monetary loss or could result in identity theft.
Cybercriminals strive to create their rogue pop-up windows to look trustworthy, however, scams typically have the following characteristics:
- Spelling mistakes and non-professional images - Closely inspect the information displayed in a pop-up. Spelling mistakes and unprofessional images could be a sign of a scam.
- Sense of urgency - Countdown timer with a couple of minutes on it, asking you to enter your personal information or subscribe to some online service.
- Statements that you won something - If you haven't participated in a lottery, online competition, etc., and you see a pop-up window stating that you won.
- Computer or mobile device scan - A pop-up window that scans your device and informs of detected issues - is undoubtedly a scam; webpages cannot perform such actions.
- Exclusivity - Pop-up windows stating that only you are given secret access to a financial scheme that can quickly make you rich.
Example of a pop-up scam:
How do pop-up scams work?
Cybercriminals and deceptive marketers usually use various advertising networks, search engine poisoning techniques, and shady websites to generate traffic to their pop-ups. Users land on their online lures after clicking on fake download buttons, using a torrent website, or simply clicking on an Internet search engine result.
Based on users' location and device information, they are presented with a scam pop-up. Lures presented in such pop-ups range from get-rich-quick schemes to fake virus scans.
How to remove fake pop-ups?
In most cases, pop-up scams do not infect users' devices with malware. If you encountered a scam pop-up, simply closing it should be enough. In some cases scam, pop-ups may be hard to close; in such cases - close your Internet browser and restart it.
In extremely rare cases, you might need to reset your Internet browser. For this, use our instructions explaining how to reset Internet browser settings.
How to prevent fake pop-ups?
To prevent seeing pop-up scams, you should visit only reputable websites. Torrent, Crack, free online movie streaming, YouTube video download, and other websites of similar reputation commonly redirect Internet users to pop-up scams.
To minimize the risk of encountering pop-up scams, you should keep your Internet browsers up-to-date and use reputable anti-malware application. For this purpose, we recommend Combo Cleaner Antivirus for Windows.
What to do if you fell for a pop-up scam?
This depends on the type of scam that you fell for. Most commonly, pop-up scams try to trick users into sending money, giving away personal information, or giving access to one's device.
- If you sent money to scammers: You should contact your financial institution and explain that you were scammed. If informed promptly, there's a chance to get your money back.
- If you gave away your personal information: You should change your passwords and enable two-factor authentication in all online services that you use. Visit Federal Trade Commission to report identity theft and get personalized recovery steps.
- If you let scammers connect to your device: You should scan your computer with reputable anti-malware (we recommend Combo Cleaner Antivirus for Windows) - cyber criminals could have planted trojans, keyloggers, and other malware, don't use your computer until removing possible threats.
- Help other Internet users: report Internet scams to Federal Trade Commission.
Frequently Asked Questions (FAQ)
What is a pop-up scam?
Pop-up scams are deceptive messages designed to trick users into disclosing vulnerable information, making monetary transactions, calling fake support lines, downloading/installing and/or purchasing software, allowing cyber criminals to remotely access their devices, or performing other actions.
What is the purpose of a pop-up scam?
Pop-up scams aim to generate revenue at victims' expense. Scammers may profit by obtaining funds through deception, abusing or selling private data, promoting software, spreading malware, and so on.
I have provided my personal information when tricked by a scam, what should I do?
If you have disclosed account log-in credentials - change the passwords of all potentially exposed accounts and inform their official support without delay. And if you have provided personally identifiable, financial, or other vulnerable private data - immediately contact the corresponding authorities.
Why do I encounter fake pop-ups?
Pop-up scams are run on various deceptive websites. These rogue pages are typically accessed through redirects caused by mistyped URLs, sites using rogue advertising networks, intrusive ads, spam browser notifications, or installed adware.
Will Combo Cleaner protect me from pop-up scams?
Combo Cleaner is capable of scanning visited websites and detecting deceptive/malicious ones. Sites that run pop-up scams also fall into this classification. Therefore, should you enter a harmful webpage - you will be warned immediately, and further access will be restricted.