I think what we might be seeing here is the outcome of some overpaid consultant's claim that they can protect ebay from fraud with 'sophisticated' malware detection.
I think what we might be seeing here is the outcome of some overpaid consultant's claim that they can protect ebay from fraud with 'sophisticated' malware detection.
Feed that into a system that monitors lots of other inputs, and you start to build improved fraud detection systems. Most of these systems benefit significantly from long tail / long history monitoring - all the other providers of systems in this space try to get beacons onto virtually all the pages you visit, monitor all mouse and other movements you carry out etc.
Why not this pretty simple and straightforward explanation vs something complicated about overpaid consultants? Amazon does $80B of sales or something per year. Each 1% of fraud on this platform is worth $800 million. How overpaid must a consultant be who can knock this down?
I'm curious how someone with crypt in their name would ignore obvious remote access trojan installs as a threat vector?
At best, the result of the data points created by this script is going to create a temporary drop in fraud, which can be used by the aforementioned 'consultant' to claim (premature) victory. Give it a month or two, and the fraud numbers are going to go back to their previous levels.
So you'll be wrong here. And even a 6 month decline in fraud is highly valuable to any of these large scale players.
I'm wondering if eBay displays a fraud warning, or pretends to allow the transaction to occur (shadow bidding?), or just hellbans the account being used.
For shill-bidding farms, the obvious counter is to move remote screen access to non-standard ports, or move to headless browser operation via other scripting methods.
It will just feed the data-point into an anti-fraud/anti-spam system along with everything else.
And the anti-fraud/anti-spam system is probably a machine learning black box. It will learn if this data-point is actually correlated with naughty behaviour, and what other factors are usually correlated.
Check out some of this guys videos: https://www.youtube.com/channel/UCm22FAXZMw1BaWeFszZxUKw
The rest just need to notice they're no longer making money and being 1337, will get updated h4xx0r t00lz once the first group releases them.
Bad guys do use compromised seevers and devices,often it's bind() shell (like a webshell) that can easily be detected. I think it helps when they use compromised hosts as proxies to avoid IP restrictions.