Paypal scammer

HIGHLIGHTS FROM VIRTUAL MACHINE BAIT:

  • The scammer, “Barry,” falsely claimed I was being charged for an antivirus service, prompting me to “cancel” by “opening the Google Chrome” and going to glcare.info (Code: 83257/10840, IP: 159.253.120.215 :moldova:). I faked the ScreenConnect download not working, and they still wanted me to check the downloads folder anyways.
  • They only use ScreenConnect and nothing else, so I Tunak’d them.