Please be aware

One of my users ended up at this domain heckmce.ce.ms whilst doing a google search on masonry bricks.

It immediately tells you you are infected and tries to download “instal security central 316.exe”

It also shows a web page that mimics my computer, with some virus warnings on it

Thankfully IE9 & the user did not allow the download. I have now blocked this domain at our firewall

11 Spice ups

Thanks I’ll spread it out now!

Kalin, that sounds so wrong in such thread.

1 Spice up

thnx 4 the info

Thanks for the heads-up. It appears that domain is littered with malware.

I submitted the domain to Safe Web for further analysis.

Best,

Thomas

1 Spice up

Awesome. Thanks for the heads up.

Will black list this domain.

thanks for the headsup. Blocked it on my end.

Oh no, there goes my new website, lol.

Good catch, thanks for the heads up.

1 Spice up

After having so many Users, Friends and Family get viruses on their computers from inadvertently clicking on these malicious websites, I proactively install WOT (Web of Trust) on all the browsers of the computers i maintain and fix. This at least helps by popping up a big warning before entering a poorly rated site. It’s saved my less savvy users plenty of times.

Here is a link to check a specific site:

http://sitecheck.sucuri.net/scanner/

I used it when our site got infected, it showed me what was wrong, and I was able to figure out how to fix it (I am not a web admin).

2 Spice ups

I am using McAfee SiteAdvisor, it has helped a bunch on the systems that must do inet searches…

It has dropped the hits and chases i have to do by 90%…

We have avg here with its safe search and surf shield, but this instance was obviously a fail for them.

I did also report the domain to them and have had a reply saying the website has now been taken down.

I also reported the domain as infected to the registrar and the website owner, got those details using a whois lookup.

This one is a bit off the subject… What do you guys think about this ? One of our users received it this morning, copying the message.

Judging by the fact that there multiple grammarical errors, the fact the user who received this message is not listed as contact on our website, nor do I know what the hell this guy talking about… Sounds like spam. oh and the fact that they are demanding 160K…

Also, usually all legal messages are sent via regular mail and the ones that are sent via e-mail usually include a disclaimer and also not sent using Mass Marketing E-mail service…


From: Graham Barr [mailto:grahambarr@democraticconventionboston.com]

Sent: Thursday, June 09,xxxxxxxxxx

To: xxxxxxxxxxxxxxxxxxxxxxxxxxxx

Subject: Cease copyright infrigement!

Dear Sir,

Attached is a list of the copyrighted material you are infriging on.

As well as hosted at http://democraticconventionboston.com/copyrights.php under Copyrighted Materials.

We are the proprietors of all copyrighted material that is being fringed upon on your companies webste.

We have reserved all rights regarding these trademarked files.

Permission was neither asked nor granted to reproduce our copyrighted material, therefore what your company is doing constitutes infringement of our rights. In terms of the Copyright Statutes, we are entitled to an injunction against your continued infringement, as well as to recover damages from you for the loss we have suffered as a result of your infringing conduct.

In the circumstances, we demand that you immediately:

  1. remove all infringing content and notify us in writing that you have done so;

  2. pay a licensing fee in the amount of 160,000 USD;

  3. immediately cease the use and distribution of copyrighted material;

We await to hear from you by.

This is written without prejudice to our rights, all of which are hereby expressly reserved.

Yours faithfully,

Senior Legal Advisor

Graham Barr

http://democraticconventionboston.com/copyrights.php

Alexander6920 wrote:

This one is a bit off the subject… What do you guys think about this ? One of our users received it this morning, copying the message.

Judging by the fact that there multiple grammarical errors, the fact the user who received this message is not listed as contact on our website, nor do I know what the hell this guy talking about… Sounds like spam. oh and the fact that they are demanding 160K…

Also, usually all legal messages are sent via regular mail and the ones that are sent via e-mail usually include a disclaimer and also not sent using Mass Marketing E-mail service…

You’re right, that looks like a scam. any legal notice would have to be in writing (not email) and chances are that you would have had someone walk up and hand deliver it.

What was the name of the attachment?

user forwarded this message to me, surprise, there were no attachments. later I also found somewhere that this specific webpage was hosting malware. I never used sucuri website scanner before, so decided to give it a shot. while the domain checked out OK by sucuri, that page copyrights.php was not listed among scanned pages… barracuda bypassed it, but message also originated from some email marketing site, I can check for the source and post back if anyone is interested.

Jason7119 wrote:

After having so many Users, Friends and Family get viruses on their computers from inadvertently clicking on these malicious websites, I proactively install WOT (Web of Trust) on all the browsers of the computers i maintain and fix. This at least helps by popping up a big warning before entering a poorly rated site. It’s saved my less savvy users plenty of times.

+1 for WoT.

Seth_the1 wrote:

Here is a link to check a specific site:

http://sitecheck.sucuri.net/scanner/

I used it when our site got infected, it showed me what was wrong, and I was able to figure out how to fix it (I am not a web admin).

That is an excellent link! Thanks!