Avast WEBforum

Other => General Topics => Topic started by: corxfinance on November 13, 2019, 03:57:09 PM

Title: Help on suspicious link
Post by: corxfinance on November 13, 2019, 03:57:09 PM
Hi

My wife today decided to click on a link (invoice) before I had to chance to stop her. This was on her android phone. The link was

//21hospitality.cmail19.com/t/i-l-purittk-ckilduus-r/

I have used some checkers like urlvoid.com etc & they validate the 21hospitality.cmail19.com as OK. However, my concern are the additional switches after the .com. Could these be used for a key logger etc to access the home network & do real damage from there having deployed something on the phone.

I installed after the event Avast as well malwatebytes and Zemana and have scanned with no issues found. I have changed email passwords and some other accounts.

Just me being twitchy - hopefully

Brian
Title: Re: Help on suspicious link
Post by: Michael (alan1998) on November 13, 2019, 04:25:27 PM
Hi Brian<

I'll get back to you in a moment with scan results - but can you please disable the link (edit your post and change the HTTP to hxxp)
Title: Re: Help on suspicious link
Post by: corxfinance on November 13, 2019, 04:31:32 PM
Hi

I have removed the link.

Please note when I said installed after the event, I mean't the android phone. I have Avast and Malwarebytes deployed on my pc along with all the usual privacy and protection options neabled.
Title: Re: Help on suspicious link
Post by: Michael (alan1998) on November 13, 2019, 04:34:40 PM
https://checkphish.ai/insights/url/1573658884311/3990e9a8da31fec3dcf8bbc4a5c250fb62e03f905d4828167bfeba08535d3a37

Removed?? >> https://rm-prod-screenshots.storage.googleapis.com/images/20191113/3990e9a8da31fec3dcf8bbc4a5c250fb62e03f905d4828167bfeba08535d3a37.png

APWG >> http://phish-education.apwg.org/r/en/index.htm
https://www.google.com/search?q=apwg&rlz=1C1CHBF_enCA866CA866&oq=apwg&aqs=chrome..69i57j0l5.622j0j7&sourceid=chrome&ie=UTF-8

Looks similar to the Anti-phishing systems we employ here at my position (we use a different company). I'd say she's fine.
Title: Re: Help on suspicious link
Post by: corxfinance on November 13, 2019, 04:39:08 PM
Much appreciated Michael