Author Topic: Fake Google Chrome update  (Read 6912 times)

0 Members and 1 Guest are viewing this topic.

Offline TheOwner

  • Poster
  • *
  • Posts: 406
Fake Google Chrome update
« on: April 19, 2017, 04:25:24 PM »
Chrome need to be updated. I was redircted to this phishing site after i visited \www.mywot.com\ (safe site by self). Automaticaly start downloading some dangerous file, but chrome detected it and ask me if i want accept ithis file, because is dangerous. So i declined this. Even if i download this file and don't run it, i am stil safe? It cannot be executed by self? Anyway, is there any reason why Avast don't detect this phishing site? And also don't detected this dangerous file which start downloads? I don't  have any screenshot or link, I was too scared so i closed browser immediately. Thank you
« Last Edit: April 19, 2017, 04:29:21 PM by TheOwner »

Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: Fake Google Chrome update
« Reply #1 on: April 19, 2017, 04:28:45 PM »
Mywot site scan, it is this? Look screenshot.
« Last Edit: April 19, 2017, 04:34:45 PM by TheOwner »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: Fake Google Chrome update
« Reply #2 on: April 19, 2017, 04:38:24 PM »
are you able to copy the redirect URL and scan it at?   www.virustotal.com

Post link to scan result here


Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: Fake Google Chrome update
« Reply #3 on: April 19, 2017, 04:44:08 PM »
I am not sure if this link is connected with this redirect or not, but you can chcek by self. Copied from Quttera. htXXps://lh6.googleusercontent.com/pvrwwt3pafvbu-88w-tfp80xutpd7xlmzm_ffpsdwxu87qdf7gjy-a62-u_e_l-69tlbo-gq=s26-h26-e365

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: Fake Google Chrome update
« Reply #4 on: April 19, 2017, 04:47:06 PM »

Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: Fake Google Chrome update
« Reply #5 on: April 19, 2017, 04:49:55 PM »
Thank you, but i still don't understand this automatic redirect from this site to phishing site and no detection from Avast. I cannot tell you if this URL is from this phishing site or not.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: Fake Google Chrome update
« Reply #6 on: April 19, 2017, 04:51:35 PM »
urlQuery > http://urlquery.net/report.php?id=1492612528937
404 error > click picture at top right to see


Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: Fake Google Chrome update
« Reply #7 on: April 19, 2017, 04:56:20 PM »
That phis site looks different, so it was another URL. There is no way search it again. It looks like standard google chrome download page but with very strange url.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: Fake Google Chrome update
« Reply #8 on: April 19, 2017, 04:58:55 PM »
This one is listed at PhishTank ... but not the exact same

Code: [Select]
https://lh6.googleusercontent.com/-kXknkrcXcpE/VOn4DqJWHCI/AAAAAAAAAK4/trPZRy5aLJM/s284/GUARDIAO-ITAU-30-HORAS.png"
PhishTank > http://www.phishtank.com/phish_detail.php?phish_id=4599499


Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: Fake Google Chrome update
« Reply #9 on: April 19, 2017, 05:01:57 PM »
Yes phishing, the same Quttera, maybe is some truth about it. A reproted this URL to Avast, let's  see what they analize.

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Fake Google Chrome update
« Reply #10 on: April 19, 2017, 05:55:33 PM »
Be careful of sites claiming to update your chrome.This is the most common way to spread Locky ransomware.

Also I would like to add that most of these locky distributing websites are .top not .com or anything else.   :)




Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: Fake Google Chrome update
« Reply #11 on: April 19, 2017, 06:03:46 PM »
I know that it is fake.... but is here any danger if i just delete downloaded file? Or it can be executed without my action? Locky is known, is already in virus database i think.
« Last Edit: April 19, 2017, 06:10:36 PM by TheOwner »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: Fake Google Chrome update
« Reply #12 on: April 19, 2017, 08:16:44 PM »
Quote
Locky is known, is already in virus database i think.
Yes / No / Maybe

Malware is not static, they update / change and release new versions to avoid detection, just like car manufacturers do to make you buy the new latest edition,  face lift / new engine / new gadgets   ;)





Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: Fake Google Chrome update
« Reply #13 on: April 20, 2017, 05:16:29 AM »
Locky is usually well detected by avast cloud and evo-gen but it is a must to be on the lookout for something like this.

Even if it bypasses avast the behaviour shield can identify it and alert the user.  :)

Offline TheOwner

  • Poster
  • *
  • Posts: 406
Re: Fake Google Chrome update
« Reply #14 on: April 20, 2017, 04:01:28 PM »
Is there any way how block page redirecting? I hate if i enter on some safe site and i am immediately redirected to some malware site.