Author Topic: Rogue AV Using Malware Domains List  (Read 3992 times)

0 Members and 1 Guest are viewing this topic.

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054

YoKenny

  • Guest
Re: Rogue AV Using Malware Domains List
« Reply #1 on: August 03, 2009, 10:31:43 AM »
Also:
WARNING: Malware Domain List has a new impersonator
http://hphosts.blogspot.com/2009/08/warning-malware-domain-list-has-new.html

Alan Baxter

  • Guest
Re: Rogue AV Using Malware Domains List
« Reply #2 on: August 03, 2009, 02:57:32 PM »
The rogue site is gone now, but the screenshots of it demonstrate a reasonably effective social engineering page.  The clumsy English grammar might have been a giveaway to a careful reading by a fluent English reader, but perhaps not noticeable to many people.  It looks so similar to the Firefox warning page that I had to examine it carefully before I realized it was bogus.

I'll keep telling my friends that don't know any better yet, "Don't accept any software installation offered to you by a website unless you asked for it."  And I've given up typing urls in the address bar.  A simple typing error could take me to a rogue site.  I only use bookmarks and search engines now.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Rogue AV Using Malware Domains List
« Reply #3 on: August 03, 2009, 04:36:47 PM »
<snip>
I'll keep telling my friends that don't know any better yet, "Don't accept any software installation offered to you by a website unless you asked for it."  And I've given up typing urls in the address bar.  A simple typing error could take me to a rogue site.  I only use bookmarks and search engines now.

Clicking on search engine results links opens you up to another means of attack, where search results have malformed URLs I believe, etc. so they have you over a barrel don't type the URL and risk possible exploit ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Alan Baxter

  • Guest
Re: Rogue AV Using Malware Domains List
« Reply #4 on: August 03, 2009, 04:43:26 PM »
Good point, David.  But I'll still take the first hit from "State of Colorado" over guessing what its url should be or relying on not misremembering or making a typo in the url bar.  It's good practice to actually look at the urls your search engine serves up.

That said, bookmarks are safer.  8)

Mr.Agent

  • Guest
Re: Rogue AV Using Malware Domains List
« Reply #5 on: August 03, 2009, 04:43:49 PM »
Well its a bad idea for them to put it in the web so maybe some guy will press on it and be infected...