Started By
Message
locked post

Malware embed on site

Posted on 7/14/14 at 9:07 am
Posted by CGSC Lobotomy
Member since Sep 2011
79936 posts
Posted on 7/14/14 at 9:07 am
This morning, this site attempted to install malware masquerading as a java update onto my PC. Norton caught it, but y'all should really look into it.
Posted by dallasga6
Scrap Metal Magnate...
Member since Mar 2009
25653 posts
Posted on 7/14/14 at 9:28 am to
I got the same fake pop-up last night, AVG caught mine... Can't remember which thread.
Posted by HamzooReb
Utah
Member since Mar 2013
11987 posts
Posted on 7/14/14 at 2:08 pm to
So that's why my anti-virus started blocking something last night
Posted by diddydirtyAubie
Bozeman
Member since Dec 2010
39829 posts
Posted on 7/14/14 at 3:30 pm to
My iphone gots the malware.
Posted by deeprig9
Unincorporated Ozora, Georgia
Member since Sep 2012
63825 posts
Posted on 7/14/14 at 3:48 pm to
Happened to me just now.

I was smart enough to close out the page.....


Many others probably arne't that smart.


Posted by deeprig9
Unincorporated Ozora, Georgia
Member since Sep 2012
63825 posts
Posted on 7/14/14 at 3:50 pm to
FYI, just now it wasn't a popup, it took me off this page and to a whole 'nuther page.....


Java update etc...

Posted by dallasga6
Scrap Metal Magnate...
Member since Mar 2009
25653 posts
Posted on 7/14/14 at 3:52 pm to
quote:

FYI, just now it wasn't a popup, it took me off this page and to a whole 'nuther page.....
Yup.. I got the little fake Java pop up box in the upper center, Tried to close & it went to another page & that's when my AVG closed it with a warning...
Posted by deeprig9
Unincorporated Ozora, Georgia
Member since Sep 2012
63825 posts
Posted on 7/14/14 at 3:54 pm to
quote:

Yup.. I got the little fake Java pop up box in the upper center, Tried to close & it went to another page & that's when my AVG closed it with a warning...



That box only gives you one option..... that was the red flag for me because it otherwise looked legit.

I didn't click the box, just closed the whole page.
Posted by deeprig9
Unincorporated Ozora, Georgia
Member since Sep 2012
63825 posts
Posted on 7/14/14 at 3:56 pm to
What happens when people stop logging in here from their work computers because of this stuff.... 50% traffic loss? 60%?

I've said it before and I'll say it again.


It wouldn't be that hard to have a pay-feature and block out all of the BS.

Many sites do it.... people I know do it... you don't need a corporation of finance managers to do it.. it's actually pretty simple....


Posted by Chicken
Jackassistan
Member since Aug 2003
21935 posts
Posted on 7/14/14 at 4:27 pm to
screen shots or any other info would be helpful...
Posted by InVolNerable
Member since Jan 2012
10203 posts
Posted on 7/14/14 at 4:32 pm to
quote:

deeprig9
You seem mad. Don't be mad.
Posted by deeprig9
Unincorporated Ozora, Georgia
Member since Sep 2012
63825 posts
Posted on 7/14/14 at 4:33 pm to
Yes, normally i would be able to but because it takes you off the page its too late to get a screenshot of what the culprit might be, i was on uga page when it happened if that helps, and my first post in this topic was probably 2 minutes after the incident, if that helps.

I do appreciate your attention to the matter!
Posted by CGSC Lobotomy
Member since Sep 2011
79936 posts
Posted on 7/14/14 at 5:41 pm to
quote:

screen shots or any other info would be helpful...


If you're using Chrome, it opens a separate tab. I'll try again later from my home computer (work PC zaps everything).

This happened about 30 minutes before I posted the original topic.
Posted by The Nino
Member since Jan 2010
21519 posts
Posted on 7/14/14 at 5:58 pm to
happened to me yesterday. separate tab was opened
Posted by CGSC Lobotomy
Member since Sep 2011
79936 posts
Posted on 7/14/14 at 6:20 pm to
quote:


screen shots or any other info would be helpful...



It's an exploit designed to fool the user into thinking it's a legitimate update.

The link was something to the effect of "site39.XXXX.XXXXX.javeupdate.exe"

Posted by The Nino
Member since Jan 2010
21519 posts
Posted on 7/14/14 at 6:32 pm to
for me
quote:

http//i-stone.org/entry/node/file/pkg/java/s/java_installer.exe?offer_id=13232&aff_id=20749&transaction_id=766887f1-fa30-4d78-8758-ed80f69c1e29
and
quote:

39vgame.com
This post was edited on 7/14/14 at 6:35 pm
Posted by CGSC Lobotomy
Member since Sep 2011
79936 posts
Posted on 7/14/14 at 7:06 pm to
39vgame. That's what it was.
Posted by deeprig9
Unincorporated Ozora, Georgia
Member since Sep 2012
63825 posts
Posted on 7/15/14 at 1:05 pm to
Just happened on this page.....





Screenshot attached....



Posted by betweenthebara
nowhere
Member since May 2013
6183 posts
Posted on 7/15/14 at 1:08 pm to
Chicken.
Posted by CGSC Lobotomy
Member since Sep 2011
79936 posts
Posted on 7/15/14 at 3:11 pm to
That's five different users reporting the same issue. This is now an IT/IA issue.
first pageprev pagePage 1 of 2Next pagelast page

Back to top
logoFollow SECRant for SEC Football News
Follow us on Twitter and Facebook to get the latest updates on SEC Football and Recruiting.

FacebookTwitter