Page 1 of 3

Malicious Redirect / Fake Flash update

Posted: Wed Aug 31, 2016 8:27 am
by WhitneyReed
When playing the daily for the first time today, after clicking the check box and before selecting a game variant I was automatically redirected to what *looked* like the Flash update page, but was actually from domain daetepurpleport.org and automatically tried to download a file from that site. Unfortunately I don't know what triggered it, whether if it was from the video or a banner ad.

(edited to add:)

I don't know if this will help, but these are the redirects that immediately preceded the malicious page:


http://gslbeacon.lijit.com/beacon?viewI ... 2214&v=1.2

http://gslbeacon.lijit.com/beacon?viewI ... 2214&v=1.2


This is the actual page:

https://daetepurpleport.org/45318161414 ... 50915.html

Re: Malicious Redirect / Fake Flash update

Posted: Wed Aug 31, 2016 8:59 am
by Webman
Thanks for the info. We will pass this along to our ad networks so they can remove whichever ad is causing this. Good job looking at the URL instead of trusting the page. Only download updates for your computer or plugins directly through the manufacturer, not from popups or web redirects.


Re: Malicious Redirect / Fake Flash update

Posted: Mon Oct 17, 2016 8:09 am
by WhitneyReed
Unfortunately this has been popping up again the last few days (about four times now). This morning while playing the daily I was about to spin the bronze wheel when it popped up, throwing me out of the game and losing my spin. Unfortunately I don't have any way of knowing what ad is triggering it. The page that's coming up now is:

https://eishirecyclart.net/122181614142 ... 3cce4.html

Re: Malicious Redirect / Fake Flash update

Posted: Mon Oct 17, 2016 8:11 am
by Webman
Yuck. What web browser are you using?


Re: Malicious Redirect / Fake Flash update

Posted: Mon Oct 17, 2016 8:17 am
by WhitneyReed
Yuck. What web browser are you using?



I'm using the the latest IE 11 on windows 10

Re: Malicious Redirect / Fake Flash update

Posted: Thu Oct 20, 2016 8:11 am
by WhitneyReed
Happened again today, this time in the middle of the weekly. This time it was a different host:

https://poojogaspadine.net/828181614142 ... c7193.html

If there's anything I can do, let me know!

Re: Malicious Redirect / Fake Flash update

Posted: Fri Oct 21, 2016 3:27 pm
by Webman
Let me know if this happens again. I think a recent change will help.

Re: Malicious Redirect / Fake Flash update

Posted: Sun Oct 23, 2016 11:08 pm
by Kap L
As I also replied to the other post about malicious site, the same thing happened to me several times this evening, on both the daily and the weekly. It's also happened a few other times this week. I'm using Safari on a Mac.

Re: Malicious Redirect / Fake Flash update

Posted: Mon Oct 24, 2016 1:14 pm
by Tedlark
I must be living under a lucky star, I dont seem to have these issues when I play here on this site.

Re: Malicious Redirect / Fake Flash update

Posted: Tue Nov 01, 2016 8:02 am
by WhitneyReed
Unfortunately I just had another incident during the monthly today. I was playing on Chrome this time and McAfee caught the redirect, but I was knocked out of the game. McAfee brought up a warning screen and I didn't click to accept the site so I don't know if it was another flash thing or not. Here is the URL, I hope it helps:

http://engine.spotsce​nered.info/Redi ... d=3​0262


[Edit:]

Just happened a second time. This is what history shows:

https://dnshost.me/in/0174615323602/?ads=wy0z4b6cj8