Author Topic: can you believe this phishing  (Read 7281 times)

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
can you believe this phishing
« on: February 01, 2019, 12:08:22 PM »
Its really a wild one, came in on a weather website my husband was looking at on his new iMac.

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Re: can you believe this phishing
« Reply #1 on: February 01, 2019, 12:20:32 PM »
Amazing amounts of computations to arrive at those numbers! And all at no "cost" to the user! Yeah, right...  :wallbash: :laughhard:
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Highmac

  • Administrator
  • TS Addict
  • *****
  • Posts: 5455
    • View Profile
Re: can you believe this phishing
« Reply #2 on: February 02, 2019, 09:37:12 AM »
I just opened up the MBP, logged in and that same message was on my screen. I had both Firefox and Safari running but that scam window was on top of a Safari page (BBC iPlayer website) - and looked just like the one Jane got. I just shut down the spoof window (red button) and quit and relaunched Safari. There's no (edit - obvious!) sign of it in the history of either browser.

Not surprisingly, all the numbers on it were identical to Jane's  :doh:
Neil
MacMini (2018) OS10.14.6 (Mojave). Monitor: LG 27in 4K Ultra HD LED.
15in MacBook Pro (Mid 2014) OS10.13.4 (High Sierra);
15in MacBook Pro (2010), (ex-Snow Leopard); now OS10.13.6 (High Sierra); 500GB Solid-State SATA drive; 4GB memory.

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
Re: can you believe this phishing
« Reply #3 on: February 02, 2019, 09:55:59 AM »
I did the same, got rid of that window, quit Safari, and restarted it. Nothing today.
Wonder if anybody actually did click on that thing?
Sure hope nobody.

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Re: can you believe this phishing
« Reply #4 on: February 02, 2019, 10:31:38 AM »
I'm not sure it's coming from Safari in particular. I suspect Flash. If you ever see it again, Quit Safari before closing the window to see if Safari was even involved.
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline Highmac

  • Administrator
  • TS Addict
  • *****
  • Posts: 5455
    • View Profile
Re: can you believe this phishing
« Reply #5 on: February 03, 2019, 07:37:49 AM »
Took another look at Jane’s screen grab and noticed the url at the top. It starts:

Quote
“mac-safety-check.com.hefjzkeo…” (lots more letters), then “index.php?browser=Safari&zo=US&app…”;
the rest cannot be seen.

So it seems likely that Safari has been hijacked/involved but I’d appreciate Jim’s views.

Just wish I’d stopped long enough to read the whole url on the one that popped up for me.

FYI: Safari 12.0.2, mid-2014 MBP Retina; High Sierra.
Neil
MacMini (2018) OS10.14.6 (Mojave). Monitor: LG 27in 4K Ultra HD LED.
15in MacBook Pro (Mid 2014) OS10.13.4 (High Sierra);
15in MacBook Pro (2010), (ex-Snow Leopard); now OS10.13.6 (High Sierra); 500GB Solid-State SATA drive; 4GB memory.

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
Re: can you believe this phishing
« Reply #6 on: February 03, 2019, 07:44:25 AM »
I wish I had saved the rest of it in a screenshot, did look at it and it was very long.
Nothing like this has shown up either before or after.
Its my husband's new iMac, and it and Safari are running perfectly.
And nothing like this has shown up on any of our other Macs.

Very interesting, looking forward to you all figuring this out.

Offline jchuzi

  • TS Addict
  • *****
  • Posts: 3094
    • View Profile
Re: can you believe this phishing
« Reply #7 on: February 03, 2019, 08:28:45 AM »
Go to System Preferences > Security & Privacy > Firewall and check your settings, including Firewall Options. You'll have to click the lock and enter your administrator password to unlock the Options button.
Jon

macOS 11.7.10, iMac Retina 5K 27-inch, late 2014, 3.5 GHz Intel Core i5, 1 TB fusion drive, 16 GB RAM, Epson SureColor P700, Photoshop CC, Lightroom CC, MS Office 365

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
Re: can you believe this phishing
« Reply #8 on: February 03, 2019, 08:38:38 AM »
I looked at this on my iMac, I dont have an admin password, so even tho I click the lock, I cant change anything on this one.
But Safari on his Mac is not listed in location services. Mine is, but never saw anything similar to this 'thing'.

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
Re: can you believe this phishing
« Reply #9 on: February 03, 2019, 04:17:24 PM »
My husband got another one, and I think I got the entire URL. I used a screenshot.
He went to the same weather site, its not appeared on any other site.

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Re: can you believe this phishing
« Reply #10 on: February 03, 2019, 05:27:42 PM »
Quote
He went to the same weather site, its not appeared on any other site.
Ah! So it is only showing when you visit the 'hacked' site? As I was once told when I smashed my thumb with a hammer... "Don't do that!" :nono: :wallbash:  :coolio: :doh:
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
Re: can you believe this phishing
« Reply #11 on: February 03, 2019, 06:48:31 PM »
Did not visit it, just took a screen capture when I highlighted the URL, and quit Safari. Did not click on anything.

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
Re: can you believe this phishing
« Reply #12 on: February 03, 2019, 07:07:51 PM »
I will post the screen capture here tomorrow if you want to see the entire thing.

Offline jcarter

  • TS Addict
  • *****
  • Posts: 5808
    • View Profile
    • http://www.jcarter.net/ourdogs/muffinpage.html
Re: can you believe this phishing
« Reply #13 on: February 04, 2019, 11:42:21 AM »
Here it is. Its a long one for sure.

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Re: can you believe this phishing
« Reply #14 on: February 04, 2019, 05:44:19 PM »
Only thing that looks interesting is the name of a dubious app called Mac Cleanup Pro (just after the "Safari&zo=US&" text. Every place you see "&" is usually a separator for a new piece of data. "%20" is the ASCII code for a space, which is not usable in most urls. Do a search for that name and you'll find all sorts of hits.

The normal way of getting this disgusting junkware is by visiting sites for free apps and fake updates. Several things you can do to see if you actually have the junkware installed:
  • See if there is an extension with parts of that name in Safari Prefs
  • Check you home/Library/LaunchAgents for any file with those three words.
  • Also check your ~/Library/Application Support directory
  • Obviously you can also look in your Applications folder
What you should never do is pay/buy/download any app named "Mac Cleanup Pro"! :doh: And, of course, practice "Safe Surfing"! :doh: Update only from Apple's Software Update and from trusted third-party dev sites. I don't recommend auto-updating any app or OS. :wallbash: Of course, you should also have an Admin password for your computer... :coolio:
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes: