Malware in Uploaded Images in Threads on the Hype

Midnyte_Sun

Medianoche de Sol
Joined
Mar 13, 2006
Messages
5,668
Reaction score
1
Points
58
I've noticed an increase in malware threats blocked from visiting pages in the Hype. It doesn't happen to my knowledge, in the main home page, but in the boards specifically threads that may use uploaded images.

On this page, there is only one uploaded image, and I believe the image has malware uploaded through it also:

Warning: Don't Click if you don't have Malware blockers installed:

http://forums.superherohype.com/showthread.php?p=19632962#post19632962

It seems to be linked to uploaded images using:

h.ttp://shareimage.ro

Looks like the Malware it wanted to run was "Palladium" Anti - Virus, which is a malware disguised as an anti virus. More info about it can be found here:

http://www.precisesecurity.com/rogue/palladium-antivirus/
 
Last edited:
Here's another image/file uploader that has Malware attached to it:

h.ttp://mkserver.ru

( I put an extra period to it to make the link invalid)
 
Um, what is the thread it's in? I'm not clicking the link, but would also like to avoid that thread all together.
 
also if you are getting any weird popups or anything like that, please screen cap them.
 
Um, what is the thread it's in? I'm not clicking the link, but would also like to avoid that thread all together.

Both those image uploader sites were used in the same thread on the new Mortal Kombat game in the Game Section, titled:

Mortal Kombat XI returns to its bloody roots - Part 1

Comic Chic,

The window basically says that WIndows has detected a trojan virus and that you should install Palladium Anti Virus. The only problem is, if you decline, it installs anyways because it won't let you get out of that window. Once it installs, it will restart your PC and it won't let you access your desktop until you buy their product (which is not a real anti virus).
 
Last edited:
ill let the techies know
 
Comic Chick,

The window looks like this:

palladiumpopup2.jpg


MalwareBytes picked this info up:

69883666.jpg
 
Last edited:
Any updates on the viruses via image hosting servers?
 
I think it's just you, no other complaints
 
happened to me a week ago tryin to open a pic uploaded...cant remember the thread though
 
I think it's just you, no other complaints

You're joking right? Ad servers and image hosting servers have been targeted by hackers in order get their malware into people's PCs. Even Google Images is infected.

Besides, since when has image hosting sites from Romania and Russia (like the ones used in that thread I mentioned) been known for their 'security' and 'safety?'
 
Last edited:
i've seen odd things coming from ImageShack of late
 
So, so far the culprits are:

imageshack.us
shareimage.ro
mkserver.ru

Have any of you used Picoodle?
 
This came out a while back, but it's more reason to have protection against malware:

Malware delivered by Yahoo, Fox, Google ads

Found in ads delivered from those networks was JavaScript code that Avast dubbed "JS:Prontexi," which Avast researcher Jiri Sejtko said is a Trojan in script form that targets the Windows operating system. It looks for vulnerabilities in Adobe Reader and Acrobat, Java, QuickTime, and Flash and launches fake antivirus warnings, Sejtko said.

Read more: http://news.cnet.com/8301-27080_3-20000898-245.html#ixzz1F5dNr1cS
 
Now all you need to do is create an FTP account, and then login to the account using your browser by using this format.



______________________

Oh shut up bot
 
I just got an unauthorized attempt to download an 'app' via my Android 2.2 while browsing through images on the "What Hypesters Look Like" thread.
 
I dont know about images I just tried to hit the games forum and got a window of possible infection. I'm running all kinds of scans now.
 
It looks for vulnerabilities in Adobe Reader and Acrobat, Java, QuickTime, and Flash and launches fake antivirus warnings, Sejtko said.

I just got one of those in the Family Guy thread. I remember last year we were having issues with the same exact problem. A few people were complaining about it.
 
Thid thread. Should be merged with the other one about malware.
 
Just got another trojan attack while browsing through the Hype. I was on the thread:

Darthphere's House of Style: From Geek to Chic. when I got this warning:

unledvy.jpg
 
Are we supposed to PM the Hype Administrator? I wish it were more clear how we're supposed to take action.
 
by posting in this thread and supplying as much backup info (details, screencaps, threads seen in, etc), the staff can give more info to the site owner who can then relay to those who can fix these problems
 
by posting in this thread and supplying as much backup info (details, screencaps, threads seen in, etc), the staff can give more info to the site owner who can then relay to those who can fix these problems
Gotcha. :up:
 

Users who are viewing this thread

Latest posts

Forum statistics

Threads
201,140
Messages
21,906,572
Members
45,703
Latest member
Weird
Back
Top
monitoring_string = "afb8e5d7348ab9e99f73cba908f10802"