An open community 
of Macintosh users,
for Macintosh users.

FineTunedMac Dashboard widget now available! Download Here

Previous Thread
Next Thread
Print Thread
Website tried to download then this happened
#42162 10/16/16 03:39 PM
Joined: Aug 2009
OP Offline

Joined: Aug 2009
On a KNITTING website, of all places.

A pop up allegedly from Adobe Flash, tried to download an update. I declined the request. As I watched, up came a screen telling me where to put the "download". Then a "warning" from "Apple" that this Mac has been infected and I should phone a number.

Firefox history shows the trail: this one shows against "Official Apple Support"

http://systemuseasurement.club/........www.knittingpatterncentral.com

Shall I tell Knitting Pattern Central that their site contains potentially malicious bugs, or not bother?

There was no download, in case you're wondering. Either I stopped it or it was a scare tactic.


Re: Website tried to download then this happened
Bensheim #42163 10/16/16 06:05 PM
Joined: Aug 2009
Offline

Joined: Aug 2009
Originally Posted By: Bensheim
... Shall I tell Knitting Pattern Central that their site contains potentially malicious bugs ... ? ...


Yes


MacStudio M1max - 14.4.1, 64 GB Ram, 4TB SSD; Studio Display; iPhone 13mini; Watch 9; iPadPro (M2) 11" WiFi
Re: Website tried to download then this happened
pbGuy #42187 10/17/16 03:38 PM
Joined: Aug 2009
OP Offline

Joined: Aug 2009
The email address provided under Contact Us on their website does not exist. My attempt to warn them bounced back.

So much for trying to help people. confused

Re: Website tried to download then this happened
Bensheim #42189 10/17/16 04:11 PM
Joined: Aug 2009
Likes: 16
Moderator
Online
Moderator

Joined: Aug 2009
Likes: 16
Your link is a redirect from another site and any malware such as you encountered may have come from any place along the reference chain and not necessarily from Knitting Pattern Central. But since my wife is a former knitter out of curiosity I Googled Knitting Pattern Central and had no problems browsing their site and encountered no malware or warnings. However, when I went to their Contact Me page I found the following notice...
Originally Posted By: Kintting Pattern Central Contact Me
Please do not write using a sbcglobal.net, att.net, earthlink.net, hotmail.com, or live.com email address. All of these email providers will currently not allow my replies through. If you have an alternate gmail.com or yahoo.com email address (etc) please use it instead. Thank you!!

The only reason I can think of that might cause sbcglobal, att, earthlink, etc. to block an email address is because it has been associated with spam or malware. The event triggering the block may, or may not, have happened with the knowledge and consent of the site owner/operator or it could have been a relatively innocent mistake such as sending an email to too many addressees (that can result in a site being blocked as a suspected spammer), but it would make me suspicious and wary of anything downloaded from such a site. ☹️


If we knew what it was we were doing, it wouldn't be called research, would it?

— Albert Einstein
Re: Website tried to download then this happened
Bensheim #42255 10/24/16 02:36 PM
Joined: Aug 2009
Offline

Joined: Aug 2009
Originally Posted By: Bensheim
The email address provided under Contact Us on their website does not exist. My attempt to warn them bounced back.

So much for trying to help people. confused

That's not an accident. The professional fraudsters go through their list of bot-harvested vulnerable websites and try to contact the owners by any of the usual means. If they can, they pass. They'll only spend time hacking and infecting a website that's going to stay under their control for awhile, due to helpful people like you being unable to contact the owners to fix their broken crap page.


I work for the Department of Redundancy Department
Re: Website tried to download then this happened
Bensheim #42271 10/24/16 06:43 PM
Joined: Aug 2009
Likes: 1
Offline

Joined: Aug 2009
Likes: 1
It looks to me like the popup you saw was not a compromise of Knitting Pattern Central. Instead, that site uses a third party ad network, and the ad network allowed a poisoned ad through.

The Contact page lists a gmail address, but the Privacy Policy page lists another address: contact (at) knittingpatterncentral (dot) com


Photo gallery, all about me, and more: www.xeromag.com/franklin.html

Moderated by  alternaut, dianne, MacManiac 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.4
(Release build 20200307)
Responsive Width:

PHP: 7.4.33 Page Time: 0.433s Queries: 26 (0.017s) Memory: 0.5940 MB (Peak: 0.6666 MB) Data Comp: Zlib Server Time: 2024-04-19 22:02:09 UTC
Valid HTML 5 and Valid CSS