Phishing/scamming by GWG notifications

AtomicMew

AtomicMew

Jungle Guide

Join Date: Apr 2005

N/A

I got this message just recently.

"Dear, trcvrs!

A virus alert was noticed on your computer.
We highly recommend you to check your computer and perform online virus check at our site immediately: http://*****.com
----------------------------------------------------
Sincerely, Forum Administration www.guildwarsguru.org. "

maxxfury

Wilds Pathfinder

Join Date: Apr 2006

[DVDF] Gp

Me/A

had the exact same message on gwo yesterday, ofc replacing who the management was :P

was from a new account with zero post count. obvious lol.

So it seems they are targeting more than one forum.

Bob Slydell

Forge Runner

Join Date: Jan 2007

That must be the database thing that was hacked a little bit back.

I also noticed, guildwarsguru[DOT]org? I didn't know .org could even work. I inspected it (since im on OS X, no windows based keyloggers, no harm to GW over on windows) It works n' shit... just...weird.

Weird in the fact that, changing it to .org reveals the same page, but with a logged off user, that dosen't make sense.

Guru, please look into this NOW. Both of these were taken at the same time, on both ".extensions" for the website. If it was the same site, it would keep Me logged on, not off.

Odinius

Odinius

Krytan Explorer

Join Date: Jun 2006

Netherlands

[OBEY]

N/R

...so that you log in with your info and they got your pass

karlik

Banned

Join Date: Sep 2009

If I ping the .com and the .org address they both come back with the same IP address.

Also whois comes back with the same basic info for both addresses.

The problem is, while the link in the actual email may appear to go to the .org address, it may actually be taking you to a totally different address. A copy/paste of the text into this forum will only show the text that was copied and not any the actual link associated in the email. I don't think I'd log in to guru at that link.

My personal guess? I think this is the result of the attack on guru - they got your email address. The real threat is the "online virus check link". That's the one that'll install a key logger and/or some other nasty.

I checked the email I used here at guru and I don't have this yet.

JR

JR

Re:tired

Join Date: Nov 2005

W/

Just to be clear, this was sent via email, not a private message on the forum?

Assuming email: It's quite possible that these are related to the recent compromise of our database. Again, I'd advise everyone to check out this guide to avoid phishing emails. I'll confer with Inde, but I'm not sure there's much we can do to prevent this happening, other than urging members to be vigilant.

What address was the email sent from?

JR

JR

Re:tired

Join Date: Nov 2005

W/

Could you please PM me the username of the person who sent the PM?

I believe they need a taste of my banhammer.

Smarty

Smarty

Krytan Explorer

Join Date: Mar 2008

England

Me/

Because the admins of guru can tell just by your browsing the forums that you have a virus on your computer! Man you guys are leet.

Faer

Faer

La-Li-Lu-Le-Lo

Join Date: Feb 2006

Quote:
Originally Posted by Smarty View Post
Because the admins of guru can tell just by your browsing the forums that you have a virus on your computer! Man you guys are leet.

To be fair, a lot of Guru users do get viruses quite often, so it'd be a safe assumption to make.

Glaed

Pre-Searing Cadet

Join Date: Jan 2010

I'm probably just paranoid, but though I should get it out there just in case it's not paranoia...

I received a private message on this board from someone saying, "Hey, I'm new here, what's up?" then had some quote and a link to a website. I checked their profile and they have never posted, but they are not new here, they have been registered since 2008.

Anyone else getting this? Or is it just a person trying to reach out? Funny thing is I'm not a regular poster, I'm more of a lurker.

tmakinen

tmakinen

Desert Nomad

Join Date: Nov 2005

www.mybearfriend.net

Servants of Fortuna [SoF]

E/

If it sounds like a phish ... in my opinion, you should contact an admin right away.

Xntryk1

Xntryk1

Pre-Searing Cadet

Join Date: Jan 2010

Ice Kold Fyre

E/

I got that message too. Nuff said. I didn't respond.

Kattar

Kattar

EXCESSIVE FLUTTERCUSSING

Join Date: Mar 2007

SMS (lolgw2placeholder)

Me/

Any time you get a message you're unsure about, forward it to the admins. One of them will take a look at it. We try to stay on top of stuff like this, but when it comes to pm's we have to rely on the affected users to give us a heads up.

Thanks.

Age

Age

Hall Hero

Join Date: Jul 2005

California Canada/BC

STG Administrator

Mo/

Yeah.I got phishy.

Age

Age

Hall Hero

Join Date: Jul 2005

California Canada/BC

STG Administrator

Mo/

No.I got in the form of an e-mail not a pm.