Help Forum How To | General Corvetteforum Questions | Feedback

Malware attacks through the Forum: veryield-malyst(.)com

Thread Tools
 
Search this Thread
 
Old Feb 5, 2019 | 01:37 PM
  #1  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,723
Likes: 1
From: Redacted
Default Malware attacks through the Forum: veryield-malyst(.)com

Getting multiple hits from my router blocking connections to a pretty nasty malware distributor, veryield-malyst.com, via Corvette Forum's advertising links.

This site distributes a very nasty bit of malware consisting of an "image" with the URL of a malware site, coupled with a javascript that decodes it from the image itself and re-directs the browser.

https://arstechnica.com/information-...hed-in-images/

It seems to be deep-linked somehow. Had to disable JS in the developer console of Safari to even be able to load enough of the Corvette Forum to post this message.

Thought you guys might want to know about it.
Old Feb 5, 2019 | 02:39 PM
  #2  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

Do you have an exact example to provide?

That site is automatically blocked for me but I see no attempts coming from CorvetteForum.
Old Feb 5, 2019 | 04:48 PM
  #3  
6T7L71CPE's Avatar
6T7L71CPE
Melting Slicks
20 Year Member
Veteran: Air Force
Liked
Community Favorite
 
Joined: Apr 2003
Posts: 2,825
Likes: 486
From: Florida
Default

I'm getting it too.

veryield-malyst.com/c95880a9-5844-4e93-aae4-ef6873648b8a?var1=dd451f9c2cac
Old Feb 5, 2019 | 05:17 PM
  #4  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

Our team is investigating but, as stated above, we need more details. If you're seeing a specific ad (which I believe is the only way this can come through), please let us know. Not everyone sees the same thing, which might be why I've not seen this logged myself.
Old Feb 5, 2019 | 05:18 PM
  #5  
dmaxx3500's Avatar
dmaxx3500
Team Owner
15 Year Member
Liked
Loved
Community Favorite
 
Joined: Jan 2008
Posts: 30,894
Likes: 1,189
From: chicago
Default

CF has been slow to load and stopped working 5-10 times in the last 2+ weeks
Old Feb 5, 2019 | 05:54 PM
  #6  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,723
Likes: 1
From: Redacted
Default

Have no way to tell as I’m not clicking ads.

I simply open a page on CF scroll a little and it gets the malware redirect.

No clicking on my part. It seems to be coming through as ads load and rotate.

I haven’t been able to get any breadcrumbs out of the browser or the web inspector console either. I’m in software engineering, but in high performance computing. Not as experienced in web development.

They seem to sneaking it in as payload through the normal advertiser channels.

Old Feb 5, 2019 | 08:16 PM
  #7  
jackthelad's Avatar
jackthelad
Melting Slicks
10 Year Member
 
Joined: Jun 2013
Posts: 3,473
Likes: 691
From: West Virginia
Default

Originally Posted by larrysb
Have no way to tell as I’m not clicking ads.

I simply open a page on CF scroll a little and it gets the malware redirect.

No clicking on my part. It seems to be coming through as ads load and rotate.

I haven’t been able to get any breadcrumbs out of the browser or the web inspector console either. I’m in software engineering, but in high performance computing. Not as experienced in web development.

They seem to sneaking it in as payload through the normal advertiser channels.

That's my take on the fake Mac "Upgrade Flash Player" popups as well. No response to my thread on that topic. Anyone actually have a Mac to see what's happening?
Old Feb 5, 2019 | 08:34 PM
  #8  
HooosierDaddy's Avatar
HooosierDaddy
Melting Slicks
 
Joined: Jul 2018
Posts: 2,758
Likes: 668
From: Fort Wayne, IN
Default

Originally Posted by jackthelad
That's my take on the fake Mac "Upgrade Flash Player" popups as well. No response to my thread on that topic. Anyone actually have a Mac to see what's happening?
I had this today, first time I've seen it. Downloaded a file by itself, but did not mount the disk (install). A quick search shows this is a real problem lately, not only on CF.

here is the link it took me to. I deleted the dmg file it downloaded, sorry I can't share that.
Originally Posted by ***DO NOT*** Click this link, it is malware!

Last edited by HooosierDaddy; Feb 6, 2019 at 02:50 PM.
Corvette Stories

The Best of Corvette for Corvette Enthusiasts

story-0

10 Ugly Corvettes That We Still Kinda Love

 Joe Kucinski
story-1

Top 10 Most Expensive Corvettes Ever Sold on Bring A Trailer

 Brett Foote
story-2

10 Things Every Corvette Owner Needs (2026 Edition)

 Michael S. Palmer
story-3

8 Most "Only Corvette Owners Understand" Quirks and Problems

 Pouria Savadkouei
story-4

10 Reasons the C6 Z06 is Still A Performance Benchmark After 20 Years

 Joe Kucinski
story-5

How Much Horsepower Every Corvette Engine "LOST" in 1972

 Joe Kucinski
story-6

Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

 Michael S. Palmer
story-7

Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

 Joe Kucinski
story-8

150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

 Joe Kucinski
story-9

8 Coolest Corvette Pace Cars (and Replicas) of All Time

 Verdad Gallardo
Old Feb 6, 2019 | 01:49 AM
  #9  
Choreo's Avatar
Choreo
Le Mans Master
Supporting Lifetime
20 Year Member
Loved
Community Favorite
Top Answer: 1
 
Joined: May 2006
Posts: 6,774
Likes: 363
From: Midland TX
Default

Getting same fake Flash Player download message? Can't use site.
Old Feb 6, 2019 | 01:08 PM
  #10  
Stevedore's Avatar
Stevedore
Le Mans Master
St. Jude 10 Year Donor
25 Year Member
Active Streak: 30 Days
Active Streak: 90 Days
 
Joined: Jun 2000
Posts: 6,904
Likes: 6
From: Long Valley NJ
St. Jude Donor '03-'05-'06-'07-'08,'11 thru '17, '21
Default

I've been getting this when I start to scroll through a CF thread on my Mac. Started yesterday.

Last edited by Stevedore; Feb 6, 2019 at 01:09 PM.
Old Feb 6, 2019 | 02:49 PM
  #11  
larrysb's Avatar
larrysb
Thread Starter
Race Director
20 Year Member
Active Streak: 30 Days
Community Builder
Community Influencer
 
Joined: Aug 2002
Posts: 16,723
Likes: 1
From: Redacted
Default

I got several re-directs to the same malware URL this morning. It is getting loaded on a timed basis, about 10 seconds or so, from loading the initial page.

I think it is coming through the rolling ad space at either the top of bottom of the CF pages.

I have logs and HAR files from Safari, if anyone is interested.

It looks like the script is likely reading an image, decoding the malware URL using JS and doing a javascipt eval on it. All designed to circumvent security by coming through the regular ad delivery network.

It really sucks, makes the forum unusable at times. I have set the host name to 0.0.0.0 in my hosts file, so it never connects to the fake flash update site. However, the uncommanded re-directs take the browser off the page over and over.
Old Feb 7, 2019 | 08:18 AM
  #12  
R66's Avatar
R66
Le Mans Master
Liked
Loved
Community Favorite
Top Answer: 1
 
Joined: Nov 2015
Posts: 7,470
Likes: 2,646
From: Really Central IL Illinois
Default

I have been fighting it for a while now. The pop-up locks up SAFARI and when not locked, everything is extremely slow (timing wheel). The URL seems to have changed from the first time it locked me up here on the forum using SAFARI. It has occurred on the Camaro Forum and when using Outlook on this APPLE machine. I have a Windows 10 unit that has not experienced the problem, however, the virus program on the Windows 10 machine has isolated a trojan that it says cannot be deleted from that machine. Don't know if it is the same trojan as it does not list any specific trojan.

https://flash-playerupdate.icu/C8Nae...RTARVJ1HUJMI0G

https://flash-playerupdate.icu/C8Nae...RTARVJ1HUJMI0G

flash-playerudate.icu - shows as currently open website in Safari - why?? Flash player is not installed on my MAC.

https://www2.yoursbestonlineflashlit...PxwWHWUZn4XlOk

I have found that if I block all COOKIES, it helps, but doesn't resolve the problems.

Ron

Last edited by R66; Feb 7, 2019 at 08:20 AM.
Old Feb 7, 2019 | 10:10 AM
  #13  
R66's Avatar
R66
Le Mans Master
Liked
Loved
Community Favorite
Top Answer: 1
 
Joined: Nov 2015
Posts: 7,470
Likes: 2,646
From: Really Central IL Illinois
Default

Here is a link to the ADOBE COMMUNITY and what is recommended for this Virus:

https://forums.adobe.com/thread/2477746

Not being computer literate, it scares me to wipe out the hard drive and start again.

Ron
Old Feb 7, 2019 | 07:42 PM
  #14  
Hib Halverson's Avatar
Hib Halverson
Pro Mechanic
Pro Mechanic
25 Year Member
Photogenic
Photoriffic
 
Joined: Oct 1999
Posts: 3,922
Likes: 1,468
From: South-Central Coast California
Default

I was having this problem but it stopped yesterday.
Old Feb 7, 2019 | 07:48 PM
  #15  
jackthelad's Avatar
jackthelad
Melting Slicks
10 Year Member
 
Joined: Jun 2013
Posts: 3,473
Likes: 691
From: West Virginia
Default

See my pos re Spam. Turning off javascript fixes things.
Old Feb 7, 2019 | 07:51 PM
  #16  
J T's Avatar
J T
IB Staff
15 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Feb 2009
Posts: 10,579
Likes: 4
Default

Originally Posted by Hib Halverson
I was having this problem but it stopped yesterday.
The team have been working on the issue when it was discovered.

Originally Posted by jackthelad
See my pos re Spam. Turning off javascript fixes things.
That probably does work. The problem is it will break certain functions. Javascript is still fairly widely used on websites.

Get notified of new replies

To Malware attacks through the Forum: veryield-malyst(.)com





All times are GMT -4. The time now is 12:30 PM.

story-0
10 Ugly Corvettes That We Still Kinda Love

Slideshow: 10 ugly Corvettes that we still kinda love.

By Joe Kucinski | 2026-06-03 10:34:17


VIEW MORE
story-1
Top 10 Most Expensive Corvettes Ever Sold on Bring A Trailer

A lot of money has changed hands at the online auction house over the years.

By Brett Foote | 2026-06-03 10:21:50


VIEW MORE
story-2
10 Things Every Corvette Owner Needs (2026 Edition)

Slideshow: 10 great gifts Corvette enthusiasts actually want for Father's Day!

By Michael S. Palmer | 2026-06-03 15:43:40


VIEW MORE
story-3
8 Most "Only Corvette Owners Understand" Quirks and Problems

Slideshow: These are the quirks, annoyances, and oddly lovable problems that every Corvette owner eventually learns to live with.

By Pouria Savadkouei | 2026-05-28 09:31:39


VIEW MORE
story-4
10 Reasons the C6 Z06 is Still A Performance Benchmark After 20 Years

Slideshow: 10 reasons why the C6 Z06 is still a performance benchmark after 20 years.

By Joe Kucinski | 2026-05-27 17:20:09


VIEW MORE
story-5
How Much Horsepower Every Corvette Engine "LOST" in 1972

Slideshow: How much horsepower every Corvette engine lost in 1972.

By Joe Kucinski | 2026-05-27 16:54:53


VIEW MORE
story-6
Top 10 DOs and DON'Ts for Protecting Your Convertible Top!

Slideshow: How to Protect A Convertible Top: 10 DOs & DON'Ts

By Michael S. Palmer | 2026-04-03 00:00:00


VIEW MORE
story-7
Top 10 Most Explosive Corvettes Ever Made: Power-to-Weight Ratio Ranked!

Slideshow: The 10 most explosive Corvettes ever built based on power-to-weight ratio.

By Joe Kucinski | 2026-05-20 07:23:03


VIEW MORE
story-8
150 hp to 1,250 hp: Every Corvette Generation Compared by the Specs That Matter

Slideshow: From C1 to C8 we compare every Corvette generation by the numbers.

By Joe Kucinski | 2026-05-12 16:54:12


VIEW MORE
story-9
8 Coolest Corvette Pace Cars (and Replicas) of All Time

Slideshow: Some Corvette pace cars became collectible legends, while others perfectly captured the look and attitude of their era.

By Verdad Gallardo | 2026-05-11 09:50:51


VIEW MORE