Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
Locked
0

Fake Flash Player Website

New Here ,
Nov 06, 2014 Nov 06, 2014

I just want to report a fake Flash Player website I was redirected to while in the middle of reading an article on a blog.  The website is as follows:

[link removed]

Luckily, I noticed the url ahead of time.  I went to the official Adobe Flash Player website and it said Flash Player on my Chrome browser is up-to-date.  Also, did a who is domain search and the information about the registrant and the registrar was very sketchy.

Message was edited by: Jeromie Clark - Removed the links so that nobody accidentally followed it

2.1K
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Nov 08, 2014 Nov 08, 2014

I am embarrassed to admit that I fell for this. I was multitasking and inattentive. Earlier today I had been prompted by a legitimate Flash reminder to upgrade my player, which primed me to agree with the installation. When I realized the mistake, I force quit the process and may have canceled the installation before it was completed.

I am not entirely sure what it installed in my brand-new Retina 5K iMac (I know... I want to kick myself too) but it appears to have installed a folder named InstallMac and an application named "Reset Search". (I verified it by Date Modified.)

I deleted the folder. I am unaware of any other changes this may have made to my system. It appears to be Adware, but Chrome and Safari appear to not have been infected.

Any other ideas and suggestions would be greatly appreciated.

This is where I got the file from (Clicking on the link will not download the "dmg" file, but the browser will prompt you to):

[removed sketchy links]

I was reading a news story on The Guardian when I was prompted.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Nov 09, 2014 Nov 09, 2014

Because I caught it in time, my computer was not infected.  But I still ran Malwarebytes and Norton.  Neither Malwarebytes and Norton anything on my system and my computer has been running fine.  I did an internet search for easyinstantupdates.be and found that this is new virus.   You may want to visit this website for tips to remove easyinstantupdates.be:

[sketchy link removed]

Good luck!

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Jan 15, 2019 Jan 15, 2019

yes, i run in the same issue

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Jan 16, 2019 Jan 16, 2019
LATEST

Thanks for the note.  I'll forward this along to our phishing team.  If you see similar sites in the future, please send a screenshot and full URL to phishing@adobe.com, and they'll be happy to pursue it.

---

For the folks that actually installed malware on their machines, sorry this happened to you.  I'm going to leave some advice here for other folks that may run across this.

Unfortunately, because Flash Player is installed on billions of computers, it's a common target for impersonation for people distributing malware.

As an industry, we've done a pretty good job of defending against technical attacks that allow bad guys to install software without your authorization.  In 2018, it's really difficult to do (assuming you're running a modern operating system and not something from 2005, in which case, you should get on that).

The result is that human factors are now the path of least resistance.  It's easier to trick you into installing something on behalf of the attacker, vs. figuring out how to defeat all of the security stuff required to do it without your express permission.

In general, you're better off setting everything to update automatically.  You can then go through life assuming that any update notifications you get are bogus.  This is actually what we strongly recommend, and it generally applies to anything tasked with handing untrusted communication (the operating system, your web browser, flash player, etc.).  The inconvenience of something functional breaking because of an update pales in comparison to the pain of recovering from identity theft.

Here are a few guidelines that will minimize your risk of getting tricked into installing malware:

- Wherever possible, use your operating system's App Store for downloading and updating software

- When software you want (like Flash Player) isn't available from the App Store for your operating system, always navigate directly to the vendor's website.  If you need to search for the download, that's cool -- but avoid "download" sites, and find the vendor's actual download link

- Never download stuff from a link in an email or update dialog.  Type it in.  It's easy to disguise fake URLs in links using internationalized characters and things (e is not the same as è, but it might be really easy to miss if you're not looking closely).  If it's a link from a URL shortener

service like tinyurl.com/abcde or bit.ly/abcde, you don't know what the end result is going to be, and you're probably wise to just head to Google to find what you need instead.

- When the software offers automatic updates, just turn them on and stop worrying about maintaining all the moving parts running on your computer.  The threat landscape is so much different than it was 10-15 years ago.  Enable updates so that you're getting critical patches as soon as they become available.  Be confident that any subsequent update notifications are probably fake, and act accordingly (either ignore them, or consult the vendor for guidance before doing anything).

For Flash Player specifically:

Always download Flash Player from here:  https://get.adobe.com/flashplayer/

When you install, choose the default option of "Allow Adobe to Install Updates (recommended)", and we'll keep it updated for you.

Google Chrome ships Flash Player as a built-in component, and keeps it updated automatically.  There's nothing separate to download, install or configure.

Microsoft Edge and Internet Explorer on Windows 8 and higher also include Flash Player as a built-in component of their browser, and updates are handled automatically through Windows Update.  Again, as long as Windows Update is enabled, there's nothing to download or configure.

Also, while you've manually cleaned up the stuff that you can see, you installed malware on your machine.  There's a large universe of unknown unknowns, but the malware guys at this point are generally professionals.  They test against the popular antivirus and cleanup tools.  While you've removed the obvious visible signs of the malware infection, you're putting a lot of faith into the tools that you used.  This sort of requires a gut-check on your part about what your risk tolerance and confidence level is.  It also depends on what you do with the computer (health care, banking, etc.).  Good malware is going to first establish a foothold, but the second order of business would be to ensure resilience.  Without an exhaustive (and expensive) forensic analysis, there are no guarantees that you've eradicated everything that was installed.

If it were me, I'd probably back up all of the critical data on the machine and then burn the whole thing down and start from scratch (e.g. format the hard disk, reinstall the operating system and applications from pristine sources, install a reputable antivirus utility, scan my backups and then restore them.  I'd then go buy a password manager like LastPass/OnePass/KeyPass/etc. and set about ensuring that I have unique, strong passwords for each of the important online services that I use (including any email services that could be used to reset those passwords), and set up two-factor authentication wherever it's offered.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines