RedCafe Malicious Advert?

Niall

All Powerful Super Being
Staff
Joined
Jun 13, 1999
Messages
24,612
Sorry just noticed you mentioned this in your OP.

There are no ads in the general forum, so it's not come from some rogue code in an ad. I don't see anything specific in any of the posts in that thread that might cause it either. Possibly something on your machine? Have you done a full virus scan / malware clean up etc?
 

Zarlak

my face causes global warming
Joined
Apr 30, 2010
Messages
45,407
Location
Truth like rain don't give a feck who it falls on.
What operating system and browser are you using?
Windows 7, Chrome. I haven't had it on any other website, it pops up pretending to be Adobe Flash player but you can see player is spelt palyer, then auto downloads a setup.exe.

It might well be a virus so I'll check when I'm back from work, I just thought it strange that it only appeared in that thread.
 

duffer

Sensible and not a complete jerk like most oppo's
Scout
Joined
Jun 24, 2004
Messages
50,421
Location
Chelsea (the saviours of football) fan.
I got exactly the same thing as Zarlak a few days ago. I am using Windows 7 and Firefox. Can't remember the thread but if it happens again i'll take a screenshot.
 

Niall

All Powerful Super Being
Staff
Joined
Jun 13, 1999
Messages
24,612
Changes have been made to the ad inventory to hopefully filter out these dodgy ads. Can people please let me know if they see them again and if possible take a screenshot?
 

Woodzy

Full Member
Joined
Sep 10, 2004
Messages
14,762
Location
Cardiff
Browsing the forums on my iPad and I was taken to the AppStore automatically very recently. Being an iPad it's likely that I clicked something for this to happen, but I'm convinced that I didn't.
 

Eugenius

Full Member
Joined
May 10, 2009
Messages
3,933
Location
Behind You
I was reading the Moyes sacking thread on my nexus 7 and got a pop up telling me I needed flash player. I pressed the back button but it still took me to a fake Ad0be site where it forcefully downloaded what I assume to be a malicious exe file
 

Madthinker

Full Member
Joined
Feb 11, 2012
Messages
1,592
Location
Behind you
At 17:15 (I think while browsing the 'invite only' thread, I got taken to update4.flashes-player.us, which forcibly downloaded a setup.exe and gave the usual spiel about needing to upgrade.

On Chrome/Windows 8.
 

Woodzy

Full Member
Joined
Sep 10, 2004
Messages
14,762
Location
Cardiff
I was reading the Moyes sacking thread on my nexus 7 and got a pop up telling me I needed flash player. I pressed the back button but it still took me to a fake Ad0be site where it forcefully downloaded what I assume to be a malicious exe file
I just got this on my desktop.
 

WeasteDevil

New Member
Joined
Jun 21, 2001
Messages
109,016
Location
Salford in Castellón de la Plana
You have something really naughty going on. At times when you refresh the page it redirects you to a page saying that you have to update Flash, which obviously Adobe would not do. It looks authentic but is asking people to install setup.exe from a dodgy site.

This has been happening all day. It happens even if you press F5 at times.
 

LR7

Full Member
Joined
Jun 6, 2012
Messages
8,885
Browsing the forums on my iPad and I was taken to the AppStore automatically very recently. Being an iPad it's likely that I clicked something for this to happen, but I'm convinced that I didn't.
I keep getting this. Definitely not clicking anything but taken to some game page in the AppStore.
 

Niall

All Powerful Super Being
Staff
Joined
Jun 13, 1999
Messages
24,612
You have something really naughty going on. At times when you refresh the page it redirects you to a page saying that you have to update Flash, which obviously Adobe would not do. It looks authentic but is asking people to install setup.exe from a dodgy site.

This has been happening all day. It happens even if you press F5 at times.
It's still happening, it has only been doing this to me today, but it seems that it has been going on all week.
I've removed the ad code which I think is the source of these Adobe ads. Please let me know if you keep seeing and what page you are on when it happens.

I keep getting this. Definitely not clicking anything but taken to some game page in the AppStore.
The iOS redirects is a widespread problem across many ad networks and I'm trying to filter them out as best I can. It's proving difficult though :(
 

Revan

Assumptionman
Joined
Dec 19, 2011
Messages
49,638
Location
London
Yeah, it happened to me today on my laptop too but my antivirus catched the malicious file.
 

jojojo

JoJoJoJoJoJoJo
Staff
Joined
Aug 18, 2007
Messages
38,320
Location
Welcome to Manchester reception committee
That fake flash player thing suddenly appeared on my network yesterday. Not just on the caf though. I ran a few tests. Turned out it was redirecting traffic that should have gone to google _ including site custom searches. It was actually a router worm rather than something on the machines.
 
Last edited:

Niall

All Powerful Super Being
Staff
Joined
Jun 13, 1999
Messages
24,612
It was a 'you have a virus alert'. No useful diagnostics I'm afraid
Has it happened on any other site you've been on? Can you remember if you were you looking at a thread, the forum list or a thread list page?
 

Crackers

greasy ginfers
Joined
May 30, 2012
Messages
29,321
Location
Glazers Out
It might be an idea to open press f12 and looking at the console tab anytime you(or any of us) gets an error. Giving Niall the information from the link might be helpful.
@Niall could it be some sort of cross site scripting?
 

Niall

All Powerful Super Being
Staff
Joined
Jun 13, 1999
Messages
24,612
It might be an idea to open press f12 and looking at the console tab anytime you(or any of us) gets an error. Giving Niall the information from the link might be helpful.
@Niall could it be some sort of cross site scripting?
Doubt it. If there was a security hole in XenForo and somebody was injecting malicious code into content on the site, it would be happening to a lot more people.

It's either ads that have malicious javascript embedded in them (a big problem with many ad networks atm) or it's an issue on the user's end, possibly a hacked router as described by somebody else in this thread.

Either way, it's extremely difficult for me to track down and stop :(
 

Silent_Running

Dr. John Hammond
Joined
Jun 6, 2013
Messages
3,281
i just got an ad saying my pc has been locked due to me looking at child porn and i have to pay £100 fine to use my 'computer' again. I'm on my phone here but if i was at work and somebody saw that i would be seriously angry. As someone who doesn't look at child porn, I'm pretty upset about this and i think something needs to be done, Niall.

i had been getting other malware ads for 'flash player' installations and stuff like that, but this is a bit too far.
 

Big-Red

Not actually very big
Staff
Joined
Apr 6, 2009
Messages
25,334
Location
Dublin
Supports
this year is my year on SM
i just got an ad saying my pc has been locked due to me looking at child porn and i have to pay £100 fine to use my 'computer' again. I'm on my phone here but if i was at work and somebody saw that i would be seriously angry. As someone who doesn't look at child porn, I'm pretty upset about this and i think something needs to be done, Niall.

i had been getting other malware ads for 'flash player' installations and stuff like that, but this is a bit too far.
Thats a virus.
 

rcoobc

Not as crap as eferyone thinks
Joined
Jul 28, 2010
Messages
41,701
Location
C-137
i just got an ad saying my pc has been locked due to me looking at child porn and i have to pay £100 fine to use my 'computer' again. I'm on my phone here but if i was at work and somebody saw that i would be seriously angry. As someone who doesn't look at child porn, I'm pretty upset about this and i think something needs to be done, Niall.

i had been getting other malware ads for 'flash player' installations and stuff like that, but this is a bit too far.
:lol: (Sorry that's hilarious)

I haven't had these stupid things in ages. I recommend everyone get Avast for the phone. It might not be doing anything, buy I haven't got it in a while
 

jojojo

JoJoJoJoJoJoJo
Staff
Joined
Aug 18, 2007
Messages
38,320
Location
Welcome to Manchester reception committee
I just know that the child porn warning thing is a well known virus. Theres something mad going on here though, I've yet to see any dodgy ads.
As I mentioned earlier, I did have a router get hacked a week or so ago that simultaneously put all these kinds of symptoms on all the gadgets in the house - phones and computers. It took me a few hours to understand the problem but since the router work that I did I've seen no recurrence - though I will say I'm getting more server busy messages from RedCafe than normal.

A common variant of the problem is Google and similar search sites getting diverted to Conduit Search either by changes in browser setting, entries in their hosts file, or by the individual machine (or the router) being switched to use a hacked or spoof DNS server. It wouldn't be a surprise if certain advertising server addresses are now being diverted as well.

I guess the other "why not everyone" thing is that context/target sensitive advertising may mean it really is just some ads that have something nasty embedded - right now my browser is busy trying to sell me flight tickets, cameras and flashAir cards but I'm sure that's not true for everyone.
 

jojojo

JoJoJoJoJoJoJo
Staff
Joined
Aug 18, 2007
Messages
38,320
Location
Welcome to Manchester reception committee
i just got an ad saying my pc has been locked due to me looking at child porn and i have to pay £100 fine to use my 'computer' again. I'm on my phone here but if i was at work and somebody saw that i would be seriously angry. As someone who doesn't look at child porn, I'm pretty upset about this and i think something needs to be done, Niall.

i had been getting other malware ads for 'flash player' installations and stuff like that, but this is a bit too far.
That sounds like the Windows classic known as the police virus
http://blog.vilmatech.com/metropoli...-remove-metropolitan-police-virus-completely/
I haven't seen it on a phone, but I don't see why they can't get it.
Do you have an AV program?

The most shocking version of it that I've seen included approximate location based on IP address and a photo of the "accused" taken with his webcam
 

rcoobc

Not as crap as eferyone thinks
Joined
Jul 28, 2010
Messages
41,701
Location
C-137
As I mentioned earlier, I did have a router get hacked a week or so ago that simultaneously put all these kinds of symptoms on all the gadgets in the house - phones and computers. It took me a few hours to understand the problem but since the router work that I did I've seen no recurrence - though I will say I'm getting more server busy messages from RedCafe than normal.

A common variant of the problem is Google and similar search sites getting diverted to Conduit Search either by changes in browser setting, entries in their hosts file, or by the individual machine (or the router) being switched to use a hacked or spoof DNS server. It wouldn't be a surprise if certain advertising server addresses are now being diverted as well.

I guess the other "why not everyone" thing is that context/target sensitive advertising may mean it really is just some ads that have something nasty embedded - right now my browser is busy trying to sell me flight tickets, cameras and flashAir cards but I'm sure that's not true for everyone.
This is a good point. My phone is trying to constantly sell me cash back credit cards and baby gates, jenga and monitors from Amazon. I havent seen any adverts but those on the caf for ages.