Backdoor malware spread by fake security Hitskin_logo Hitskin.com

This is a Hitskin.com skin preview
Install the skinReturn to the skin page

The forum of the forums
Would you like to react to this message? Create an account in a few clicks or log in to continue.
3 posters

    Backdoor malware spread by fake security

    jkh
    jkh
    Forumember


    Posts : 627
    Reputation : 17
    Language : english

    In progress Backdoor malware spread by fake security

    Post by jkh Fri 12 Feb 2021 - 14:48

    Howdy all

    My forum was running slow today and I kept getting a 'maintenance' page. While I was waiting for the forum to load I could see, in the bottom left hand corner it said waiting for dealctr.com - I googled it and it said it's a 'backdoor malware that's spread through fake security'.

    Marvellous.

    Does anyone know how it got there and how I can get rid of it please? Does this affect all members of my forum? I don't get the same alert on any other website, so I guess it's not a virus on my computer...

    I'm a bit concerned about 'fake security'.

    Thank you.
    skouliki
    skouliki
    Manager
    Manager


    Female Posts : 15311
    Reputation : 1705
    Language : English,Greek
    Location : Greece

    In progress Re: Backdoor malware spread by fake security

    Post by skouliki Fri 12 Feb 2021 - 15:29

    Your forum is definitely secured
    Now I refresh many times you forum but i didnt get any error or maintenance page
    Is this still happening?

    The Godfather
    The Godfather
    Administrator
    Administrator


    Posts : 5297
    Reputation : 844

    In progress Re: Backdoor malware spread by fake security

    Post by The Godfather Fri 12 Feb 2021 - 16:19

    Hello @jkh

    We experienced a problem with one of our servers which was charged for several minutes. Based on your post and the time you posted it, this corresponds perfectly to this problem. Hence the latencies you encountered while browsing your forum.


    Last edited by The Godfather on Fri 12 Feb 2021 - 16:20; edited 1 time in total

    Niko likes this post

    jkh
    jkh
    Forumember


    Posts : 627
    Reputation : 17
    Language : english

    In progress Re: Backdoor malware spread by fake security

    Post by jkh Fri 12 Feb 2021 - 16:20

    Hi Skouliki  Hello

    I activated the adblocker on my browser for my forum, then I didn't get the alert. I also didn't get the alert after I deactivated the adblocker.

    I also deleted the forum cookies and ran a virus check, but no virus on my pc, so I guess whatever the problem was it's been resolved somehow.

    I haven't seen that dealctr.com thingy before.  


    Backdoor malware spread by fake security 526998

    How do you know my forum is secure? Is it because of the padlock thing at the top?
    jkh
    jkh
    Forumember


    Posts : 627
    Reputation : 17
    Language : english

    In progress Re: Backdoor malware spread by fake security

    Post by jkh Fri 12 Feb 2021 - 16:22

    The Godfather wrote:Hello @jkh

    We experienced a problem with one of our servers which was charged for several minutes. Based on your post and the time you posted it, this corresponds perfectly to this problem. Hence the latencies you encountered while browsing your forum.
    Ah thank you for explaining...all seems to be well now :rose:
    jkh
    jkh
    Forumember


    Posts : 627
    Reputation : 17
    Language : english

    In progress Re: Backdoor malware spread by fake security

    Post by jkh Fri 12 Feb 2021 - 16:27

    Oh, I've just seen it again....

    and this: ct.sddan.com (open threat exchange)
    skouliki
    skouliki
    Manager
    Manager


    Female Posts : 15311
    Reputation : 1705
    Language : English,Greek
    Location : Greece

    In progress Re: Backdoor malware spread by fake security

    Post by skouliki Fri 12 Feb 2021 - 16:36

    Please don't double/tripple post, use the edit button instead

    The Godfather
    The Godfather
    Administrator
    Administrator


    Posts : 5297
    Reputation : 844

    In progress Re: Backdoor malware spread by fake security

    Post by The Godfather Fri 12 Feb 2021 - 16:44

    You talk about external resources. For the first mentioned, certainly called by an advertising network that we use: Criteo, Google Adsense, Taboola...

    For the second (sddan.com), it is the provider of our consent banner for the GDPR.

    Likewise, we have just intervened once again on the server in question.

    TonnyKamper likes this post