I just saw this and felt I should share it. I’m sure most people here wouldn’t fall for it but it can’t hurt to make sure 👍

Edit: I just wanted to add, I have no idea what this tried to copy. I’m using Firefox on Linux which is perhaps why it didn’t make it to my clipboard 🤷

  • zdanger@lemmy.world
    link
    fedilink
    English
    arrow-up
    64
    ·
    2 days ago

    My brother ran into this while car shopping on a reputable Utah based Toyota dealership’s website. It was a powershell script that downloaded and executed something from a base64 encoded Bitly URL. Bitly took down the URL so we couldn’t see where it was redirecting.

    It seems like attackers are embedding this in vulnerable legit websites

    • UnH1ng3d@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      20
      ·
      2 days ago

      Thanks, that’s very interesting to know. I assumed it was just a malicious site before.

    • JoshCodes@programming.dev
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 days ago

      Yeah, some wordpress themes have vulnerable bits that allow attackers to inject cross site scripting attacks into the page via various methods. Some have pivoted to using wordpress plugins which is a newer method I don’t entirely understand yet.

  • Hikermick@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    I came across this yesterday. It was right after a run of the mill “I am not a robot” message.

  • Treczoks@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    2 days ago

    Could someone just copy the clipboard content into a text editor so one could see what they are trying to do?

    • UnH1ng3d@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      I can’t actually make it copy 😅 I’ve now also tried in Firefox and Chrome but it still hasn’t worked.

  • JRaccoon@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    I think Microsoft should add a warning before allowing pasting into the Run dialog for the first time. Similarly like they already have in Edge’s console

    • Brosplosion@lemm.ee
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      Hot take, win+r should be disabled by default and have an option to enable. Probably 99% or more of users will never use the run dialogue

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        2 days ago

        Linux does this better by defaulting to files not being executable, versus Windows needing the downloading software to apply a specific “downloaded file” flag to trigger a notice about potentially unsafe files.

        You could make a lot of the commands available by default much less dangerous. Stuff like requiring using protected screens more (like UAC and ctrl+alt+del) for enabling the risky stuff.

        Also, sandboxing by default would do even more to prevent the worst dangers.

      • Aqarius@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 days ago

        Disagree, mostly because half the time I WinR is when I’m trying to fix someone else’s PC, and getting to the settings is half the problem.

  • markovs_gun@lemmy.world
    link
    fedilink
    English
    arrow-up
    23
    arrow-down
    3
    ·
    2 days ago

    Legit question- who is this for? I can’t imagine anyone getting to PC Master Race on Lemmy that would fall for something this obvious.

    • Warl0k3@lemmy.world
      link
      fedilink
      English
      arrow-up
      65
      ·
      2 days ago

      There’s a ton of IT workers on lemmy (go figure). Being aware of the current scams is quite valuable, since it means both that you can warn your users and you know what to look for when they inevitably ignore your warning and do it anyways.

      • SirSamuel@lemmy.world
        link
        fedilink
        English
        arrow-up
        13
        ·
        2 days ago

        Hi. That’s me. I came from all.

        I’m also not a complete dumbass, but i appreciate the post, b/c some of my family could BSoD a pocket watch

    • peto (he/him)@lemm.ee
      link
      fedilink
      English
      arrow-up
      16
      ·
      2 days ago

      You maybe not, your family? All your friends/coworkers/etc? Talk about scams with people, lots of people use PCs without knowing what is and isn’t safe.

    • Mouselemming@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      ·
      2 days ago

      Useful for someone like me who saw this in All. You know the “Granny lowers her glasses and peers into the computer screen” meme? That’s me, except I have progressive lenses (to match my politics) so I leave my glasses up.

  • nukeforyou@lemm.ee
    link
    fedilink
    English
    arrow-up
    30
    ·
    2 days ago

    Easily stopped by using Ad Blockers… Now if only chrome wasnt trying to kill ad blockers

    • Jolteon@lemmy.zip
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      2
      ·
      2 days ago

      Someone having a virus on their computer doesn’t prevent them from giving Google ad revenue.

  • SwizzleStick@lemmy.zip
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    2
    ·
    2 days ago

    Anyone falling for this lacks a basic understanding of technology, and should not be near the Internet unsupervised until they do. Regardless of age - plenty of young folk blindly walking into shit too.

    If you know people like this - please teach them. If you can’t teach them, at least set them up with foolproof tools. A non-chromium browser and ublock origin is a good start. If you’ve got the know-how, a DNSBL like a pihole (for whole home blocking) or adaway/blokada (for Android) are good additional layers.

    And get their data backed up 😬

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    118
    arrow-down
    3
    ·
    2 days ago

    If your web browser tells you to do something outside of your web browser, you shouldn’t.

  • Telorand@reddthat.com
    link
    fedilink
    English
    arrow-up
    23
    ·
    2 days ago

    This tactic is so old, but it weaponizes the annoying ubiquity of capchas. People just want to get to where they’re going, so they click the squares and do the dance to get past the seemingly arbitrary barriers.

    This technique shows up on [email protected] every few weeks as the initial attack vector for some new RAT.

  • Onno (VK6FLAB)@lemmy.radio
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 days ago

    URL?

    Knowing what it’s doing would be useful and people who have the ability to reverse engineer this can work on a fix or filter.

    • UnH1ng3d@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 days ago

      motorandwheels(dot)com

      • I think it would be best if it isn’t clickable

      I’ve also noticed, it doesn’t always come up but let me know if it does for you.

      • Fonzie!@ttrpg.network
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 days ago

        It didn’t show up when I first visited it, but it did after a hard refresh (Ctrl+Shift+R)

        I didn’t copy anything to the clipboard, though.

        Firefox 137.0 (64-bit) on Linux 6.8.0-57-generic on Mint 22.1

      • FeelzGoodMan420@eviltoast.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        2 days ago

        I’m confused. Is this a malicious website that you came across? Is this website normally legit? Was this an ad popup? Do you use ublock origin? It would be great if you gave a little more information here. Otherwise we don’t really know what you were doing or what we should avoid. If this is a real legit website then my guess is this was an ad popup.

        Edit: virustotal for that website is clean. So either this was a popup (you should use ublock origin) or your PC is infected with malware and you may want to take action (idk for sure, just a guess.) Another possibility is that website was compromised.

        • UnH1ng3d@lemmy.worldOP
          link
          fedilink
          English
          arrow-up
          4
          ·
          2 days ago

          I’ve never visited the site before so I just assumed it was just malicious, but as @zdanger said, it might be a hijacked legit site.

          I do use uBlock. It also didn’t ‘feel’ like an ad. I now expect the site was compromised as you suggested.

          • JRaccoon@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 days ago

            For me accessing that site in Firefox on Windows (even with uBO) does trigger the scam popup, but in any other browser I tried (Edge, Chrome, FF dev edition), it doesn’t. Kinda interesting.

            The popup does not manage to add anything to the clipboard. There are tons of JS errors in the console, so luckily the thing seems to be pretty broken right now.

          • FeelzGoodMan420@eviltoast.org
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            2 days ago

            I wonder if this is an issue on Linux only maybe? Not seeing anyone here on Windows confirming this.

            Edit: nvm someone on windows confirmed it