. Codes: HTML: FakeAlert-T [Trj]
HTML:EvilCursor-B [Trj]
HTML:Tech-Scam-M [Phish]
. Filed under:Windows Fake Alerts
. Properties: This error is displayed by a malicious website that claims that the victim's PC is infected with viruses and other malware. These
websites use aggressive tactics to keep the victim from exiting the
website by closing the tab and some also prevent the visitor from
closing the internet browser, through normal means These webpages can
also cause the browser and the victims mouse to act erratically. Some of
these webpages also overload the victim's computer by running many
background process through the browser, causing the browser to either
freeze or shut down unexpectedly. Often, an "official looking" Windows
error message along with a telephone number will be displayed, prompting the
victim to call the number for official technical support. Should the
victim call the number, they will be asked by the scammer to download
additional software as to gain access to the victims computer remotely
which in turn, the scammer on the other end will charge the victim an
enormous sum of money for bogus Anti-virus software and technical
support. While this is one of the oldest scams on the internet, the
biggest flaw of this scam is the fact that all supposed virus warning
come the the webpage and not through the desktop notifications.
Microsoft itself is alos another give away. Microsoft has not and will not ever call or ask any of their customers to call them if their PC's are infected.
Microsoft's built in anti-malware, Windows Defender, has been released
with every version of Windows since Windows Vista & Windows 7.
. Organizations affected: Microsoft
. Reported to: Scumware.org, Google Safe browsing (Report Phishing, Report Malware), EST.com (Via Report a Phishing page)
. Organizations affected: Microsoft
. Reported to: Scumware.org, Google Safe browsing (Report Phishing, Report Malware), EST.com (Via Report a Phishing page)
*Warning: For your safety, it is highly recommend that users do not visit any of the websites under the following codes: HTML:EvilCursor-B [Trj] debug-filing244.gq [URL:Phishing]
These webpages are extremely aggressive and will cause crashes and other undesired effects.
. Screenshots:
![]() |
HTML: FakeAlert-T [Trj] |
![]() |
HTML: FakeAlert-T [Trj] |
![]() |
HTML:Tech-Scam-M [Phish] HTML:EvilCursor-B [Trj] |
![]() |
HTML:Tech-Scam-M [Phish] HTML:EvilCursor-B [Trj] |
. Offending website URL's:
*These websites are considered dangerous. For your safety, the links have been published as plain text.
https://ovprescanal.ga/ln/Q6n8TohQhao_UV.hvySJzHJXIr96qE5WbCCqUotN6Ob_hK5.2IQ1m75rdizrt35UyfXqnipiE4AhF39KGNTKScInEwwaDdYePBPyDSW2Xv8PP.QBQKyOaUcSXOSQgSohDDk0mqUpIc5nk88wiYk_ApvqCG2q4zz9WK7VpoLMwU0ozhaepVLFc06PC1xCitvlrCQ_Aa.OpoR.VinyUqb33kYUmO.vZC2eRk8gFMESjh8cpRc91pEs2_duutNewliVg2yjj029S6QjETpxR3ML5RlAcRpaZLX_ZNufe63YmjC822LjxogvejlZLOeTkOut8v6DDd5sg8l7Tud7YsFXxqVlnKOr.aidamU__2byUP2ddF3pUiVMCYmoIvLeKDsHitiPkd0WMaeWfNWacNXfvEKBwsp6dYBdqQGqkhTkgJDiOLzz9RPI0dmSnApNtZy_v3eJWh20TZ_A1DFOl7wsod03H9WrzAz2DxJMOFt2wWM3cLLK.um9kkFTKDaD15KR2z_6Lsay_x1Vy.qro1ouE0vd7ELOlKJq3d6cPQsaQrUxrWLPY1Nk.LcBMfHQRe1ra9MbF5kuMsUQfcLjVkywnRxxG4uacRzwdED8xtdfYY6PEpY0D1xEXl5ERbSyoZB.sjfnR5zPR56bsvE1LSdLu0r1AQS2GSIe75EBwfczvGfH9ouYXnYW5OQy7O.RbBehUkCEdaaxJApDzXwZ76AAOz0tbnL6ZxBQUyKRJKzgqU1elbUPvkdK3.2G0FtJ4GKptq3A_hU1GORdXYmkhVMiCA__KJQEw6MHAgozuugMzrXWqfz.I8DTaSBWeCG_kRZGk1vUA6IcK_9T.hHEo5sSEvk3nlUq_nec6x1KTgTgpUh0_rvw5fTDLIfLor58jN1g
http://infopovod.press/MSSTORE/?bemobdata=c=04a6fd61-61d5-4f79-bd29-4ea4e758850f..a=0..b=0..z=0.03..e=s_4641250700071292145_156_6_0..c1=s156_2340893..c2=321757..c3=US..c4=Chrome..c5=332307..r=https%3A%2F%2Fclick-us.mppmnetwork.com%2Fv1%2Fdclick%2F42%2FeJwNTk1LAlEUVUETCXLtJpCYQHgz917ve_ddQYpq5dKIwFUzzgxKHw7OJPgn-gf9rZb9hhZt2vXgwPngwDmDCxBnwZZoilS8YZc6k-auNAVQqaXLVEWGX3_fv93RsT8Zfv58tEc9Uec9j4cWPCuQFY9OlWFyyTQTnXosSjWcZ9aw5myyHMkISsqZoE7tms7Q-piIYvQcYzCdm87D_aL7uH1DWPZuN_vda7E6uSvq52ZXjc_70WiACEzowblxF2JvYdKDGAgVWrTaNE1Vz5KkeOe4OKR5esjrKq72uyRwUm2S9cv6Kt3mc3aMZEEAQJCUkG3UzMODkJD1FNXzKaFYierQRuuuW4t-2EH2SsvToER9gCI_tf8BXVBQRg%3D%3D
https://klausen.in.net/click.php?key=q8yh8wwoh8u5w1npyh96&conversion_id={click_id}&cost=0.0400&tid=2619058&sid=2340893&cid=1057022&did=42%3Aac2694b4-b751-44d4-a658-7175035c5467&countr=US&brow=Chrome&devicetype=Desktop&platf=Win10
http://206.189.162.10/0CHfdfdfdfddfd99900NN1/?phone=+1-(888)-779-1896&