When going to the homepage, I just got a maladvertisement that was trying to spread a virus/trojan-horse using a fake captcha and user phishing, asking me to copy and paste an unknown command (I should have captured and stored it as evidence). While ad payloads can be injected by hosts and even ISPs, you might want to check your server for any malware!
Hi!
I’m sorry to co-opt the comments with this, but I have noticed a so-called “ClickFix” attack on this website:
When opening the site for the first time, a fake CAPTCHA is shown that tries to goad users into executing malicious code on their computers. It is important for everyone not to follow the instructions under “Verify you’re human”.
It should be possible to see this fake CAPTCHA again by opening the site in a fresh private window.
Hey, unrelated to the post, I just wanted to let whoever runs this website know that there’s some kind of malware shenanigan going on for first time visitors of the site. It seems like it’s storing a cookie, or otherwise tracking you, such that it only triggers on the first visit. But I’m reproducing it every time in a fresh incognito window. Instead of the website, I’m being shown a fake, “prove you’re not a robot” thing, which instructs me that in order to prove i’m human, i must copy a string into the Windows Run dialogue, which looks like a command to install some malware. If I refresh, then I see the crookedtimber website like normal. And on all subsequent refreshes. But I’m seeing it every time on a new incognito window.
{ 6 comments }
Alan White 07.26.26 at 2:54 pm
How ominous!
Julian Mark Summerhayes 07.27.26 at 7:07 am
What a great picture. It reminds of a place in Plymouth, near to the Hoe.
Chris Pitchford 07.28.26 at 3:48 pm
When going to the homepage, I just got a maladvertisement that was trying to spread a virus/trojan-horse using a fake captcha and user phishing, asking me to copy and paste an unknown command (I should have captured and stored it as evidence). While ad payloads can be injected by hosts and even ISPs, you might want to check your server for any malware!
Thomas R. 07.28.26 at 9:18 pm
Hi!
I’m sorry to co-opt the comments with this, but I have noticed a so-called “ClickFix” attack on this website:
When opening the site for the first time, a fake CAPTCHA is shown that tries to goad users into executing malicious code on their computers. It is important for everyone not to follow the instructions under “Verify you’re human”.
It should be possible to see this fake CAPTCHA again by opening the site in a fresh private window.
Please have a look into this. I have also found an article with more information about the issue here: https://techearl.com/wordpress-fake-cloudflare-verification-clickfix
Peter 07.28.26 at 11:57 pm
Hey, unrelated to the post, I just wanted to let whoever runs this website know that there’s some kind of malware shenanigan going on for first time visitors of the site. It seems like it’s storing a cookie, or otherwise tracking you, such that it only triggers on the first visit. But I’m reproducing it every time in a fresh incognito window. Instead of the website, I’m being shown a fake, “prove you’re not a robot” thing, which instructs me that in order to prove i’m human, i must copy a string into the Windows Run dialogue, which looks like a command to install some malware. If I refresh, then I see the crookedtimber website like normal. And on all subsequent refreshes. But I’m seeing it every time on a new incognito window.
Thought I’d let you know!
Alan White 07.29.26 at 5:23 am
I’ve seen that too. And avoided it.
Comments on this entry are closed.