Closed Bug 948300 Opened 11 years ago Closed 10 years ago

www.update-browser.org/firefox/ serving fake Updater-setup.exe

Categories

(Marketing :: Trademark Violations, task)

task
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: james.bugzilla, Assigned: jeff)

Details

Attachments

(1 file)

2.18 MB, application/x-ms-dos-executable
Details
Attached file Updater_Setup.exe
User Agent: Mozilla/5.0 (X11; Linux i686; rv:26.0) Gecko/20100101 Firefox/26.0 (Beta/Release)
Build ID: 20130821030213

Steps to reproduce:

This website www.update-browser.org/firefox/ has popped up on SUMO and mozillaZine forums every so often in last couple months and the site is still up. It seems to either popup due to some malware on computer or be by ads or redirects on some sites.


Actual results:

Go to www.update-browser.org/firefox/ and get presented with "Outdated Browser Detected" and "Please Update to the Latest Version of Firefox (Recommended)" and it then tries to get you to download a Updater-setup.exe that is 2.2MB in size.


Expected results:

Site should ideally should not exist and be taken down of course ;) instead of preying on inexperienced users.

I have reported it by fraud report however I wanted to increase the odds the appropriate people do know about it and deal with it sooner as it has been up too long now. Thank you.
Another site to mention is http://www.updating-your-browser.com/Firefox/
another such variation site is 
http://updatesoftnow.com/s/2/
http://updatesoftnow.com/s/3/
I've received lots of reports of these fake update needed pop-ups. I've consulted with outside counsel and there's not much we can do legally, it's almost impossible to find out who is behind them. Jeff Bryner has been working with law enforcement to see if they can help. I'm reassigning this bug to him. I think the other best course of action is to report these to Google Safe Browsing and perhaps anti-virus vendors as well Jeff is also working on that.
Assignee: liz → jbryner
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Just met the CISO of go-daddy at a conference and asked him about these sort of issues. He offered to help as we see them especially if they are hosting malware. Looking at all of these they are currently inactive.

Should we keep this bug open as a tracker for currently active sites? Or close it and open one per site?
One version that I have seen recently that is the most convincing to inexperience Firefox users so far is http://www.schoolsport.edu.au/safebrowsing/firefox/ and may be one that can be taken down more easily due to where it is hosted.

On the up side the first three links I posted seem to be down now however the http://updatesoftnow.com/s/2/ and http://updatesoftnow.com/s/3/ is still up for me.
I've contacted the registrar for both sites to assist.
Registrar returned my email, worked with the customer to identify an exploited wordpress site and disabled it.
Status: ASSIGNED → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
Here is another site that has popped up. 

Watchnow.deliciousgoldfish.com
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: