Locky Ransomware being Distributed through Fake Flash Player Update Sites

  • 17 November 2016
  • 1 reply
  • 1 view

Userlevel 7
Badge +54
As we have said many times in here, always download from the vendors own site.
 
November 17, 2016  By Lawrence Abrams
 
Fake Flash Player update sites have long been a favorite distribution method for adware and other unwanted programs. Today, a fake Flash update site was discovered by ExecuteMalware that is pushing the Locky ransomware.  When someone visits the site they will be presented with a page that states that Flash Player is out of date and then automatically downloads an executable. If you look carefully at the URL in the browser's address you can see that the domain of fleshupdate.com does not seem to  be spelled right.
 
                              


 
Full Article

1 reply

Userlevel 7
Very, very true...and also one shoul;d check the URLs involved as they can be a dead giveaway to nefarious sites.

Reply