Sdp-38359625.bid

The Sdp-38359625.bid domain is associated with a technical support tactic that relies on pop-up loops to trick users into thinking a virus infiltrated their systems. Pop-up loops are scripts that prevent browsers like Mozilla Firefox, Google Chrome, Edge, Internet Explorer, Opera and others from functioning correctly. The pop-up loop scripts are used by technical support con artists very often. The Sdp-38359625.bid hosts a phishing page that resembles the official support page for Microsoft customers available on Support.microsoft.com. The Sdp-38359625.bid phishing page includes logos of trusted Microsoft services and a pop-up window that is titled 'WARNING!.' The pop-up alert is presented to visitors, and it displays the following message:

'Your Windows has been blocked due to suspicious activity! please call Support Now!
Call Toll-Free 040-668-8973 To find right solution.'

The user is given the option to say or leave Sdp-38359625.bid via two buttons placed below the 'WARNING!' message. However, the buttons are there as a facade, and the pop-up loop scripts are loaded in the browser immediately after the 'Windows has been blocked due to suspicious activity' message appears on your screen. Hence, leaving Sdp-38359625.bid can be tricky, and you might have to access the Task Manager and kill the browser's primary process. You should ignore the Sdp-38359625.bid pop-ups and avoid making contact with the crooks waiting on the other end of the 040-668-8973 phone line. Their goal is to convince users into approving remote access to their systems and then lead them to pay for system repairs they don't need in the first place. Needless to say, the remote access may be used to hijack your online accounts, destabilize your system and delete data so that you are convinced that help from a technician is required. The best way to react is to block any incoming remote desktop requests and report the Sdp-38359625.bid phishing portal via the reporting system in your browser. We have found that the 18.216.98.141 IP address corresponding to Sdp-38359625.bid appears to be used by a dozen more phishing pages that include (but not limited to):

  • aah-1621894161[.]racing
  • aeu-6713519226[.]racing
  • eol-0840337351[.]review
  • gqd-8853628667[.]download
  • jvt-9373964558[.]trad
  • klx-2274708884[.]accountant
  • mcc-1871319324[.]science/?h=NTI=
  • mzj-7928924851[.]party
  • oxq-4431179104[.]date
  • qlb-0185495081[.]cricket
  • wfw-5088742779[.]date
  • zqf-8402556114[.]faith

Trending

Most Viewed

Loading...