Threat Database Adware Web-alrt-phsng-atck.xyz

Web-alrt-phsng-atck.xyz

By GoldSparrow in Adware

The Web-alrt-phsng-atck.xyz domain is flagged as unsafe by most Web filtering services and AV vendors. The Web-alrt-phsng-atck.xyz is known to host phishing messages and load a JavaScript that crashes the visitor's browser. The messages show by Web-alrt-phsng-atck.xyz aim to convince the user that a threat named RDN/YahLover.worm!055BCCAC9FEC is loaded into Windows. Experts strongly advise against opening the Web-alrt-phsng-atck.xyz site and ignoring the security alerts shown by the browser. Opening Web-alrt-phsng-atck.xyz will result in fake security notifications from the site, which can freeze your browser and you will have to use the Windows Task Manager to resume your activity online.

Web-alrt-phsng-atck.xyz is styled to resemble the warning screen in Google Chrome and Mozilla Firefox that notifies the user of an untrusted site ahead. The Web-alrt-phsng-atck.xyz features a background image colored in red and a text that says:

'Your computer has been Locked
Your computer with the IP address has been infected by the Virus RONINahLover wormID55BCCAC9FEC --Because System Activation KEY has expired & Your information (for example, passwords, messages, and credit cards) have been stolen. Call the Technical Support number +1-844-592-9882 to protect your files and identity from further damage.
111 Automatically report details of possible security incidents to Google.
Privacy policy
+1-844-592-9882'

A JavaScript code is responsible for a dialog box displayed in the foreground while Web-alrt-phsng-atck.xyz is loaded in your browser. The message box shown on Web-alrt-phsng-atck.xyz cannot be closed with the 'X' button unless you instruct your browser to prevent Web-alrt-phsng-atck.xyz from loading additional messages. The alert on Web-alrt-phsng-atck.xyz reads as follow:

'++++++++++++++++++++++++++++++++++++++++
RDN/YahLover.worm!055BCCAC9FEC infection
++++++++++++++++++++++++++++++++++++++++
Call Technical Support immediately at +1-844-592-9882
The following data will be compromised if you continue:
1. Passwords
2. Browser History
3. Credit card Information
This virus is well known for complete identity and credit card theft. Further action through this computer or any computer on the network will reveal private information and involve serious risks.
Call Technical Support immediately at +1-844-592-9882'

You should note that loading Web-alrt-phsng-atck.xyz may crash your browser and the built-in task manager in Google Chrome may not be available. The Web-alrt-phsng-atck.xyz page is coded to make the browser refresh the page countless times. Therefore, it is not a good idea to open Web-alrt-phsng-atck.xyz. Researchers discovered that Web-alrt-phsng-atck.xyz is registered to the 74.208.236.115 IP address where several clones can be found. The following pages are known to exhibit the same problems associated with Web-alrt-phsng-atck.xyz:

  • Phsng-atck-win-crpt.xyz
  • Win-crsh-sytm-dmg.xyz
  • Act-hck-info-lost.xyz
  • Win-dmg-vrs-atck.xyz
  • Ybr-atck-vrs-inf.xyz
  • Ip-hck-win-dmg.xyz

Computer users should avoid domains related to Web-alrt-phsng-atck.xyz and contact with the fake technical support staff on the 844-592-9882 phone line. If your browser opens Web-alrt-phsng-atck.xyz as your start page, you might be infected with a browser hijacker. In that case, you should consider using a reliable anti-malware tool to delete badware that exchanges information with the 74.208.236.115 IP address.

Trending

Most Viewed

Loading...