Fake Virus Warning Targets Mac Users to Download MacKeeper

macoscheckdotcom scam site

I received a frantic message from a friend when she saw a message that “virus found” on her Mac. She then sent me a few photos of the message.

macoscheckdotcom scam site fake virus check

As it turns out, it is related to none other than MacKeeper. In January2014, a class action lawsuit was filed against ZeoBIT, the maker of MacKeeper.

“macoscheck.com” was registered on December 26, 2015.

Whois info on macoscheck.com:

Deus-ex-Mac:~ ultra-slacker$ whois macoscheck.com

Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered

with many different competing registrars. Go to http://www.internic.net

for detailed information.

Domain Name: MACOSCHECK.COM

Registrar: INTERNET DOMAIN SERVICE BS CORP

Sponsoring Registrar IANA ID: 2487

Whois Server: whois.internet.bs

Referral URL: http://www.internetbs.net

Name Server: NS1.SPEEDLOADINGSERVER.COM

Name Server: NS2.SPEEDLOADINGSERVER.COM

Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited

Updated Date: 26-dec-2015

Creation Date: 26-dec-2015

Expiration Date: 26-dec-2016

>>> Last update of whois database: Wed, 06 Jan 2016 11:49:01 GMT <<<

For more information on Whois status codes, please visit

https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en.

NOTICE: The expiration date displayed in this record is the date the

registrar’s sponsorship of the domain name registration in the registry is

currently set to expire. This date does not necessarily reflect the expiration

date of the domain name registrant’s agreement with the sponsoring

registrar. Users may consult the sponsoring registrar’s Whois database to

view the registrar’s reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois

database through the use of electronic processes that are high-volume and

automated except as reasonably necessary to register domain names or

modify existing registrations; the Data in VeriSign Global Registry

Services’ (“VeriSign”) Whois database is provided by VeriSign for

information purposes only, and to assist persons in obtaining information

about or related to a domain name registration record. VeriSign does not

guarantee its accuracy. By submitting a Whois query, you agree to abide

by the following terms of use: You agree that you may use this Data only

for lawful purposes and that under no circumstances will you use this Data

to: (1) allow, enable, or otherwise support the transmission of mass

unsolicited, commercial advertising or solicitations via e-mail, telephone,

or facsimile; or (2) enable high volume, automated, electronic processes

that apply to VeriSign (or its computer systems). The compilation,

repackaging, dissemination or other use of this Data is expressly

prohibited without the prior written consent of VeriSign. You agree not to

use electronic processes that are automated and high-volume to access or

query the Whois database except as reasonably necessary to register

domain names or modify existing registrations. VeriSign reserves the right

to restrict your access to the Whois database in its sole discretion to ensure

operational stability. VeriSign may restrict or terminate your access to the

Whois database for failure to abide by these terms of use. VeriSign

reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and

Registrars.

Domain Name: MACOSCHECK.COM

Registry Domain ID: 1989721914_DOMAIN_COM-VRSN

Registrar WHOIS Server: whois.internet.bs

Registrar URL: http://www.internetbs.net

Updated Date: 2015-12-26T12:22:03Z

Creation Date: 2015-12-26T12:22:03Z

Registrar Registration Expiration Date: 2016-12-26T12:22:03Z

Registrar: Internet Domain Service BS Corp.

Registrar IANA ID: 2487

Registrar Abuse Contact Email: abuse@internet.bs

Registrar Abuse Contact Phone: +44.7546458118

Reseller:

Domain Status: clientTransferProhibited – http://www.icann.org/epp#clientTransferProhibited

Registry Registrant ID:

Registrant Name: Domain Admin

Registrant Organization: Whois Privacy Corp.

Registrant Street: Ocean Centre, Montagu Foreshore, East Bay Street

Registrant City: Nassau

Registrant State/Province: New Providence

Registrant Postal Code: 0000

Registrant Country: BS

Registrant Phone: +1.5163872248

Registrant Phone Ext:

Registrant Fax:

Registrant Fax Ext:

Registrant Email: macoscheck.com-owner@customers.whoisprivacycorp.com

Registry Admin ID:

Admin Name: Domain Admin

Admin Organization: Whois Privacy Corp.

Admin Street: Ocean Centre, Montagu Foreshore, East Bay Street

Admin City: Nassau

Admin State/Province: New Providence

Admin Postal Code: 0000

Admin Country: BS

Admin Phone: +1.5163872248

Admin Phone Ext:

Admin Fax:

Admin Fax Ext:

Admin Email: macoscheck.com-admin@customers.whoisprivacycorp.com

Registry Tech ID:

Tech Name: Domain Admin

Tech Organization: Whois Privacy Corp.

Tech Street: Ocean Centre, Montagu Foreshore, East Bay Street

Tech City: Nassau

Tech State/Province: New Providence

Tech Postal Code: 0000

Tech Country: BS

Tech Phone: +1.5163872248

Tech Phone Ext:

Tech Fax:

Tech Fax Ext:

Tech Email: macoscheck.com-tech@customers.whoisprivacycorp.com

Name Server: ns1.speedloadingserver.com

Name Server: ns2.speedloadingserver.com

DNSSEC: unsigned

URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/

>>> Last update of WHOIS database: 2016-01-06T11:49:10Z <<<

Whois info on speedloadingserver.com:

Deus-ex-Mac:~ ultra-slacker$ whois speedloadingserver.com

Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered

with many different competing registrars. Go to http://www.internic.net

for detailed information.

Domain Name: SPEEDLOADINGSERVER.COM

Registrar: TLD REGISTRAR SOLUTIONS LTD

Sponsoring Registrar IANA ID: 1564

Whois Server: whois.tldregistrarsolutions.com

Referral URL: http://www.tldregistrarsolutions.com

Name Server: NS-CANADA.TOPDNS.COM

Name Server: NS-UK.TOPDNS.COM

Name Server: NS-USA.TOPDNS.COM

Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited

Updated Date: 09-sep-2015

Creation Date: 03-sep-2015

Expiration Date: 03-sep-2016

>>> Last update of whois database: Wed, 06 Jan 2016 12:17:54 GMT <<<

For more information on Whois status codes, please visit

https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en.

NOTICE: The expiration date displayed in this record is the date the

registrar’s sponsorship of the domain name registration in the registry is

currently set to expire. This date does not necessarily reflect the expiration

date of the domain name registrant’s agreement with the sponsoring

registrar. Users may consult the sponsoring registrar’s Whois database to

view the registrar’s reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois

database through the use of electronic processes that are high-volume and

automated except as reasonably necessary to register domain names or

modify existing registrations; the Data in VeriSign Global Registry

Services’ (“VeriSign”) Whois database is provided by VeriSign for

information purposes only, and to assist persons in obtaining information

about or related to a domain name registration record. VeriSign does not

guarantee its accuracy. By submitting a Whois query, you agree to abide

by the following terms of use: You agree that you may use this Data only

for lawful purposes and that under no circumstances will you use this Data

to: (1) allow, enable, or otherwise support the transmission of mass

unsolicited, commercial advertising or solicitations via e-mail, telephone,

or facsimile; or (2) enable high volume, automated, electronic processes

that apply to VeriSign (or its computer systems). The compilation,

repackaging, dissemination or other use of this Data is expressly

prohibited without the prior written consent of VeriSign. You agree not to

use electronic processes that are automated and high-volume to access or

query the Whois database except as reasonably necessary to register

domain names or modify existing registrations. VeriSign reserves the right

to restrict your access to the Whois database in its sole discretion to ensure

operational stability. VeriSign may restrict or terminate your access to the

Whois database for failure to abide by these terms of use. VeriSign

reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and

Registrars.

Domain Name: SPEEDLOADINGSERVER.COM

Registry Domain ID: 1957177560_DOMAIN_COM-VRSN

Registrar WHOIS Server: whois.tldregistrarsolutions.com

Registrar URL: http://www.tldregistrarsolutions.com

Updated Date: 2015-09-09T07:28:32Z

Creation Date: 2015-09-03T07:26:31Z

Registrar Registration Expiration Date: 2016-09-03T07:26:31Z

Registrar: TLD Registrar Solutions Ltd.

Registrar IANA ID: 1564

Registrar Abuse Contact Email: abuse@tldregistrarsolutions.com

Registrar Abuse Contact Phone: +44.2034357312

Reseller:

Domain Status: clientTransferProhibited – http://www.icann.org/epp#clientTransferProhibited

Registry Registrant ID:

Registrant Name: Domain Admin

Registrant Organization: Whois Privacy Corp.

Registrant Street: Ocean Centre, Montagu Foreshore, East Bay Street

Registrant City: Nassau

Registrant State/Province: New Providence

Registrant Postal Code: 0000

Registrant Country: BS

Registrant Phone: +1.5163872248

Registrant Phone Ext:

Registrant Fax:

Registrant Fax Ext:

Registrant Email: speedloadingserver.com-owner@customers.whoisprivacycorp.com

Registry Admin ID:

Admin Name: Domain Admin

Admin Organization: Whois Privacy Corp.

Admin Street: Ocean Centre, Montagu Foreshore, East Bay Street

Admin City: Nassau

Admin State/Province: New Providence

Admin Postal Code: 0000

Admin Country: BS

Admin Phone: +1.5163872248

Admin Phone Ext:

Admin Fax:

Admin Fax Ext:

Admin Email: speedloadingserver.com-admin@customers.whoisprivacycorp.com

Registry Tech ID:

Tech Name: Domain Admin

Tech Organization: Whois Privacy Corp.

Tech Street: Ocean Centre, Montagu Foreshore, East Bay Street

Tech City: Nassau

Tech State/Province: New Providence

Tech Postal Code: 0000

Tech Country: BS

Tech Phone: +1.5163872248

Tech Phone Ext:

Tech Fax:

Tech Fax Ext:

Tech Email: speedloadingserver.com-tech@customers.whoisprivacycorp.com

Name Server: ns-canada.topdns.com

Name Server: ns-uk.topdns.com

Name Server: ns-usa.topdns.com

DNSSEC: unsigned

URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/

>>> Last update of WHOIS database: 2016-01-06T12:16:03Z <<<

OS X 10.10.2 Update

OS X Update 10.10.2

Apple releases OS X 10.10.2 Update build 14C109.

About the update

  • This update includes the following improvements:
  • Resolves an issue that might cause Wi-Fi to disconnect
  • Resolves an issue that might cause web pages to load slowly
  • Fixes an issue that could cause Spotlight to load remote email content when this preference is disabled in Mail
  • Improves audio and video sync when using Bluetooth headphones
  • Adds the ability to browse iCloud Drive in Time Machine
  • Improves VoiceOver speech performance
  • Resolves an issue that could cause VoiceOver to echo characters when entering text on a web page
  • Addresses an issue that could cause the input method to switch languages unexpectedly
  • Improves stability and security in Safari

Enterprise content

For enterprise customers, this update:

  • Improves performance for browsing DFS shares in the Finder
  • Fixes an issue where certain Calendar invitations could be displayed at the incorrect time
  • Fixes an issue for Microsoft Exchange accounts where the organizer of a meeting might not be notified when someone accepts an invitation using Calendar
  • Addresses an issue where Safari could continually prompt for credentials when accessing a site protected by NTLM authentication
  • Adds the ability to set “Out of Office” reply dates for Microsoft Exchange accounts in Mail

Security Content

This update is said to include fix against “Thunderstrike” (via iMore).

One thing I noticed with the pre-release build, the computer was no longer incremented. The last time it happened my MacBook Pro was named “Deus ex Macintosh (13)”.

Apple Issues Patch for Critical NTP Vulnerability

Apple NTP Security Update 20141222

Apple issues OS X NTP Security Update for Mountain LionMavericks and Yosemite.

OS X NTP Security Update
ntpd

Available for: OS X Mountain Lion v10.8.5, OS X Mavericks v10.9.5, OS X Yosemite v10.10.1

Impact: A remote attacker may be able to execute arbitrary code

Description: Several issues existed in ntpd that would have allowed an attacker to trigger buffer overflows. These issues were addressed through improved error checking.

To verify the ntpd version, type the following command in Terminal: what /usr/sbin/ntpd. This update includes the following versions:

Mountain Lion: ntp-77.1.1
Mavericks: ntp-88.1.1
Yosemite: ntp-92.5.1

CVE-ID

CVE-2014-9295 : Stephen Roettger of the Google Security Team

From ICS-CERT:

Google Security Team researchers Neel Mehta and Stephen Roettger have coordinated multiple vulnerabilities with CERT/CC concerning the Network Time Protocol (NTP). As NTP is widely used within operational Industrial Control Systems deployments, NCCIC/ICS-CERT is providing this information for US Critical Infrastructure asset owners and operators for awareness and to identify mitigations for affected devices. ICS-CERT may release updates as additional information becomes available.

These vulnerabilities could be exploited remotely. Exploits that target these vulnerabilities are publicly available.

Products using NTP service prior to NTP-4.2.8 are affected. No specific vendor is specified because this is an open source protocol.

Ars Technica Asks Readers to Change Password Following Security Breach

Ars Technica

Due to the recent hack on the website, Ars Technica “strongly encourages all Ars readers — especially any who have reused their Ars passwords on other, more sensitive sites — to change their passwords today.”

Full Email:

Ars Technica was hacked: Please change your password

You are receiving this email because you may have – at some point – registered as a user on ArsTechnica.com. Our site was recently hacked.

Log files suggest that this intruder had the opportunity to copy the user database. This database contains no payment information on Ars subscribers, but it does contain user e-mail addresses cryptographically-protected passwords.

Out of an excess of caution, we strongly encourage all Ars readers — especially any who have reused their Ars passwords on other, more sensitive sites — to change their passwords today.

Read more about the incident here: http://arstechnica.com/staff/2014/12/ars-was-briefly-hacked-yesterday-heres-what-we-know/

Please login to Ars and update your password or use the “Forgot your password” form to change your password.

Settings page: https://arstechnica.com/civis/ucp.php?i=profile&mode=reg_details

Forgot your password? https://arstechnica.com/civis/ucp.php?mode=sendpassword

We sincerely apologize for any inconvenience this has caused.

– Ars

To paraphrase Al Bundy: “Hey! Come to think of it, I remember creating an account at Ars Technica.”

What The Hell, Twitter?

Twitter App Graph

Jack Marshall, writing for WSJ.com:

Twitter is now collecting information about the apps installed on users’ devices in order to better target and tailor advertising and other content to them.

WHAT?!

From Twitter:

To help build a more personal Twitter experience for you, we are collecting and occasionally updating the list of apps installed on your mobile device so we can deliver tailored content that you might be interested in.

DFQ?!

If you’re not interested in a tailored experience you can adjust your preferences at any time (read below). Additionally, if you have previously opted out of interest-based ads by turning on “Limit Ad Tracking” on your iOS device or by adjusting your Android device settings to “Opt out of interest-based ads,” we will not collect your apps unless you adjust your device settings.

I have always enabled the “Limit Ad Tracking” option on all of my iOS devices.

iOS Privacy Settings: Limit Ad Tracking

WordPress 4.0.1

Welcome to WordPress 4.0.1

WordPress 4.0.1 is out now.

  • Three cross-site scripting issues that a contributor or author could use to compromise a site. Discovered by Jon Cave, Robert Chapin, and John Blackbourn of the WordPress security team.
  • A cross-site request forgery that could be used to trick a user into changing their password.
  • An issue that could lead to a denial of service when passwords are checked. Reported by Javier Nieto Arevalo and Andres Rojas Guerrero.
  • Additional protections for server-side request forgery attacks when WordPress makes HTTP requests. Reported by Ben Bidner (vortfu).
  • An extremely unlikely hash collision could allow a user’s account to be compromised, that also required that they haven’t logged in since 2008 (I wish I were kidding). Reported by David Anderson.
  • WordPress now invalidates the links in a password reset email if the user remembers their password, logs in, and changes their email address. Reported separately by Momen Bassel, Tanoy Bose, and Bojan Slavković of ManageWP.

I would say that it is mandatory to update your WordPress installation, because of these important security fixes.