View previous topic :: View next topic |
Author |
Message |
Living Culture Contributore Level V

Joined: 14 Oct 2007 Posts: 189 Location: Taipei
|
Posted: Mon May 25, 2009 9:52 am Post subject: Strange smelling e-mail request—Graffiti Studio |
|
|
I just got a rather odd e-mail. I thought I'd check here, as the last time that happened, it seemed to go to a few people here too.
The first funky smell was from
Quote: | I came upon your website and I thought that we could partner very well together.
|
This is strange as it came to my personal e-mail which is not on my website.
I first checked the link to see if it would go where it said it would, and it that was fine. It went to http://graffittistudio.com/en/voiceover-studio.html, but as it was going there, I noticed the status at bottom of my page saying "transferring marutz.cn". Sometimes these are fine, as some big sites like yahoo subcontract other servers for content hosting. But I was suspicious of this because the site was not big enough to need extra hosts and it was a .cn(China), the site itself was a voice-over company in Eastern Europe.
I put marutz.cn directly into my browser and came up with a blocked site, so I googled it. Here is a brief description:
Quote: | Gumblar (edit:AKA Marutz) is a complex web exploit. Reportedly, it compromises websites through FTP credentials stolen from infected machines used to administer them. Once in, it appends obfuscated code to many types of files, HTML, JavaScript, PHP and even images. It also installs backdoors, for example in .htaccess, making cleaning more difficult.
The obfuscated code proceeds to infecting visitors through a method called drive-by download. More specifically, it attempts to exploit known vulnerabilities in Adobe Reader or Flash Player through malicious files served from a domain called gumblar.cn, hence its name. Recently, Sophos has reported that JSRedir-R amounts to over 40% of the infections detected on the web. |
Since this specific attack was directly on the VO community, I thought I'd better share it with you. If you have had the same or similar e-mail, check your website and computer at http://www.unmaskparasites.com/[/url] _________________ Mandarin Chinese Voiceovers & Localization
http://lcmsmedia.com
http://imagesbykenny.com/ |
|
Back to top |
|
 |
imaginator The Thirteenth Floor

Joined: 10 Nov 2004 Posts: 1348 Location: raleigh, nc
|
Posted: Mon May 25, 2009 11:20 am Post subject: |
|
|
MANY THANKS for the warning (and research) !!!
i had hesitated in answering this and am now glad i did.
once again, my "link" to the vo-bb proves the most valuable. _________________ rowell gormon
www.voices2go.com
"Mr. Warm & Friendly Voice...with Character!"
Rowell Gormon's Clogged Blog - http://voices2go.com/blog |
|
Back to top |
|
 |
Rognog Flight Attendant

Joined: 20 Apr 2006 Posts: 807 Location: New Jersey
|
Posted: Mon May 25, 2009 11:56 am Post subject: |
|
|
I got the same email. Thanks for the due diligence! _________________ Tom Dheere - The "H" is Silent, but I'm Not!
www.tomdheere.com |
|
Back to top |
|
 |
mcm Smart Kitteh

Joined: 10 Dec 2004 Posts: 2600 Location: w. MA, USA
|
Posted: Mon May 25, 2009 6:02 pm Post subject: |
|
|
Hmmmm. There was actually an article about them over at Voice Over Xtra a while back. They sounded legitimate enough. |
|
Back to top |
|
 |
Living Culture Contributore Level V

Joined: 14 Oct 2007 Posts: 189 Location: Taipei
|
Posted: Tue May 26, 2009 7:50 am Post subject: |
|
|
Quote: | Hmmmm. There was actually an article about them over at Voice Over Xtra a while back. They sounded legitimate enough. |
Sorry, I don't think the bit of info I posted was clear enough. There is nothing bad about the company itself. The marutz or gumblar parasite uses FTP access on a website to do its deeds. This one just happened to be using Graffiti Studio, while Graffiti studio are not themselves the culprit. Thats why I suggested doing a scan if you clicked on any of the given links.
It may even be a legitimate e-mail, but they are unaware the parasite is in their system. _________________ Mandarin Chinese Voiceovers & Localization
http://lcmsmedia.com
http://imagesbykenny.com/ |
|
Back to top |
|
 |
Moe Egan 4 Large

Joined: 11 Sep 2006 Posts: 4339 Location: Live Free or Die
|
Posted: Tue May 26, 2009 8:07 am Post subject: |
|
|
Thanks for the head's up!!! _________________ Moe Egan
i want to be the voice in your head.
~~~~~ |
|
Back to top |
|
 |
Chrissy Guest
|
Posted: Tue May 26, 2009 1:00 pm Post subject: |
|
|
Oh sh*te. I had signed up with Graffitti back in December, and was confused by this email so I clicked on it and left them a message. The email that was sent to me was there, and I said I confused, and wanted to make sure that they had received my demos. I asked that they give me a quick email to let me know. So far I haven't received anything from them.
I just checked on the link to unmaskparasites, and it says my site is clean.
Is there anything else I can do? Or do I just wait to see if my computer blows up???  |
|
Back to top |
|
 |
Lizden A Zillion

Joined: 04 Dec 2006 Posts: 8864 Location: The dark recesses of my mind
|
Posted: Tue May 26, 2009 1:26 pm Post subject: |
|
|
I actually got the same email from Nick, and had a back & forth email chat with him over the weekend about my English/French capabilities.
I had seen the VoiceoverXtra article a while back & had meant to get in touch with them and was reminded about it when the email came in.
I haven't checked if I'm on his roster, but like I said I DID have a back & forth with him
Of course....now I'm waiting for my computer to blow up!
(Although I do have a firewall & scan running all the time.) _________________ Liz de Nesnera O.A.V. ~ Livin' The VO Dream!
English/French Bilingual VO w/ ISDN
HireLiz.com / liz@hireliz.com |
|
Back to top |
|
 |
ConnieTerwilliger Triple G

Joined: 07 Dec 2004 Posts: 3381 Location: San Diego - serving the world
|
Posted: Sun May 31, 2009 10:48 am Post subject: |
|
|
As I remember, the first time I tried to email Nick - after the VoiceoverXtra article, the email bounced - and I just haven't had time to get back on that horse.
Too busy trying to dry out my BlackBerry - I decided it needed a drink of water last night and it hasn't been the same since. (Well, I decided I needed a drink of water and didn't wait for the Brita filter to actually filter the water before trying to pour it into a glass.)
I have it in the oven right now - the screen comes on and I can roll over the icons using the roller ball, but it won't actually "click" on anything.
Waaaaa - no insurance of course. _________________ Playing for a living...
www.voiceover-talent.com
YouTube Channel: http://youtube.com/connieterwilliger |
|
Back to top |
|
 |
Lee Gordon A Zillion

Joined: 25 Jul 2008 Posts: 6864 Location: West Hartford, CT
|
Posted: Sun May 31, 2009 12:22 pm Post subject: |
|
|
ConnieTerwilliger wrote: | I have it in the oven right now |
So, you making Blackberry cobbler or something?  _________________ Lee Gordon, O.A.V.
Voice President of the United States
www.leegordonproductions.com
Twitter: @LeeGordonVoice
 |
|
Back to top |
|
 |
Yoda117 M&M

Joined: 20 Dec 2006 Posts: 2362 Location: Philadelphia, Pennsylvania
|
Posted: Sun May 31, 2009 10:12 pm Post subject: |
|
|
Folks, just because your website comes back clean, doesn't mean that your computer is. Run a good malware and AV a on your computer if you're concerned (and you should be). If there's a cyber nasty on their site, it'll infect your computer long before it goes for your site.
I got the same e-mail last week, but for me I wasn't so concerned by the .cn address while the page was loading at first because they might be using it for his hosting, DNS, etc., and the links in the e-mail weren't re-directs.
However, my browser detected that some scripts were trying to be loaded by the site onto my system (not uncommon), but I didn't recognize them and the code was obfuscated (that's not common). Brings me to the same conclusion as most others.
Despite noticing on my logs that someone from the same city had spent time on my site, it looked like a form e-mail and I hadn't seen any activity on any of the recording sites where someone like this might have gone, established a reputation, etc. I also asked some of their clients whom I've done work with in the past and they heard of them either.
Looked like either a cold-call to be added to their library list like so many other sites, or something more based on some of the scripts I'd seen. Regardless of whether it's a cold-call, or if someone has put a "value added feature" on the site that might cause damage to your computer, the fact that most of us haven't heard or worked with these folks is enough for me to ignore the e-mail for now (especially with the red flags we've seen so far). _________________ Voiceovers by Gregory Houser
Philadelphia based Voice Actor
Blog - A man, a martini, and a lot of microphones |
|
Back to top |
|
 |
|