VO-BB - 19 YEARS OLD! Forum Index VO-BB - 19 YEARS OLD!
Where A.I. is a four-letter word.
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Strange smelling e-mail request—Graffiti Studio

 
Post new topic   Reply to topic    VO-BB - 19 YEARS OLD! Forum Index -> Chat
View previous topic :: View next topic  
Author Message
Living Culture
Contributore Level V


Joined: 14 Oct 2007
Posts: 189
Location: Taipei

PostPosted: Mon May 25, 2009 9:52 am    Post subject: Strange smelling e-mail request—Graffiti Studio Reply with quote

I just got a rather odd e-mail. I thought I'd check here, as the last time that happened, it seemed to go to a few people here too.

The first funky smell was from
Quote:
I came upon your website and I thought that we could partner very well together.

This is strange as it came to my personal e-mail which is not on my website.

I first checked the link to see if it would go where it said it would, and it that was fine. It went to http://graffittistudio.com/en/voiceover-studio.html, but as it was going there, I noticed the status at bottom of my page saying "transferring marutz.cn". Sometimes these are fine, as some big sites like yahoo subcontract other servers for content hosting. But I was suspicious of this because the site was not big enough to need extra hosts and it was a .cn(China), the site itself was a voice-over company in Eastern Europe.

I put marutz.cn directly into my browser and came up with a blocked site, so I googled it. Here is a brief description:
Quote:
Gumblar (edit:AKA Marutz) is a complex web exploit. Reportedly, it compromises websites through FTP credentials stolen from infected machines used to administer them. Once in, it appends obfuscated code to many types of files, HTML, JavaScript, PHP and even images. It also installs backdoors, for example in .htaccess, making cleaning more difficult.

The obfuscated code proceeds to infecting visitors through a method called drive-by download. More specifically, it attempts to exploit known vulnerabilities in Adobe Reader or Flash Player through malicious files served from a domain called gumblar.cn, hence its name. Recently, Sophos has reported that JSRedir-R amounts to over 40% of the infections detected on the web.


Since this specific attack was directly on the VO community, I thought I'd better share it with you. If you have had the same or similar e-mail, check your website and computer at http://www.unmaskparasites.com/[/url]
_________________
Mandarin Chinese Voiceovers & Localization
http://lcmsmedia.com
http://imagesbykenny.com/
Back to top
View user's profile Send private message Send e-mail Visit poster's website
imaginator
The Thirteenth Floor


Joined: 10 Nov 2004
Posts: 1348
Location: raleigh, nc

PostPosted: Mon May 25, 2009 11:20 am    Post subject: Reply with quote

MANY THANKS for the warning (and research) !!!

i had hesitated in answering this and am now glad i did.

once again, my "link" to the vo-bb proves the most valuable.
_________________
rowell gormon
www.voices2go.com
"Mr. Warm & Friendly Voice...with Character!"
Rowell Gormon's Clogged Blog - http://voices2go.com/blog
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Rognog
Flight Attendant


Joined: 20 Apr 2006
Posts: 807
Location: New Jersey

PostPosted: Mon May 25, 2009 11:56 am    Post subject: Reply with quote

I got the same email. Thanks for the due diligence!
_________________
Tom Dheere - The "H" is Silent, but I'm Not!
www.tomdheere.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website AIM Address
mcm
Smart Kitteh


Joined: 10 Dec 2004
Posts: 2600
Location: w. MA, USA

PostPosted: Mon May 25, 2009 6:02 pm    Post subject: Reply with quote

Hmmmm. There was actually an article about them over at Voice Over Xtra a while back. They sounded legitimate enough.
Back to top
View user's profile Send private message Visit poster's website
Living Culture
Contributore Level V


Joined: 14 Oct 2007
Posts: 189
Location: Taipei

PostPosted: Tue May 26, 2009 7:50 am    Post subject: Reply with quote

Quote:
Hmmmm. There was actually an article about them over at Voice Over Xtra a while back. They sounded legitimate enough.


Sorry, I don't think the bit of info I posted was clear enough. There is nothing bad about the company itself. The marutz or gumblar parasite uses FTP access on a website to do its deeds. This one just happened to be using Graffiti Studio, while Graffiti studio are not themselves the culprit. Thats why I suggested doing a scan if you clicked on any of the given links.

It may even be a legitimate e-mail, but they are unaware the parasite is in their system.
_________________
Mandarin Chinese Voiceovers & Localization
http://lcmsmedia.com
http://imagesbykenny.com/
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Moe Egan
4 Large


Joined: 11 Sep 2006
Posts: 4337
Location: Live Free or Die

PostPosted: Tue May 26, 2009 8:07 am    Post subject: Reply with quote

Thanks for the head's up!!!
_________________
Moe Egan
i want to be the voice in your head.
~~~~~
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Chrissy
Guest





PostPosted: Tue May 26, 2009 1:00 pm    Post subject: Reply with quote

Oh sh*te. I had signed up with Graffitti back in December, and was confused by this email so I clicked on it and left them a message. The email that was sent to me was there, and I said I confused, and wanted to make sure that they had received my demos. I asked that they give me a quick email to let me know. So far I haven't received anything from them.

I just checked on the link to unmaskparasites, and it says my site is clean.
Is there anything else I can do? Or do I just wait to see if my computer blows up??? Gasp Cry Embarrassed
Back to top
Lizden
A Zillion


Joined: 04 Dec 2006
Posts: 8856
Location: The dark recesses of my mind

PostPosted: Tue May 26, 2009 1:26 pm    Post subject: Reply with quote

I actually got the same email from Nick, and had a back & forth email chat with him over the weekend about my English/French capabilities.

I had seen the VoiceoverXtra article a while back & had meant to get in touch with them and was reminded about it when the email came in.

I haven't checked if I'm on his roster, but like I said I DID have a back & forth with him

Of course....now I'm waiting for my computer to blow up!
(Although I do have a firewall & scan running all the time.)
_________________
Liz de Nesnera O.A.V. ~ Livin' The VO Dream!
English/French Bilingual VO w/ ISDN
HireLiz.com / liz@hireliz.com
Back to top
View user's profile Send private message Send e-mail Visit poster's website
ConnieTerwilliger
Triple G


Joined: 07 Dec 2004
Posts: 3381
Location: San Diego - serving the world

PostPosted: Sun May 31, 2009 10:48 am    Post subject: Reply with quote

As I remember, the first time I tried to email Nick - after the VoiceoverXtra article, the email bounced - and I just haven't had time to get back on that horse.

Too busy trying to dry out my BlackBerry - I decided it needed a drink of water last night and it hasn't been the same since. (Well, I decided I needed a drink of water and didn't wait for the Brita filter to actually filter the water before trying to pour it into a glass.)

I have it in the oven right now - the screen comes on and I can roll over the icons using the roller ball, but it won't actually "click" on anything.

Waaaaa - no insurance of course.
_________________
Playing for a living...
www.voiceover-talent.com
YouTube Channel: http://youtube.com/connieterwilliger
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Lee Gordon
A Zillion


Joined: 25 Jul 2008
Posts: 6844
Location: West Hartford, CT

PostPosted: Sun May 31, 2009 12:22 pm    Post subject: Reply with quote

ConnieTerwilliger wrote:
I have it in the oven right now


So, you making Blackberry cobbler or something? Sarcastic
_________________
Lee Gordon, O.A.V.
Voice President of the United States
www.leegordonproductions.com
Twitter: @LeeGordonVoice
Back to top
View user's profile Send private message Visit poster's website
Yoda117
M&M


Joined: 20 Dec 2006
Posts: 2362
Location: Philadelphia, Pennsylvania

PostPosted: Sun May 31, 2009 10:12 pm    Post subject: Reply with quote

Folks, just because your website comes back clean, doesn't mean that your computer is. Run a good malware and AV aHobo Tounge on your computer if you're concerned (and you should be). If there's a cyber nasty on their site, it'll infect your computer long before it goes for your site.

I got the same e-mail last week, but for me I wasn't so concerned by the .cn address while the page was loading at first because they might be using it for his hosting, DNS, etc., and the links in the e-mail weren't re-directs.

However, my browser detected that some scripts were trying to be loaded by the site onto my system (not uncommon), but I didn't recognize them and the code was obfuscated (that's not common). Brings me to the same conclusion as most others.

Despite noticing on my logs that someone from the same city had spent time on my site, it looked like a form e-mail and I hadn't seen any activity on any of the recording sites where someone like this might have gone, established a reputation, etc. I also asked some of their clients whom I've done work with in the past and they heard of them either.

Looked like either a cold-call to be added to their library list like so many other sites, or something more based on some of the scripts I'd seen. Regardless of whether it's a cold-call, or if someone has put a "value added feature" on the site that might cause damage to your computer, the fact that most of us haven't heard or worked with these folks is enough for me to ignore the e-mail for now (especially with the red flags we've seen so far).
_________________
Voiceovers by Gregory Houser
Philadelphia based Voice Actor

Blog - A man, a martini, and a lot of microphones
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic    VO-BB - 19 YEARS OLD! Forum Index -> Chat All times are GMT - 7 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2005 phpBB Group