Go Back  FlyerTalk Forums > Support&Services > Technical Support and Feedback
Reload this Page >

Malicious calls to powerpint.net on FT [Merged threads]

Community
Wiki Posts
Search

Malicious calls to powerpint.net on FT [Merged threads]

Thread Tools
 
Search this Thread
 
Old Feb 6, 2012, 10:59 am
  #1  
Original Poster
 
Join Date: Aug 2007
Location: Near SEA
Programs: UA MM, AS MVPG75K, Marriott Lifetime Gold
Posts: 7,969
Malicious code in FT ad?

I've been getting a number of TrendMicro warnings about possible malicious code when visiting FT. Believe it's related to the MileagePlus Explorer card ads.

Error below:
bmvaughn is offline  
Old Feb 6, 2012, 6:07 pm
  #2  
Original Poster
 
Join Date: Aug 2007
Location: Near SEA
Programs: UA MM, AS MVPG75K, Marriott Lifetime Gold
Posts: 7,969
Pretty much making browsing the site unusable. Happens on all Chase ads.
bmvaughn is offline  
Old Feb 6, 2012, 6:14 pm
  #3  
No longer with Internet Brands
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Is it your virus warnings that are making browsing difficult, or is it the ads themselves? What exactly is happening?
IBobi is offline  
Old Feb 6, 2012, 6:15 pm
  #4  
Original Poster
 
Join Date: Aug 2007
Location: Near SEA
Programs: UA MM, AS MVPG75K, Marriott Lifetime Gold
Posts: 7,969
Originally Posted by IBobi
Is it your virus warnings that are making browsing difficult, or is it the ads themselves? What exactly is happening?
Virus warning that pops to be Always on Top whenever I browser any FT page that has a Chase ad.
bmvaughn is offline  
Old Feb 6, 2012, 6:17 pm
  #5  
No longer with Internet Brands
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Hmm, well, not getting any other reports of this behavior. Not sure what to tell you at this point.
IBobi is offline  
Old Feb 6, 2012, 6:22 pm
  #6  
Original Poster
 
Join Date: Aug 2007
Location: Near SEA
Programs: UA MM, AS MVPG75K, Marriott Lifetime Gold
Posts: 7,969
Originally Posted by IBobi
Hmm, well, not getting any other reports of this behavior. Not sure what to tell you at this point.
I suggest having your ad reps look for redirects on the Chase ads to route via powerpint.net. Right now anyone browsing your site with Trend Micro would get this result.

You can check maliciousness here:
http://global.sitesafety.trendmicro.com/
using "powerpint.net/in.cgi?2" as the destination.
bmvaughn is offline  
Old Feb 7, 2012, 3:33 am
  #7  
 
Join Date: Oct 2009
Location: Brisbane Australia
Programs: Singapore, Cathay, QANTAS, Delta, Velocity, Etihad
Posts: 429
Originally Posted by bmvaughn
I suggest having your ad reps look for redirects on the Chase ads to route via powerpint.net. Right now anyone browsing your site with Trend Micro would get this result.

You can check maliciousness here:
http://global.sitesafety.trendmicro.com/
using "powerpint.net/in.cgi?2" as the destination.
I can confirm that this is the case!
RBH58 is offline  
Old Feb 8, 2012, 11:05 am
  #8  
Original Poster
 
Join Date: Aug 2007
Location: Near SEA
Programs: UA MM, AS MVPG75K, Marriott Lifetime Gold
Posts: 7,969
Not sure if you still have the issue... I got tired of the warning so I changed my HOSTS file.
bmvaughn is offline  
Old Feb 8, 2012, 11:12 am
  #9  
No longer with Internet Brands
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
TrendMicro warning

Hi all,

Our internal malvertising team has rescanned the ads in question (Chase) and determined that the ads are safe. Also, Google's SafeBrowsing service did not flag any of the content.

Most likely the reason it was flagged is due to differences in classification of malicious content; the website VirusTotal shows that only 1 out of 17 security sites have listed the URL mentioned here as malicious. That one security site is TrendMicro (https://www.virustotal.com/url/bd943...5b3a/analysis/).

Please let me know if we can be of any further help on this!

Paul

Last edited by IBobi; Feb 9, 2012 at 1:04 pm
IBobi is offline  
Old Feb 13, 2012, 5:13 pm
  #10  
Flyertalk Evangelist and Moderator: Coupon Connection and Travel Products
 
Join Date: Jul 2000
Location: Milton, GA USA
Programs: Hilton Diamond, IHG Platinum Elite, Hyatt Discoverist, Radisson Elite
Posts: 19,040
Malicious calls to powerpint.net on FT [Merged threads]

I am having problems browsing Flyertalk.... I am having to double click on the "Back" button on my IE browser.Used to only have to click once... and I see at the bottom of the screen a web address that has powerpint.net in the name.

That is new to me... never noticed that before.

Last edited by wharvey; Feb 14, 2012 at 3:43 pm
wharvey is offline  
Old Feb 13, 2012, 5:14 pm
  #11  
No longer with Internet Brands
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Could be ad-related; I'll check it out.
IBobi is offline  
Old Feb 14, 2012, 11:49 am
  #12  
No longer with Internet Brands
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
We're not seeing it as an ad; did you try clearing your cache?

Also is it possible it's local to your machine, i.e. a bad cookie or malware? Issue has not been reported by other users as yet.
IBobi is offline  
Old Feb 14, 2012, 3:49 pm
  #13  
Flyertalk Evangelist and Moderator: Coupon Connection and Travel Products
 
Join Date: Jul 2000
Location: Milton, GA USA
Programs: Hilton Diamond, IHG Platinum Elite, Hyatt Discoverist, Radisson Elite
Posts: 19,040
Looks like this is related to this issue I just saw in another thread:

http://www.flyertalk.com/forum/techn...ode-ft-ad.html

I tried clearing the cache... but still only getting the powerpint.net message at the bottom when on FT... and having to doble click the back button to get back to the previous page.
wharvey is offline  
Old Feb 15, 2012, 11:32 am
  #14  
No longer with Internet Brands
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Still happening?

Tech investigations see no malicious code on the site, FYI.
IBobi is offline  
Old Feb 15, 2012, 9:31 pm
  #15  
FlyerTalk Evangelist
 
Join Date: Nov 2009
Location: Northeast Kansas | Colorado Native
Programs: Amex Gold/Plat, UA *G, Hyatt Globalist, Marriott LT Gold, NEXUS, TSA Disparager Unobtanium
Posts: 21,606
Originally Posted by IBobi
Still happening?

Tech investigations see no malicious code on the site, FYI.
Had it happen to me this morning, as well as last night.
FriendlySkies is online now  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.