Protect yourself from PayPal phishing attacks: Learn to spot the signs of a spoofed email and avoid falling for scams that use legitimate PayPal accounts to deceive unsuspecting victims.
PayPal has been one of the most lucrative targets for hackers and spammers which is why customers often complain about phishing scams. Now, the cybersecurity researchers at Avanan have discovered that cybercriminals are once again exploiting PayPal’s online payment system to send malicious invoices directly to users.
In the ongoing campaign, attackers are reportedly abusing PayPal by creating accounts and generating invoices for sending phishing emails. This should not come as a surprise, as just last month, PayPal notified over 35,000 customers about a security breach, which goes to show the popularity of PayPal among cyber criminals.
Email Content Analysis
The email informs the recipient about fraudulent activity on their account, and if they do not call the listed number, they will be charged a hefty amount, such as $699.99 or more.
It is worth noting that the emails sent in this campaign are not malicious; they are sent directly via PayPal and can pass several checks, such as DMARC, DKIM, and SPF. The problem is that these emails are sent from service@paypal.com, so they appear legitimate, and users fail to identify the trap.
The phishing invoice (Credit: Avanan)
Additionally, in a blog post, Jeremy Fuchs of Avanan stated that the scam works because of static email Allow Lists, which allow content to go directly into the inbox if it arrives from a reputable service like PayPal.
Why is PayPal being Targeted?
The reason PayPal is so easily targeted in this campaign is that the platform allows users to create accounts easily. Therefore, anyone can exploit the free service. Furthermore, threat actors can use PayPal’s tools to create professional-looking malicious invoices. This way, attackers can easily disguise themselves as employers or family members.
How Can You Detect Malicious Invoices?
This campaign is different from other attacks leveraging PayPal, as detecting or preventing the attack proved to be very difficult for email security services and users. It happened because the malicious invoices “comes directly from PayPal.”
However, according to Jeremy Fuchs, marketing content manager at Avanan, the email’s content is such that it can raise suspicion. For instance, the content has many grammar and spelling errors.
Moreover, the phone number listed in the email does not belong to PayPal. Fuchs suggests that users should call the phone numbers to find out whether the invoice is legitimate or not.
Here are some additional steps you can take to detect and protect yourself from PayPal phishing emails:
Google the content of the email before responding: It is always a good idea to Google the content and email address of the email that you suspect is a phishing one; it is quite possible that someone has already addressed the issue on discussion forums.
Look for spelling and grammar mistakes: Phishing emails often contain spelling and grammar mistakes. Be especially wary of emails that contain urgent requests or threats, as scammers often use these tactics to create a sense of urgency and panic.
Don’t click on any links: If an email asks you to click on a link to verify your account or update your information, don’t click on it. Instead, go directly to the PayPal website and log in to your account to see if there are any alerts or messages.
Never enter personal information: Never enter your personal or financial information in response to an email. PayPal will never ask you to provide sensitive information such as your password, Social Security number, or credit card details via email.
Use two-factor authentication: Enable two-factor authentication on your PayPal account to add an extra layer of security. This will require you to enter a code sent to your phone or another device in addition to your password when logging in to your account.
Report suspicious emails: If you receive a suspicious email, report it to PayPal immediately. Forward the email to phishing@paypal.com and then delete it from your inbox.
The Vivo X90 Pro is one of those phones that feature a 1-inch camera sensor. There are not many of them out there. That sensor, on its own, is great, but in this phone, it gets backing from both Vivo’s image processing, and ZEISS optics and expertise. The end results are… spoiler alert… outstanding. I had to open this intro with a camera-focused, there’s no other way to do it. The Vivo X90 Pro, of course, has a lot more going for it than just its camera setup, even though that is the highlight of this phone, and we’re here to review it to give you a better idea of what you’ll be dealing with, should you choose to buy it.
The Vivo X90 Pro is the company’s global flagship smartphone. An even more powerful Vivo X90 Pro+ also launched in China, but unfortunately not globally. The good news is, those two phones are very similar. The bad news is, the Snapdragon 8 Gen 2 is exclusive to the Vivo X90 Pro+, and so is the periscope telephoto camera. That aside, the same 1-inch camera is included in both phones, and the MediaTek Dimensity 9200 that fuels this phone is also excellent. So, let’s get started, there’s a lot of ground to cover.
Table of contents
Vivo X90 Pro Review: Hardware / Design
The first thing I thought to myself when I took this phone into my hand is… this is a larger variant of the Vivo X60 Pro+. It feels very similar to that phone, and that’s a good thing. It feels really good in the hand, unlike the Vivo X80 Pro which felt a lot larger (even though it barely was), and a bit more awkward to hold. The vegan leather backplate does help with the grip, which is always preferred when it comes to large phones, in my opinion. Vegan leather does become even a bit grippier after you use the phone for some time, without the case, of course.
Only one color is available outside of China
There is only one color this phone is available in, globally, the ‘Legendary Black’ color. That is essentially a dark gray model. The ‘Red’ color option is available in China only, at least for now. Its front and back sides are proportional, as both of them curve into the aluminum frame. Yes, the display is curved on the phone, and the bezels are quite minimal. There is also a centered display camera hole at the top. All the physical buttons sit on the right-hand side, and the device includes an in-display fingerprint scanner. More on that soon.
It has a large, circular camera island on the back
There is a huge circular camera module on the back, which hides three cameras. The main camera utilizes a 1-inch sensor from Sony, which we’ll talk more about in the camera section. ZEISS branding is visible on the back as well, as is Vivo’s. The company also decided to place a metallic line with an “Xtreme Imagination” caption under the camera module, to separate the top and bottom parts of the phone, in a way. The design does look much better in person, than it does in renders. This design won’t be everyone’s cup of tea, but the phone feels premium, sits well in the hand, and it’s less slippery than metal+glass slabs. I, personally, don’t have any complaints, as Vivo made the phone feel more compact than it is.
Accessories
The Vivo X90 Pro we received comes with an included silicone case. You may have seen some models come with a vegan leather case that comes with the same design as the back of the phone. I’m not sure if that’s reserved for the Vivo X90 Pro+ model in China only, or does it come with the Red Vivo X90 Pro model as well. It was not included in this packaging, however, that’s all I can say.
Vivo X90 Pro Review: Display
The Vivo X90 Pro features a gorgeous display, which is also large at the same time. It features a 6.78-inch 2800 x 1260 AMOLED display. This panel can project up to 1 billion colors, and has a 120Hz refresh rate (yes, it’s an LTPO panel). It supports HDR10+ content, and gets up to 1,300 nits of peak brightness. It has a 20:9 display aspect ratio, in case you were wondering, and the display is curved.
The display defaults to fullHD+ mode, and it’s really good
Now, the panel itself looks gorgeous. It’s plenty sharp, even in fullHD+ regular mode that the phone defaults to. You wouldn’t be able to tell the difference, to be quite honest. The colors are vivid, and the viewing angles are excellent too. You will be able to see some hazing on the sides because of the curves, though, when you look at the display straight on. The display is curved to that point, unfortunately. Also, we know that the Gorilla Glass protects the display, but we don’t know the exact iteration.
The scrolling is smooth, though the touch sampling rate could be higher
This panel is exceptionally adapted to this phone. The scrolling is buttery smooth, and the animations are also excellent. I did speed them up a bit, and they worked perfectly fine before and after that tweak. The touch response is also really good, but I wish Vivo went with at least a 480Hz touch sampling rate, and not 300Hz. The difference is noticeable if you’ve used higher touch sampling rate that’s for sure. If not, this will make no difference to you whatsoever. The only thing I wish for is higher brightness, to be quite honest. It’s perfectly fine and bright enough, until you get under direct sunlight. Oh, and yes, AOD (Always-On Display) mode is also available.
You can tweak this display to your liking, with ease
Vivo also gives you the ability to tweak the display to your liking. You can adjust the color temperature manually, or select one of the pre-loaded modes. If you prefer more vivid colors, that’s not a problem. If you’d like realism… the same thing, Vivo has you covered. The default setting is really good, though, so no worries if you’re not into making such changes.
Vivo X90 Pro Review: Performance
Alright, so… the specs. The Vivo X90 Pro is an immensely powerful smartphone, on paper. It doesn’t include the Snapdragon 8 Gen 2 SoC, as its ‘Plus’ sibling in China, but it comes with the MediaTek Dimensity 9200 SoC. That is MediaTek’s most powerful offering now, and it’s immensely powerful. It was my first phone with that chip, and quite frankly, I’m not really missing the Snapdragon 8 Gen 2 as far as performance is concerned. More on that soon.
You’re getting both LPDDR5X RAM & UFS 4.0 flash storage here
Vivo also stuffed 12GB of LPDDR5X RAM inside this phone, along with 256GB UFS 4.0 flash storage (that’s the only model available globally). In other words, the company didn’t really skimp out on RAM or storage. These are the latest modules available. Those two, in combination with the aforementioned SoC, keep this phone running smoothly at all times. It doesn’t really matter if you’re using it for multitasking, multimedia consumption, or gaming… it runs really smooth.
It can run even the most demanding games on Android
Even if you end up running the most intensive titles for Android, this phone won’t break a sweat. It’ll get warm at one point, but not hot, nor will that impact performance at all. Vivo thought about cooling here, and it did a great job in that regard. Truth be said, we can’t really say the Snapdragon 8 Gen 2 and MediaTek Dimensity 9200 apart in day-to-day performance. MediaTek’s chip does benchmark lower than the Snapdragon 8 Gen 2 SoC, but you won’t really feel the difference in day-to-day usage. This thing can even run Genshin Impact at the highest settings available, so… there you have it.
Vivo X90 Pro Review: Battery
Let’s get the spec details out of the way first, shall we. The Vivo X90 Pro comes with a 4,870mAh battery on the inside. It supports 120W wired charging, and a 120W charging brick is included in the retail box. The device also offers support for 50W wireless charging, though you’ll have to get a wireless charger separately, of course. On top of all that, reverse wired charging is also supported in case you need to charge up your earbuds on the go, or something like that.
The battery life is really good, but it could be even better
Having said that, what’s the battery life like? Well, it’s really good, though not outstanding like we’ve seen on some other flagship phones lately, as the Snapdragon 8 Gen 2 seems to have great power consumption control. I was able to get between 6-7 hours of screen-on-time during my usage, I even hit 7.5 once or twice. The first few days, I was closer to 5.5-6 hours because YouTube was draining power for some reason. Since I restricted its activity in the background, the battery life did improve, and I was getting around 6.5-7 hours of screen-on-time.
Do note that I’m not gaming on my phone, but I’m editing images, watching plenty of YouTube, taking tons of pictures, browsing, messaging, emailing… basically everything else you can imagine. Another thing to note is that I spend the vast majority of my day on WiFi, as do most of you, probably. Your mileage may vary, though, of course. Different usage habits, different apps, signal, and so on… all that affects battery life.
Even if you run out of battery ahead of time, you get immensely fast charging here
Now, even if you run out of battery ahead of time, don’t fret. Vivo’s 120W FlashCharge can get you from 0 to 50% in only 8 minutes. Getting a full charge takes less than half an hour. 50W charging is slower, but also plenty fast, if you opt for that option. It’s certainly much faster than the 15W charging that Samsung and Apple offer, it’s not even close.
Vivo X90 Pro Review: Camera
Spoiler alert… the Vivo X90 Pro is an outstanding camera smartphone. I’ve thoroughly enjoyed my time with it, and have taken some really nice pictures, some of which I’ll share below. There’s actually a lot to talk about here, but let’s get the technicalities out first. Unlike the China-exclusive Vivo X90 Pro+, this one does not have a periscope camera, unfortunately. It does have the exact same main camera, though, and it utilizes a 1-inch camera sensor from Sony. That’s the Sony IMX989 sensor, in case you’re keeping track. That is the largest camera sensor made for smartphones to date, and it has huge potential. It needs proper software in order to shine, and Vivo has certainly provided it here.
A truly excellent camera sensor is backed by ZEISS and great camera software
Vivo has a 50.3-megapixel main camera with an f/1.8 aperture and 1.6um pixel size. It has OIS support, and the same goes for Dual Pixel PDAF. Laser Autofocus is also here for faster focusing times. In addition to that, a 50-megapixel ultrawide camera is here as well. That unit has an f/2.0 aperture and a 108-degree FoV. This camera also supports auto-focusing. A rather capable 50-megapixel telephoto camera is also included on the back. It has an f/1.6 aperture, 0.7um pixel size, OIS support, and 2x optical zoom.
When it comes to pictures from the main camera, they’re great. They’re vibrant, filled with detail, and well-balanced. The phone handles highlights like a champ, even in the harshest HDR conditions. Considering the size of the sensor, you’re also getting that creamy bokeh effect which reminded me of DSLR cameras. I’ve never seen such a depth of field on other smartphone cameras, it really does bring a photo to life. Taking pictures of my pets with this sensor was a joy, even in low light. Some such samples are included below.
You can choose between Vivo’s default & ZEISS shooting modes
Now, do note that there are two shooting modes at your disposal here. You can shoot with Vivo’s default setting, or the ‘ZEISS’ mode. I much preferred ZEISS, as the colors were not oversaturated, and the images were closer to real life, but still quite vivid and lifelike. At times, Vivo’s mode came in handy, but I used ZEISS over 90% of the time after I realized what kind of pictures it takes. So, the vast majority of samples below are taken with the ZEISS setting, I’ll also include some comparisons below, so that you can see the difference. I used ZEISS in both regular and low light, as it made images look truly great.
You don’t even have to use a dedicated night mode, it’s not necessary
In low light, there’s really no need for you to use a separate night mode, which is available here. You can, if you want images to be even brighter, but the regular mode does the trick. This phone can take a photo in low light either instantly or in a couple of seconds, depending on the setting. The point is, it’s really fast in that regard, and the results are really good. It balances images really well. It pulls plenty of detail from the shadows, but not the level of overexposure. Thanks to ZEISS’ T* coating, the reflections are kept to a minimum as well. That has been the case with Vivo’s flagships for years, and I’m really glad it’s here. Vivo and ZEISS have been collaborating for a long time, and it shows.
It’s a shame it doesn’t have a periscope camera
I’d much prefer to see a periscope telephoto camera on this phone, in addition to this telephoto camera Vivo included, but… it is what it is. You can zoom in up to a certain level while retaining good details (depending on the scene), but don’t expect a crazy zoom level. Macro photography, on the other hand, is really good. You can see a couple of examples below. Even in a more challenging light indoors, during the night, it managed to do the job. The ring image below shows it best.
The video recording is also quite good
The video recording is also quite good. It’s not the best, as you can see the jelly effect in low light when panning, and there are a couple of other issues, but overall, the video recording is also good. This phone shines when it comes to still, though, it shines to the level that is hard to put into words. The Vivo X90 Pro is my favorite camera smartphone to date, as it takes full advantage of that 1-inch camera sensor to provide outstanding results. It does take some getting used to, but once you do… it’s a joy to use.
No ZEISS vs ZEISS samples:
Various camera samples (almost all in ZEISS mode):
Vivo X90 Pro Review: Software
Android 13 comes pre-installed on the Vivo X90 Pro, with the company’s Funtouch 13 UI on it. Funtouch is different than stock Android, but it has a lot of stock elements in it. It feels like your genuine Android experience, and it’s miles better than the version from years ago were. That being said, I did not really notice any major issues with the software. It worked really well, and was quite fluid too. Even the notification center and quick toggles do resemble stock Android, which is always a good thing. That goes for both looks and functionality. You’re even getting that media widget in the notification center, with the squiggly animation.
Funtouch UI has some useful gestures to offer
You can choose whether you want all your installed apps to be on home screens, or if you want a more regular Android experience with an app drawer. The settings screen looks similar to Samsung’s. The overall look is really nice, and as I said, this UI works really well. You do get some extra functionality here too. You can use gestures, for example, you can swipe with three fingers up or down to activate certain actions, such as taking a screenshot, activating a split screen, and so on. I’ve been using this quite a lot, as I did on previous Vivo phones.
This UI does give you the option to lock apps in multitasking, in case a specific app ends up being killed off, and you don’t want that. The RAM management is generally really good, and if you ever have issues with a specific app working in the background, you can always lock it. I had to do that with an app for my smartwatch, for example. I did it from the get-go, and had no issues after that.
There were a couple of smaller issues, but the software overall is really great
I did have a couple of instances when a notification didn’t arrive the second it was supposed to, but that happened only twice. Everything else was basically instant, so I presume that everything will be polished out soon. I have this version of UI on the Vivo X60 Pro+ as well, and it works like a charm. I really don’t have any major complaints about the UI, and I’m pretty sure most of you will be happy with the software included in the Vivo X90 Pro.
Vivo X90 Pro Review: Should you buy it?
The Vivo X90 Pro is one of the best camera smartphones in the market at the moment. Vivo managed to combine arguably the best camera sensor (for smartphones) currently available with excellent software, and ZEISS optics to provide a truly outstanding experience. The Vivo X80 Pro had its issues with consistency, but the Vivo X90 Pro does not show such problems. I do wish Vivo released the Vivo X90 Pro+ globally, as the Snapdragon 8 Gen 2 would offer better battery life, and the periscope camera would be useful. Even without those additions, however, the Vivo X90 Pro is an outstanding offering. Its price tag will play a huge part for most of you, and unfortunately, at the moment, we still don’t know its price tag outside of China. One thing is for sure, though, this phone excels in many ways, and doesn’t really have a lot of downsides. So, if the camera performance is important to you, this is a phone you should consider, definitely.
You should buy the Vivo X90 Pro if:
You appreciate smartphone photography, and want a truly great camera performance
You like vegan leather backplates that are less slippery than glass
You don’t mind a considerable curve on the display
You appreciate and need truly fast wired & wireless charging
You want the piece of mind IP68 certification offers
You don’t want to buy a charger separately
You’re tired of bad in-display fingerprint scanners
SAS Airlines was been hit by a cyber attack. The airline has confirmed that its websites and apps were impacted by the attack – Read on for the latest updates on the cyber attack and how it may have affected SAS customers.
The Scandinavian airline SAS was hit by a crippling cyber attack, after which its website and app went offline. It is suspected that the incident may have leaked the airline’s customer data from the app briefly. The incident occurred on Tuesday 14th February evening.
Reuters reported that the airline urged customers to refrain from using its mobile app, as they might receive incorrect information. Reportedly, some users, including customers from Norway, logged into the wrong accounts and accessed data or other customers. The company’s website remained offline for some time.
SAS’s head of press, Karin Nyman, stated that the issue had been fixed now. The airline didn’t provide details of the incident; however, users have posted resentful comments on its Twitter account in response to the company’s Valentine’s Day message.
The airline asked its Twitter followers if they dreamed of a trip to the “world’s most romantic city this Valentine’s Day?” to which one user replied:
“Well, I’m just dreaming of being able to actually book flights on your website or in the app at the moment,” and shared a screenshot of the downed website.
Some users posted about a technical glitch in the airline website that prevented them from buying tickets; it is not yet clear whether these complaints were resolved or not.
It is worth noting that several Scandinavian media outlets were hit by hackers on the same day that SAS was attacked. This includes SVT, a popular Swedish television channel that became a victim of a DDoS attack by a group named “Anonymous Sudan”.
The hackers stated that the cyber attack was a response to the recent Quran-burning incident near the Turkish embassy in Stockholm.
Popunders are the ideal vehicle to serve ad fraud. In this case, we investigate a scheme where a webpage you can’t see is loading a bunch of ads while code mimics user activity by scrolling and visiting links.
WordPress is an immensely popular content management system (CMS) powering over 43% of all websites. Many webmasters will monetize their sites by running ads and need to draw particular attention to search engine optimization (SEO) techniques to maximize their revenues.
But some people will take a shortcut to gaining traffic by engaging in legal but sometimes fraudulent practices. In this instance, we identified someone buying popunder traffic to promote their websites. A popunder is a very common occurrence online and consists of launching a secondary page under the current one. In itself, it could be considered simply an annoyance and is not malicious except when the website that is being launched uses various techniques to defraud advertisers.
We discovered a few dozen WordPress blogs using the same plugin that mimics human activity by automatically scrolling a page and following links within it, all the while a number of ads were being loaded and refreshed. The blogs would only exhibit this invalid traffic behavior when launched from a specific URL created by this plugin, otherwise they appeared completely legitimate.
In this post, we share the technical details behind this ad fraud scheme and any clues pointing to the developer of this WordPress plugin.
Key findings
About 50 WordPress blogs have been backdoored with a plugin called fuser-master
One of the blogs performing this ad fraud had 3.8 M visits in January, with an average visit duration of 24:55 minutes and 17.50 pages per visit
This plugin is being triggered via popunder traffic from a large ad network
The WordPress sites are being loaded in a separate page underneath and display a number of ads
The plugin contains JavaScript code that mimics the activity of a real visitor: scrolls the page, clicks on links, etc.
The code also monitors for real human activity (mouse movement) and will immediately stop the fake scrolling when that happens
Figure 1: Diagram summarizing ad fraud case
Fuser-master WordPress plugin
Recently we blogged about ad fraud involving a popunder as well, except in that case it was using an iframe to hide the ads. Here, there is nothing hidden at all and the ad fraud can only be deduced when the page is being scrolled down, and back up at random intervals. Because it is a popunder, anyone becomes an unwitting accomplice and does not see any of the fraudulent behavior.
In this investigation, we won’t be spending time on the ad network facilitating these popunders but we have a fairly good idea of which one it might be based on anti-debugging code that they used. What makes popunders particularly enticing for ad fraud is the fact they allow content to be loaded and remain until further action. Unlike the main browser window where a user can easily navigate away from the current website they are visiting, the popunder will remain open for several minutes or even hours, until it is closed.
We were able to trigger the popunder several times and noticed that the fraudsters were using several different blogs that all had the same thing in common, namely they used a plugin called ‘fuser-master’. There aren’t many references for this plugin such as where to download it or who its author might be. We were only able to find one mention from themesinfo.com which is a WordPress theme detector.
Figure 2: A list of websites using the fuser-master plugin
Not all the sites listed in the gallery still exist or are fully functional, but that still gave us a good indication of what was being used to turn standard blogs into ad fraud robots. It’s worth mentioning again that when visited at their homepage, all these blogs are static in nature, meaning we don’t see this kind of zombie activity where the page is scrolling by itself. In the next section, we will look at the URL entry point that triggers that specific behavior.
User check and redirect
All of these blogs appear typical when visited directly, so they would likely pass both a manual and human verification. However, when a special URL (the entry point) is entered with the corresponding parameters, they turn into ad fraud. Below you can see the URL path and its parameters that are being used on all the blogs where that plugin has been installed:
/wp-content/plugins/fuser-master/entrypoint.php?
First, the current user is checked to determine if they should be allowed to enter into the ad fraud scheme or not:
Figure 3: Pre-check for cookies
The fraudsters are using open redirects from Google and Twitter in an interesting way. A keyword from an array corresponding to related Google search terms is picked and added to a Google search URL:
Figure 4: SEO trick
That keyword is chosen randomly and makes up the dynamic redirect URL:
Figure 5: Keyword used in redirect
The next web request is the actual redirect code which also drops some cookies. The URL and code for the redirect will vary based on the different options set up previously:
Figure 6: Google open redirect
Figure 7: Twitter open redirect
The popunder will effectively load the blog via the entrypoint, then immediately leave it to re-enter via a Google open redirect as if someone had clicked on one of the search results. This is what it looks like:
Figure 8: Animation showing open redirect mechanism
Faking user activity
As mentioned previously, the blogs will only exhibit their ad fraud nature when visited via the fuser-master plugin’s entry point. We know that this happens when a user was browsing the web, clicked on a page and a popunder was launched. The blog will open up in a new window behind the current window, which means the user is completely unaware of what is happening.
It becomes quickly obvious that there is something odd when the popunder is exposed. We notice some scrolling back and forth and somewhat randomly which truly mimics what a human would do when reading an article. When looking at the code we can see that it checks for user activity (more on that later) and only performs this scrolling activity if it has not detected real mouse movements on the page:
Figure 9: Code for automated scrolling
Had the popunder been the same blog without this fake scrolling there would be no reason to suspect mischief. Of course the fraudsters aren’t interested in a static page without any kind of user interaction as their goal is monetization via ads. This invalid traffic needs to look as valid as possible in order to not get flagged by anti ad fraud solutions:
Figure 10: Animation showing automated scrolling
Another interesting aspect of this fraud is how at regular intervals, a new article is being viewed. This makes sense in the context of a standard visitor to a blog continuing on the site by following other articles that they might be interested in reading. Looking at the fuser-master’s code, we see that it tries to get all internal URLs from the currently loaded page and places these links into an array. If we observe what’s happening, see that after a certain number of scrolling up and down, a different article gets loaded and the scrolling resumes. This fake activity could last from minutes to hours, until it is interrupted by the real human who’s currently at their computer.
Freeze game
At some point, the real user will close their browser or the page that was in front of the popunder. When that happens, all fake activity suddenly stops and the blog becomes static. This is a clever trick to avoid suspicion and reminds us of the ‘freeze’ game kids play. The fraudsters are able to detect when the mouse is being placed over the current page and can quickly stop the code from running.
Figure 11: Monitoring for real user activity
Figure 12: Stopping fake activity after real user is detected
Same web developer built those blogs
Looking through the Internet Archive, we identified an Indian web developer behind several of these sites. Some of the older posts were written by him and the layout such as the scroll bar style and test ads are also identical. There is nothing that definitely proves that this web developer created the ad fraud plugin although he had the technical skills to do so and based on his community WordPress identity was involved in a number of posts about various SEO plugins.
Figure 13: Demo blog using a similar template reused elsewhere
In addition, his own business website also features those blogs in his portfolio and while hovering over the thumbnails we can’t help but notice a scrolling technique very similar to what we saw previously with the ad fraud.
Figure 14: Portfolio showcasing some of the blogs
We contacted one of his supposed customers to let them know about the fuser-mater plugin running on their site. While we did not hear back from them, within about an hour the plugin had been removed from their WordPress installation.
Figure 15: Fuser-master plugin was deleted shortly after our notification
If the web developer wanted to earn from this ad fraud scheme, he would need to have his own publisher IDs and overwrite the ones used by his customers, however we could not immediately verify that this was the case. It’s also possible that the plugin is sold as an “add-on” and that some of his customers are fully aware of it, but we could not prove that either.
Contrary to the previous ad fraud case we looked at, this one does not simply use Google ads. Instead they are going through a number of ad platforms which makes their publisher ID and potential revenue more difficult to figure out. We do know that one of the websites featured in this investigation (momplaybook[.]com) had 3.8 million visitors in January, spending an average of 24 minutes and looking at 17 pages on the site (stats by SimilarWeb).
Figure 16: Malwarebytes Browser Guard
Visiting that same website, Malwarebytes Browser Guard blocked over a thousand ad trackers after a few minutes of sitting idle on the main page. The majority of requests came from Google’s DoubleClick and OpenX which we have informed.
Conclusion
While popunders are a legitimate form of advertising, their very format is susceptible to abuse. For ad fraud in particular, popunders allow websites to be loaded and serve ads that will never be viewed by real humans.
The plugin we identified during this investigation is relatively simple and allows anyone with an ordinary WordPress blog to increase their earnings dramatically. Because regular visitors will come to the blog via a different flow (standard search or referral link), none of the fraudulent behaviors will be shown. All that is needed is to purchase ad space via a large popunder distributor and use the special entry point URL that triggers the fuser-master plugin.
We have shared details about this invalid traffic case with other partners in the industry.
Samsung’s Galaxy A series of phones have been really popular among those looking to save. Also, we can’t rule out Galaxy S users hopping down to the Galaxy A line in the face of the fumbling economy. Well, the Galaxy A23 5G is now being offered at Verizon.
There are two purchasing options that you can choose from. Firstly, you can buy the phone outright for the price of $349.99. However, if you can swing an extra $9.72/month, you can get it on a contract. Just know that this is a 36-month plan. The company may do a credit check, and if it’s not the best, you might have to pay a down payment.
The Galaxy S23 5G is at Verizon, what does it have to offer?
So, since this is a phone that’s meant for budget-conscious folks, you can expect the specs to be rather subdued. This phone is rocking a decently large 6.6-inch LCD display with a 1080 x 2400 resolution. What’s notable about it is the fact that it runs at 120Hz.
Moving onto the internals, the Galaxy A23 5G uses the Snapdragon 695 5G SoC, so you can expect pretty middle-of-the-road performance, but it shouldn’t be bad. This phone has 4GB of LPDDR4X RAM and 64GB of storage. You can expand it up to 1TB with a microSD card.
As for the camera, we’re looking at a quad-camera package. The main camera is a 50MP camera, and it’s accompanied by a 5MP ultrawide, 2MP macro, and 2MP depth camera. At the front, there’s an 8MP selfie camera.
Keeping the lights on, we have a 5000mAh battery. That will keep it powered for a while on a single charge. Speaking of charging, the Galaxy A23 5G supports 25W fast charging.
On the software side, this phone is launching with Android 13 running on One UI 5 out of the box. This means that you’ll have a pretty up-to-date software experience. All in all, the Galaxy A23 5G is a decent phone, and if you’re a Verizon customer, you can pick it up.
YouTube TV is Google’s own streaming live TV service. And it offers over 85 channels, live.
This product was designed for those that are looking to cut the cord from cable and be able to still watch cable channels. Without being tethered to their cable box, and be able to watch it anywhere.
YouTube TV is heralded as one of the best streaming live TV services on the market right now, despite the pretty regular price increases it has seen. It now costs $64.99 per month, after costing just $35 a few years ago. It’s the only streaming service that has PBS, and it is also the only one with an unlimited cloud DVR service. Making this a really incredible service for those that are looking to cut the cord from Comcast, Cox, AT&T, Verizon and other cable operators.
What is YouTube TV? And should you ditch cable for Google’s TV service? We’ll attempt to answer that, as well as other questions, like the cost, cloud DVR limitations, multiple screen limitations and more. Here’s everything you need to know about YouTube TV.
Table of contents
What is YouTube TV?
YouTube TV is Google’s attempt at capturing the cord-cutting audience. It’s a streaming Live TV service that offers 85+ channels, and continues to add more every few months. It also has YouTube Originals available.
YouTube TV initially launched in 2017, and it was restricted to a handful of markets in the US. The reason for the slow rollout, was gathering all local channels. Google did not want to launch in a market that did not have all of the locals. That includes ABC, NBC, CBS and FOX. Initially, Google was offering around 60 channels for $35 per month. In 2018, ahead of its nationwide launch, it increased prices from $35 to $40, but those that got in on the $35 price were grandfathered in.
In 2019, Google made YouTube TV available in all 210 markets in the US. It also added nine networks from Discovery, and raised the price from $40 to $50 per month. This also ended the grandfathered-in pricing for those that were paying $35. Google forced everyone to start paying $50.
In 2020, YouTube TV was able to strike a deal with ViacomCBS to bring over their channels to the service. Bringing over all of their channels meant another price increase. Going from $50 to $65 per month, and bringing the total number of channels to 85+. On March 17, 2021, YouTube TV added the rest of the ViacomCBS Channels to the service. These include BETher, Dabl, Nicktoons, Nick Jr, teenNick, MTV2, and MTV Classic.
YouTube TV is pretty unique for a couple of features that it offers and most of its competitors do not. The biggest one being an unlimited Cloud DVR. Allowing you to record just about everything. The other big feature is it’s availability. It’s available on almost any platform.
YouTube TV costs $64.99 per month for the base package. That includes 85+ channels, and all of its features.
There are some premium networks you can add-on, as well as the Sports Plus package. Sports Plus is priced at $10.99 per month and gives you an additional eight networks. The premium networks that are available include HBO and HBO MAX for $14.99. Showtime for $11/month, STARZ for $7/month, Cinemax for $10, Epix for $6/month, Curiosity Stream for $3, AMC Premiere for $5, Shudder for $6, Sundance Now for $7, Urban Movie Channel for $5 and AcornTV for $6. These all come with a free trial, anywhere from five days to 14 days. So it’s pretty easy to check out these premium channels before paying for them.
YouTube TV announced its new Spanish Plus package on May 10, 2022. It’s actually a package that can be an add-on, or purchased by itself without the base plan.
Spanish Plus includes 29 Spanish channels including: FOX Deportes, ESPN Deportes, Discovery en Español, beIN SPORTS en Español, CNN en Español, and more.
Currently, Spanish Plus is available for $9.99 per month for the first six months, $14.99 per month after for the add-on. Or you can get the package by itself for $24.99 per month for the first six months, and $34.99 per month after.
Sports Plus Package
Google added the Sports Plus package in September 2019. This is a new add-on for YouTube TV that will allow you to add even more sports networks. Included in this package is NFL RedZone, beIN SPORTS, FOX Soccer Plus, VSiN, Outside TV+, PokerGO+, MAVTV, TVG, Stadium, GOLTV, Billiard TV, SportsGrid, PlayersTV, Fight Network, IMPACT Wrestling. It’s available for $10.99 per month.
Update : On April 8, 2021, YouTube TV added FightNet and Impact Wrestling. For the same $10.99 per month.
Entertainment Plus Package
YouTube TV announced the Entertainment Plus package in February 2021. This package bundles HBO MAX, SHOWTIME and STARZ for $30 per month. Individually, these would cost you $35 per month, so you’re saving $5 here. Not a big savings, but a great way to bundle them with YouTube TV.
Supported Devices
4K Plus
On June 28, 2021, Google debuted another new add-on for YouTube TV – 4K Plus. This is an add-on that adds three main features. Of course, the ability to stream in 4K. Though that will be limited, at least at first, since most content is not available in 4K. But you can rest assured that the Olympics will be available in 4K.
It also brings offline downloads with almost no restrictions. Google says anything that you can record to your cloud DVR, you can download for offline viewing.
The third feature is that you’ll be able to watch unlimited streams with this package. Instead of the three concurrent streams that YouTube TV normally has.
This package is going to cost an additional $19.99 per month, and is available now.
Standalone channels
Announced on September 30, 2022, YouTube TV is allowing you to subscribe to some standalone channels without paying for the base plan on YouTube TV. Meaning you can subscribe to just these channels, without having to pay $65 per month on top of it. Those channels include:
HBO MAX
Showtime
STARZ
NBA League Pass
Cinemax
Epix
Hallmark Movies Now
Acorn
CuriosityStream
Outside TV Features
ALLBLK
Shudder
Sundance Now
IFC Films Unlimited
Dove
CONtv
Docurama
Law & Crime
VSiN
Update: In February 2023, YouTube TV announced that MLB Network and MLB.TV won’t be returning for the 2023 season. So you can’t buy the standalone MLB.TV package through YouTube TV any longer.
What devices are supported?
YouTube TV is available on a large variety of devices right now, and it is still adding more to its list.
As of today, YouTube TV is available on Android, iOS, Android TV, Apple TV, Chromecast, Fire TV, Roku OS, PlayStation 4 and Xbox One. As far as smart TVs go, it is available on many smart TVs from LG, Samsung, Hisense, Sharp, TCL and VIZIO that are 2016 and newer. Not to mention the fact that any TV that has Android TV, Roku or Fire TV built-in will also work – which includes almost every Hisense and TCL Smart TV from recent years.
On September 30, Google announced that the new Chromecast with Google TV will have a pretty tight integration with YouTube TV. With a new “Live” tab on the home screen that shows the current TV listings for what is live. At launch, only YouTube TV works with this tab, but Google plans to add more to that tab in the future. Like Sling TV, FuboTV and others.
Update: As of April 30, 2021, Roku no longer carries YouTube TV. Existing users can still use YouTube TV, for now. However, you do still have the option to Cast to your Roku device. This is in result of the carriage dispute between Google and Roku. This should only be a temporary thing, hopefully.
YouTube TV has steadily been adding new channels to its service since its inception in 2017. Currently it has over 85 channels, and covers the majority of the top 100 most popular cable channels.
Recent YouTube TV changes
YouTube TV added ViacomCBS channels: BET, CMT, Comedy Central, MTV, Nickelodeon, Paramount Network, TV Land, and VH1. Five of the 14 ViacomCBS channels have not yet arrived on YouTube TV, but will be very soon. Those include BET Her, MTV2, Nick Jr, Nicktoons, TeenNick and MTV Classic.
YouTube TV lost all Fox regional sports networks on October 1: After trying to renegotiate with Sinclair following its extension, YouTube TV lost access to all Fox regional sports networks. These include: Fox Sports Arizona, Fox Sports Carolinas, Fox Sports Detroit, Fox Sports Florida, Fox Sports Indiana, Fox Sports Kansas City, Fox Sports Midwest, Fox Sports New Orleans, Fox Sports North, Fox Sports Ohio, Fox Sports Oklahoma, Fox Sports Prime Ticket, Fox Sports San Diego, Fox Sports South, Fox Sports Southeast, Fox Sports Southwest, Fox Sports Sun, Fox Sports Tennessee, Fox Sports West, Fox Sports Wisconsin, SportsTime Ohio, and the YES Network. It’s worth noting that Fox, FS1 and FS2 will remain on YouTube TV though.
NFL Network came to YouTube TV in September 2020: Without any sort of price increase.
YouTube TV debuted new Sports Plus package in September 2020: YouTube TV debuted its first add-on package in September with Sports Plus. For $10.99 per month you can add NFL RedZone, Fox College Sports, GolTV, TVG, MAV, Stadium and Fox Soccer Plus.
MLB.TV comes to YouTube TV: In February 2021, YouTube TV announced that it was bringing MLB.TV to its service (as an added cost). It is available as of March 2021. With subscribers getting a free preview throughout March. MLB.TV costs $24.99 per month or $129.99 for the season.
Scripps Networks come to YouTube TV: In January 2023, YouTube TV announced that Scripps networks were coming to the service. That includes Ion, Bounce TV and Scripps News. That’s in addition to Newsy, which has been on YouTube TV for a few years already.
YouTube TV has a number of great features, some of which none of its competitors even have. As a result, it really helps make it stand out among the competition. Here are some of the bigger features for YouTube TV.
Unlimited Cloud DVR
Cloud DVR
By far the most popular feature for YouTube TV is its unlimited Cloud DVR. Which is included in the $64.99 price.
Because it is unlimited, you can record virtually anything and everything on YouTube TV, and watch it later. You can also record as many shows at the same time as you want. Something that is not possible with traditional TV.
Finally, with YouTube TV, you can also opt to start from the beginning or join live, if it is a show that you are recording. So if you come home late to watch The Masked Singer that starts at 8PM, you can start from the beginning and fast-forward through commercials until you catch up to the live recording. It is a really useful feature to have.
Dolby Digital 5.1
On August 27, 2021, YouTube TV announced that it had rolled out Dolby Digital 5.1 to all users.
Currently the compatible devices list is still pretty short. But it will be available on all devices that work with Dolby Digital 5.1 and YouTube TV in the very near future.
This feature is going to improve the audio quality from both live and on-demand content on YouTube TV. This also makes YouTube TV only the second streaming service to offer it for live content, along with DIRECTV Stream.
Google has started rolling out Dolby Digital 5.1 to more Roku and Android TV devices in June 2022.
Multiple Users
Another feature that sets YouTube TV apart is multiple users. Most streaming services do have multiple users support, but not quite in the same way.
With YouTube TV, you can invite up to five people to your subscription. So instead of sharing your password with other people, they can sign in with their own Google account. That is much smarter than sharing passwords, especially for something like your Google account, which is used for almost everything on the web.
While you can have up to five accounts on your YouTube TV account, you are still limited to only three simultaneous streams on YouTube TV. So not everyone can watch at the same time. But three screens is also more than its competitors offer, without paying for an upgraded plan.
Voice Control via Google Assistant
As expected, YouTube TV is integrated with Google Assistant. So if you have a Google Assistant device like a Nest Mini or Nest Audio, you can use it to start YouTube TV on your TV. If you have a Chromecast or Nest Home Hub, you can tell the Assistant to start playing YouTube TV on that screen.
You also have the ability to control other functions, like selecting a TV channel to watch live, starting a show, recording a show and even using playback functions like pause, resume and rewind.
On-Demand
YouTube TV does have an on-demand section of different movies and TV shows. If something you recorded is available as on-demand, you can choose between those two options. For example, if election coverage interrupted your recording of Ellen’s Game of Games, you can opt to watch the on-demand version instead.
The main difference between on-demand and DVR though, is that you cannot fast-forward through commercials on on-demand content. Though some won’t have commercials – like FOX shows for some reason. On DVR content, you can fast-forward or rewind to your heart’s content.
Picture-in-Picture on Mobile
Surprisingly, most other streaming live TV services do not offer this feature, but YouTube TV allows you to do picture-in-picture on mobile. So you can continue watching your show while you are on Twitter or Facebook, or replying to your friend’s text message.
This works on Android smartphones and tablets. However, it doesn’t yet work on iOS. It’ll work on iPads and iPhones starting with iOS 14.
Dark Mode
As with everything these days, there is a dark mode for YouTube TV on both desktop and mobile. This can be very useful for when you are watching TV or scrolling through the app at night or in a dark room.
Mark shows as viewed
Since you can’t “delete” shows from your DVR – they will auto-delete after nine months, and be replaced with a newer recording if that show played on TV again – mark as viewed is really useful.
You can “Mark as Watched” on any movie or TV show on YouTube TV, from the desktop or mobile versions of the service. This means that it won’t show up as “new” in your library any longer. As a result, it makes it easier to view your new shows in your library, to catch up on what’s new.
No offline viewing
This is likely no real surprise, but YouTube TV does not allow for offline viewing. Most streaming Live TV services do not allow for this, since it is live. But it would be nice to be able to download your DVR’d content to watch offline, if you are going to be flying somewhere with no internet, or taking the subway to work. Hulu with Live TV does it, but there are some serious caveats to it.
Multiple channel sorting options
YouTube TV has always offered the default view for sorting channels, and then a Customized view. Which was a pain to actually do. Imagine dragging and dropping channels when there are over 100 channels in the list.
But on January 18, 2022, Google started rolling out a few more options. Like the ability to sort by “Most Watched” and then A-Z and Z-A. The Most Watched option takes into effect your DVR watching habits too.
When you look at the channels and the pricing of YouTube TV, it is a pretty good deal. The only downside here is that there’s no telling when the price may go up again. But if the recent Sports Plus package addition is anything to go by, it looks like Google is planning to add some more premium packages. Instead of giving everyone, every single channel and just raising the price.
I am a subscriber of YouTube TV and have been since almost the beginning, so my opinion here is a little bit biased, but I feel that this is the best value. There’s over 85 channels here, including the majority of the top 100 cable channels available. As well as cloud DVR, where you can save literally everything (and I do) to watch later. Not to mention the fact that it is available on almost every platform you can think of.
If you’re looking to check out YouTube TV, use this free trial to check it out before paying for it. Google gives everyone a free seven-day trial. But right now, if you sign up before October 15, 2020, you can get that doubled to 14 days.
Starting next month, Apple is changing App Store pricing in certain countries. The price changes will be seen with apps in the App Store and with in-app purchases. Apple released a note to developers in which it points out that it deals with 44 currencies across 175 iOS app storefronts. Obviously, the tech giant needs to deal with always fluctuating foreign exchange rates and changes that are made to the tax policies of the countries it serves.
Apple has made similar changes to App Store pricing in the past for the same reasons. For example, last month Apple made a huge change to App Store pricing by adding 700 new price points for developers. This change was first made available last month for apps offering auto-renewable subscriptions. Other apps and in-app purchases will be able to use the new price points starting this spring.
As for the changes announced by Apple on Friday, the company told developers that “apps and in-app purchases (excluding auto-renewable subscriptions) on the App Store will increase in Colombia, Egypt, Hungary, Nigeria, Norway, South Africa, and the United Kingdom.” This increase will start on February 13th.
Meanwhile, a drop in the value-added tax rate from 15% to 12% in Uzbekistan will lead to a drop in app and in-app pricing. Apple tells developers not to worry because “Your proceeds will be adjusted accordingly and will be calculated based on the tax-exclusive price.”
Fluctuations in foreign-exchange rates is one reason why Apple often changes prices in the App Store
In Ireland, Luxembourg, Singapore, and Zimbabwe, app and in-app prices won’t change but developers’ proceeds will fluctuate due to the following tax changes:
Ireland: Reduction of value-added tax rate on electronic newspapers and periodicals from 9% to 0%
Luxembourg: Reduction of value-added tax rate from 17% to 16%
Singapore: Increase of goods and services tax rate from 7% to 8%
Zimbabwe: Increase of value-added tax rate from 14.5% to 15%
At the end of the current month, Apple says that proceeds will increase for local developers in Cambodia, Kyrgyzstan, Indonesia, Singapore, South Korea, Tajikistan, Thailand, and Uzbekistan.
Apple reminds developers that they can change the prices of their apps and in-app purchases (which include auto-renewable subscriptions) anytime using App Store Connect. The company also reminds developers selling subscriptions that they can also leave pricing the same for existing subscribers.
SideWinder is apparently an India-based advanced persistent threat (APT) group known for spreading malware, infiltrating networks, and stealing sensitive information.
Security researchers at Group-IB have finally been successful in connecting a series of phishing campaigns between June and November 2021 to an Indian Advanced Persistent Threat (APT) group, SideWinder.
The suspected state-sponsored group has targeted 61 government, military, law enforcement, and other organizations across the Asia-Pacific region, according to a report from Group-IB.
Also known as Rattlesnake, Hardcore Nationalist (HN2), and T-APT4, the group is considered one of the oldest national-state groups, going as far back as 2012. In January 2020, the group was found to be infecting Android devices with malware through the Play Store.
In another attack reported in February 2022, SideWinder was observed collaborating with another group called ModifiedElephant and targeting unsuspecting users by planting incriminating evidence on their devices.
In June of last year, the group’s custom tool, SideWinder.AntiBot.Script, was used in previously undocumented phishing attacks against Pakistani organizations. The group was also linked to an attack on the Maldivian government in 2020.
Like many others, SideWinder also uses spear phishing as its initial attack vector, sending phishing emails containing malicious attachments or URLs to victims. Two of these campaigns featured emails in which the group impersonated a cryptocurrency firm, said Group-IB.
If a user clicks on the link attachment, a malicious document, an LNK file, or a payload is subsequently downloaded onto their computer. The LNK file downloads an HTA file, which then downloads the payload. This payload could be either a remote access Trojan (RAT) or an information stealer, according to Group-IB’s technical analysis.
Further, two new custom-made SideWinder tools discovered by Group-IB during the campaign were SideWinder.RAT.b, a RAT, and SideWinder.StealerPy, an info-stealer.
The info-stealer is capable of collecting Google Chrome browsing history, credentials saved in the browser, the list of folders in the directory, meta-information, the contents of docx, pdf, and txt files and more.
The APT group’s motive seems to be linked to India’s cryptocurrency market, Group-IB’s report speculates.
“Interestingly, Group-IB analysts discovered two phishing projects mimicking crypto companies. SideWinder’s growing interest in cryptocurrency could be linked to the recent attempts to regulate the crypto market in India.”
However, Group-IB cannot confirm how many, if any, of these phishing campaigns were successful. Nevertheless, users and organizations must take precautions against SideWinder’s attack, starting with the following steps:
Keep your software up to date: Make sure your operating system and all your software are up to date with the latest security patches. This will help protect you against known vulnerabilities that could be exploited by SideWinder.
Use strong passwords: Use complex and unique passwords for all your accounts and enable two-factor authentication whenever possible. This can help prevent unauthorized access to your accounts and make it more difficult for SideWinder to gain access.
Be cautious of phishing emails: SideWinder often uses phishing emails to trick users into clicking on a malicious link or downloading a malicious attachment. Be cautious of emails from unknown senders, and do not click on links or download attachments unless you are sure they are safe.
Use anti-malware software: Install and use anti-malware software to help detect and prevent SideWinder attacks. Make sure your anti-malware software is up to date and set to automatically scan your system on a regular basis.
Limit access to sensitive information: Limit the number of people who have access to sensitive information, and use encryption to protect data that is transmitted or stored.
Train employees:Train employees on how to recognize and avoid SideWinder attacks. Educate them on safe browsing habits, how to identify phishing emails, and the importance of keeping software up to date.
SSL Checker helps you in troubleshooting common SSL issues and SSL endpoint vulnerabilities. With the free SSL certificate checker tool, just you need to submit the domain name or IP address along with the port number to analyze the configuration and security of the website.
These diagnostics tools help you in finding vulnerabilities in SSL Suites, Weak Ciphers, and protocols. SSL analyzer tools make sure that your SSL/TLS certificate is installed correctly and doesn’t give any errors to users.
How SSL Works
The SSL markets continue to grow, according to the new report, 80% of the web page that loads in Chrome and 70% of the page that loads on Android devices are with HTTPS.
Free SSL Checker Tools & Keywords
SSL Labs
In-depth scan Ciphers, Protocols Certificate status
Here is the list of the Ten Best SSL analyzers that save you hours of troubleshooting time and headaches.
SSL Labs
SSL Security Test
SSL certificate Decoder
COMODO SSL Analyzer
Certificate Analyzer
DigiCert SSL Checker
AppSec SSL Analyzer
GocertsSSL
SSLShopper
Cheap SSL Checker
OpenSSL & SSLyze
testssl.sh
SSL Labs
The SSL Labs is powered by Qualys, with the tool you can check your website for certificate and configuration and your browser for SSL installation.
You can start the analysis by just entering the domain name or the Ip address of the target server, it runs an in-depth scan and provides you with a detailed analysis report.
The report details the certificate installed, serial numbers, Certificate Transparency, Revocation status, Signature algorithm, DNS CAA, certification path, ciphers, protocols, and Handshake Simulation.
It also checks for the possible subdomains of the domain, chain, and vulnerabilities like heartbleed and POODLE OVER TLS.
Also, it do checks for standard Industry practices such as CAA, Support for TLSv1.3, Ciphers, HSTS, and other standard practices.
SSL certificate Decoder
The decoder link powered by Namecheap is the best source for all your SSL-related troubleshooting needs.
It contains an SSL Checker, SSL Converter, CSR Decoder, DCV checker, Certificate & key checker, and decoder. link is a single-stop solution for all of your digital certificate needs.
COMODO SSL Analyzer
Gives you a crystal clear report that Certificate Details, status, web server software used, Protocol Versions, Ciphers, and Protocol Features.
Its clean design and rapid response are the advantages of this SSL Checker, by default it checks with port 443, but you can change it.
Certificate Analyzer
The Certificate Analyzer is powered by Trustwave, all you need is just to enter the domain name and the port number and click on test my server.
It does a basic installation check and provides you with a report about the certificate installed on the server.
DigiCert SSL Checker
DigiCert SSL Checker OR Symantec SSL checker (Acquired) helps you in locating the problems with the installed SSL certificates and also checks for certificate status, Expiration, ciphers, andcommon vulnerabilities.
It’s a simple tool, if you want to check the installation with port 443 then just need to enter the domain name alone, if it is for the port number, then you need to provide the port number also like domain.com:8443.
AppSec SSL Analyzer
Like other SSL checkers, AppSec is not web-based, you can download and launch the application from your computer.
It checks for the domain and/or IP address, and tests vulnerabilities related to the encryption algorithms. The latest version is AppSec Labs SSL Analyzer version 2.0.
GeocertsSSL
GeocertsSSL SSL checker is yet another simple SSL installation checker that checks for the certificate chain, DNS,and Certificate Common Name.
It also includes tools such as a CSR decoder, Certificate decoder, and certificate key matcher. All you need is just to enter the domain name, and port number and click on search.
SSLShopper
With the SSLShopper SSL Checker tool, you can diagnose installation problems with the SSL installation and it helps you to make sure that certificate is correctly installed, valid, and trusted.
It also tracks the server type and the IP address of the domain, along with the chain. To use the SSL Checker with the port you just need to enter the server’s hostname.
Cheap SSL Checker
The Cheap SSL Checker is a simple SSL checker tool that verifies the SSL installation details such as common name, issuer, validity, server type, certificate chaining, etc.
To run the scan simply you need to enter the IP address or the domain name.
OpenSSL & SSLyze
You can also use the following OpenSSL command to run an installation check
SSLyze is the Fast and Complete SSL Scanner to find Misconfiguration in the servers configured with SSL.
sslyze –regular domain.com
testssl.sh
It is a free command line tool that checks a server’s service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws, and more.
Final Words
With SSL Checker you can diagnose all the issues related to issues and ensure the certificate is installed correctly on the server.
With Hogwarts Legacy becoming the popular game it was expected to be, online criminals have resorted to old tricks to get users clicking.
Hogwarts Legacy, the much-anticipated Harry Potter video game, has finally landed on major gaming platforms. But, as with all games like this, it comes with a steep price tag, so it’s no surprise to suddenly see websites peddling “cracked” versions of the game for free.
These sites are easily accessible via a quick Google search.
“hogwarts legacy crack” sample search result by Google (Source: Malwarebytes | Stefan Dasic)
Cracked games are games that are rendered playable due to tampering or file modification. They’re also generally available for free. Essentially, they’re pirated games, which is illegal in some states. Malware Intelligence Analyst Stefan Dasic looked into the above websites claiming to share the cracked PC version of the game.
One website, games-install[.]com, asks users for an activation key once they’ve downloaded the “game”. In order to access the key, the site says the user must verify themselves via a survey.
Everything falls apart at that point. Either the survey leads to a dead end, or ask users to enter their data, such as a phone number. Suffice it to say the website is a survey scam.
This is what happens when you try and download a “free” version of Hogwarts Legacy (Source: Malwarebytes | Stefan Dasic)
Dasic said the sites from the above screenshot all resolve to gameportpc[.]ru, which redirects to changing sites that are seen hosting a file named Hogwarts_Legacy_Setup.exe.
When users click the “Download” button, they find that they have downloaded a copy of the legitimate 7-Zip file compression program.
If you visit the same gameportpc URL, however, the downloaded filebecomes a Trojan dropper, which then drops adware.
Malwarebytes detects the Trojan and adware as Trojan.Dropper and Adware.Agent.Generic, respectively. We also block the websites we’ve seen pushing fake Hogwarts Legacy game cracks.