NameSilo

Security fix from Verisign? Or Scam?!

Spaceship Spaceship
Watch

YesBrilliant

Account Closed
Impact
38
I've been receiving this email several times during the last few days, asking me to install a file on my server. Other people may have as well.

Those emails seem perfectly coming from Verisign. However, they are Not from Verisign.

Please be alert if you receive it and send a copy, with full header, back to Verisign so that they can take an action against those hackers.

And do NOT install any software from that email!

Here is the full copy of the email I received (except my email):

-----------------------------------------------------------

Verisign Inc. ([email protected]) +Add contact
Reply-To:[email protected]
To: my email
Subject: Hosting Regular Security Maintenance

Attachments: Security scan upon download guard.php (157.1 KB)

Dear FDIC valued Members

Regarding our new security regulations, as a part of our yearly maintenance we have provided a security guard script in the attachment.

So, to secure your websites, please use the attached file and (for UNIX/Linux Based servers) upload the file "guard.php" in: "./public_html" or (for Windows Based servers) in: "./wwwroot" in your site.

If you do not know how to use it, you can use the following instruction:

For Unix/Linux or Windows based websites that use PHP/CGI/PERL/ASP:
1) Download the attachment named "guard.php"
2) Login to your site Control panel.
3) Open "File Manager" window.
4) Go through "Public_html" or "htdocs" (for UNIX/Linux Based servers), but for Windows Based server, please Go through "wwwroot" directory.
5) Choose "Upload Files"
6) Upload the file "guard.php"
7) Check its URL too "http://www.yoursite.com/guard.php", if it is ok

Thank you for using our services and products. We look forward to providing you with a unique and high quality service.

Best Regards

Verisign Inc
http://www.verisign.com
Address:487 E. Middlefield Rd.
Mountain View, CA 94043

--------------------------------------------------------------------

Thanks for looking.
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
Have you contacted Verisign about this and forwarded a copy? Interesting to
see the headers.
 
0
•••
Yes, I sent a copy to them, with the headers.

No response to me but hope they are taking an action.
 
0
•••
Of course it's a scam...how would putting a php file on your server improve security. Why don't you put the contents of it here so we can check out what's in it.
 
0
•••
I'd like to but my antivirus does not allow me to save the file in my computer.

If you want I can forward it to you by email. Just PM me it.

The virus shown is named

Trojan horse PHP/BackDoor.c

with that exact spelling.
 
0
•••
4) Go through "Public_html" or "htdocs" (for UNIX/Linux Based servers), but for Windows Based server, please Go through "wwwroot" directory.
This poorly constructed sentence is enough proof of the email's illegitimacy.
 
0
•••
Dynadot — .com Registration $8.99Dynadot — .com Registration $8.99

We're social

Unstoppable Domains
Domain Recover
NameMaxi - Your Domain Has Buyers
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back