{"id":11102,"date":"2018-01-12T16:10:19","date_gmt":"2018-01-13T00:10:19","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/01\/12\/news-4873\/"},"modified":"2018-01-12T16:10:19","modified_gmt":"2018-01-13T00:10:19","slug":"news-4873","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/01\/12\/news-4873\/","title":{"rendered":"Stripchat bot spells block"},"content":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Fri, 12 Jan 2018 23:26:29 +0000<\/strong><\/p>\n<p>Here at Malwarebytes, we spent a lot of time and effort scouring the Internet looking for malicious websites that we can protect our users from. Sometimes, these websites are pushing malware or some kind of scam. Other times it comes down to bad advertising practices that are used to fool the user into clicking on something.<\/p>\n<p>We used to see a lot of this kind of trick with <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2012\/10\/pick-a-download-any-download\/\" target=\"_blank\" rel=\"noopener\">fake download buttons<\/a> that redirected users to sites for installer downloads or to surveys. More recently, we found a site using a different type of deception, and it&#8217;s shot up to our second-most common detection over the last month. The site is called creative.stripchat.com.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/Stripchat_Mbam.png\" target=\"_blank\" rel=\"noopener\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-21064 size-medium\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/Stripchat_Mbam-300x184.png\" alt=\"\" width=\"300\" height=\"184\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/Stripchat_Mbam-300x184.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/Stripchat_Mbam.png 472w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>Stripchat.com is an online streaming video service operated by Technius LTD and offered on a number of popular websites. The streaming service targets adult audiences for the purposes of online sexual encounters. The service boasts many active subscribers and a number of channels available for use.<\/p>\n<p>&nbsp;<\/p>\n<p>Stripchat has a number of valid channels, feeds, and websites, but one particular subdomain has caught the attention of Malwarebytes for implementing various deceptive tactics and misleading techniques.\u00a0 The website, creative.stripchat.com, is a domain which is used for advertising purposes. Once opened in a web browser, the website purports to engage the user via a &#8220;live&#8221; chat window and the ability to chat with a model. This, however, is not the case.<\/p>\n<p>The reported live video feed is nothing more than a video retrieved from the Internet and subsequently looped, or in some cases terminated with a message indicating the model is in a private chat. These messages are deceptive, as the feeds are not live as claimed to be and the responses are pre-programmed, as can be seen from the Javascript code and subsequent chat session.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/StripChat_JavaScript_Edited.png\" target=\"_blank\" rel=\"noopener\" data-rel=\"lightbox-1\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-21122 size-full aligncenter\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/StripChat_JavaScript_Edited.png\" alt=\"\" width=\"1285\" height=\"573\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/StripChat_JavaScript_Edited.png 1285w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/StripChat_JavaScript_Edited-300x134.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/StripChat_JavaScript_Edited-600x268.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/StripChat_JavaScript_Edited-604x270.png 604w\" sizes=\"auto, (max-width: 1285px) 100vw, 1285px\" \/><\/a><\/p>\n<p>Malwarebytes blocks the creative.stripchat.com sub-domain for the use of these misleading marketing tactics.<\/p>\n<p>However, if you&#8217;d like to continue visiting this sub-domain, you can add an exception. Scroll down to the &#8220;How to add an exception&#8221; heading of <a href=\"https:\/\/blog.malwarebytes.com\/security-world\/2017\/10\/why-is-malwarebytes-blocking-coinhive\/\" target=\"_blank\" rel=\"noopener\">this post<\/a> on why we block CoinHive to learn how.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/social-engineering-threat-analysis\/2018\/01\/stripchat-bot-spells-block\/\">Stripchat bot spells block<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/social-engineering-threat-analysis\/2018\/01\/stripchat-bot-spells-block\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Malwarebytes Labs| Date: Fri, 12 Jan 2018 23:26:29 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/social-engineering-threat-analysis\/2018\/01\/stripchat-bot-spells-block\/' title='Stripchat bot spells block'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/01\/shutterstock_425877313.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Learn why Malwarebytes is blocking a sub-domain of an adult website.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/threat-analysis\/social-engineering-threat-analysis\/\" rel=\"category tag\">Social engineering<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/advertising\/\" rel=\"tag\">advertising<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/block\/\" rel=\"tag\">block<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/creative-stripchat-com\/\" rel=\"tag\">creative.stripchat.com<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/fake-chat\/\" rel=\"tag\">fake chat<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/malwarebytes\/\" rel=\"tag\">Malwarebytes<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/streaming\/\" rel=\"tag\">streaming<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/stripchat\/\" rel=\"tag\">stripchat<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/web-protection\/\" rel=\"tag\">web protection<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/threat-analysis\/social-engineering-threat-analysis\/2018\/01\/stripchat-bot-spells-block\/' title='Stripchat bot spells block'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/threat-analysis\/social-engineering-threat-analysis\/2018\/01\/stripchat-bot-spells-block\/\">Stripchat bot spells block<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11147,15174,17159,17160,10560,10510,12151,17161,15904],"class_list":["post-11102","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-advertising","tag-block","tag-creative-stripchat-com","tag-fake-chat","tag-malwarebytes","tag-social-engineering","tag-streaming","tag-stripchat","tag-web-protection"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11102"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11102\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}