MegaUpload typosquatting exposed – check your typing

24 Jan, 2012  |  Written by  |  under News

megaupload_logoThe MegaUpload take-down is one of the hottest stories on the net, involving the FBI, illegal file-sharing, hackers’ revenge, the specter of SOPA and more. But don’t be too curious…

It’s only natural, given the relevance of the MegaUpload takedown, for people to be interested. What does the FBI message pasted on the MegaUpload front page look like? Is the site still down, or has it found some way to survive? But beware, because curiosity can infect the cat.

megaupload_banner_fbi

GFI Labs is warning about Megaupload(dot)cm. That’s not my typo – it’s the criminals hoping that you do one of your own. If you mistype ‘cm’ for ‘com’ you won’t go to the file-sharing website, you’ll go to a completely different site, registered in the Cameroons (cm).

Megaupload(dot)cm was registered way back in 2009. It is one of many Cameroon-registered sites seeking to capitalize on mistyping. In the wake of the MegaUpload takedown, GFI Labs is warning that this particular mistyping will redirect visitors to surveytakelive(dot)com, which offers prizes in exchange for some personal information. After this, the visitor is offered three options.

The GFI Labs researcher concerned, Christopher Boyd, didn’t follow the process through to it’s natural conclusion. He chose ‘a love thermometer’ (shaped like a baseball bat) but doesn’t know what lies beyond it (other than another site, enterfactory(dot)com). The internet is full of such scams, all leading to nefarious destinations. This one relies on an initial user typo, and is particularly relevant given the MegaUpload takedown.

The solution is simple: don’t go there, and, as Boyd says, “Be mindful of what you’re typing into the URL bar, and let me know if you discover what the Love Thermometer actually does…”

2 Responses so far | Have Your Say!

  1. Sarah Connelly  |  January 25th, 2012 at 2:02 am #

    acually did not want to try log on to the site and have a look as not sure what would happen if I did so thanks for showing us what it actually looks like shaun

    Sarah Connelly - Gravatar
  2. Shaun Ellerton  |  January 31st, 2012 at 9:42 pm #

    Hello Sarah,

    Thanks for your comments. Your right in not attempting to even view the site as you do not want to get yourself into a sticky situation.

    I used a proxy browser to extract the image from the site for my blog article.

    Glad you found the post interesting.

    Best wishes,

    Shaun Ellerton

    Shaun Ellerton - Gravatar

Leave a Feedback

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

*