Re: [GNC-dev] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread Andrew Ruthven
Hey, This IP is assigned to Cloudflare: puck@dirk:~$ whois 2606:4700:3030::6815:5f93 ... NetRange: 2606:4700:: - 2606:4700:::::: CIDR: 2606:4700::/32 NetName: CLOUDFLARENET NetHandle: NET6-2606-4700-1 Parent: NET6-2600 (NET6-2600-1) NetType: Direct Allocation OriginAS:

Re: [GNC-dev] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread Andrew Ruthven
The domain is registered with webnic.cc, but all the registrar details are hidden: puck@dirk:~$ whois gnu-cash.org Domain Name: gnu-cash.org Registry Domain ID: 9a42474dfe5d4a8e9e50e0c56e101812-LROR Registrar WHOIS Server: https://iwhois.webnic.cc Registrar URL: https://www.webnic.cc/ Updated

Re: [GNC-dev] [GNC] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread Vincent Dawans
OK got the setup.exe back from my recycling bin and submitted it to virustotal. Here is the result: https://www.virustotal.com/gui/file/15d333959c6bf4bc913a3526a7aae8855af60b08a2542ee245d18b79dc7eede5 On Fri, Dec 9, 2022 at 4:41 PM Glenn Fowler wrote: > Thanks Vincent. If you could upload the

Re: [GNC-dev] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread Craig Arno
Seems like this information could be used to report and pull the gnu-cash.org domain: Domain Name: gnu-cash.org Registry Domain ID: 9a42474dfe5d4a8e9e50e0c56e101812-LROR Registrar WHOIS Server: https://iwhois.webnic.cc Registrar URL: https://www.webnic.cc/ Updated Date: 2022-10-25T22:39:36Z

Re: [GNC-dev] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread Vincent Dawans
OK sorry for the flood of email but as of 4:05PM US Pacific time the ad is no longer showing for me either. So possibly already removed via my report and others. As for the actual site there is nothing we can do, the important thing is that it doesn't show up on Google. No trace of it on Bing

Re: [GNC-dev] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread Vincent Dawans
You need to go to the main.php page link to see the fake site. Full link is https://gnu-cash.org/main.php or possibly https://www.gnu-cash.org/main.php Google ads are location and search history dependent so might not show up everywhere. Google has a separate tool to report phishing sites. But

Re: [GNC-dev] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread David Carlson
Mystery deepens! When I tried to open this fake website it was not available in Tor browser but pinging it revealed a response from IPV6 address 2606:4700:3030::6815:5f93. That IP does not seem to be registered On Fri, Dec 9, 2022 at 5:40 PM Vincent Dawans wrote: > Added screenshot showing

Re: [GNC-dev] URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread John Ralls
I don't see that ad when I search Google for gnucash; when I type https://www.gnu-cash.org/ into my browser's address bar I'm taken to a page titled "Dot Com Inovations"[sic] with a heading "October 20, 2022" and nothing at all about GnuCash. Not that there would be anything we could do about

Re: [GNC-dev] [GNC] ANNOUNCE: IRC: irc.gnome.org Alias Changed

2022-12-09 Thread John Ralls
If there was a matrix bridge before it was through irc.gnome.org. One of the reasons the infrastructure team decided to move the irc.gnome.org alias to libera.chat was because they thought that the Matrix bridge would be easier to maintain. Someone offered on IRC the other day to set up a

[GNC-dev] Fwd: URGENT: Fake gnucash website with fake download, most likely compromised file

2022-12-09 Thread Vincent Dawans
Sent this to gnucash-user but it's sort of urgent so wanting to make sure it gets to the main developers as well. The link to the fake site reported below is actually https://gnu-cash.org/main.php -- you need the full page link to see the fake site that shows in the google ad. --

Re: [GNC-dev] [GNC] ANNOUNCE: IRC: irc.gnome.org Alias Changed

2022-12-09 Thread Derek Atkins
There are literally dozens of IRC clients out there to choose from. If you care about Matrix, then I suggest you contact them about it; it was working before, so I'm sure they can make it work again. We have no control over such third-party integrations. While we do have a channel registered