It has been a while since I’ve come across one of these.. And here one pops up today..
Running from “ms-support-ge8gl.xyz” ( hxxps://ms-support-ge8gl.xyz/chroot/us/ch/ )and asking victims to call a UK freephone number of:
“0808 189 6146” aka 08081896146 or +448081896146.
The warnings on the page read:
VIRUS ALERT FROM MICROSOFT This computer is BLOCKED Do not close this window and restart your computer Your computer's registration key is Blocked. Why we blocked your computer? The window's registration key is illegal. This window is using pirated software. This window is sending virus over the internet. This window is hacked or used from undefined location. We block this computer for your security. Contact microsoft helpline to reactivate your computer.
and
“WWW-Authenticate: Basic realm=”Suspicious activity detected on your IP address due to harmful virus installed in your computer. Call Toll Free now @ for any assistance. Your data is at a serious risk.There is a system file missing due to some harmfull virus Debug malware error, system failure. Please contact technicians to rectify the issue.Please do not open internet browser for your security issue to avoid data corruption on your operating system. Please contact technicians at Tollfree Helpline at @ PLEASE DO NOT SHUT DOWN OR RESTART YOUR COMPUTER, DOING THAT MAY LEAD TO DATA LOSS AND FAILURE OF OPERATING SYSTEM , HENCE NON BOOTABLE SITUATION RESULTING COMPLETE DATA LOSS . CONTACT ADMINISTRATOR DEPARTMENT TO RESOLVE THE ISSUE ON TOLL FREE @.”
Also associated are the following hostnames:
ms-support-cm83.tk
ms-support-geeir.xyz
ms-support-gdwru.xyz
ms-support-gdlts.xyz
ms-support-gdyyx.xyz
ms-support-ge2z7.xyz
ms-support-gdp9a.xyz
ms-support-gcou5.xyz
ms-support-gdjsl.xyz
ms-support-ge4fl.xyz
email-fix-problem.com
ms-support-gdtlr.xyz
ms-support-gd83t.xyz
ms-support-gdfmd.xyz
ms-support-gdraf.xyz
yes3no1.duckdns.org
ms-support-gcqye.xyz
ms-support-gcfzl.xyz
ms-support-gclgz.xyz
ms-support-gduqn.xyz
ms-support-gcubj.xyz
ms-support-gddl7.xyz
ms-support-gcimr.xyz
ms-support-gcwfr.xyz
ms-support-gd2mf.xyz
ms-support-gc7rn.xyz
ms-support-gakii.xyz
shrekbot.com
ms-support-gczsx.xyz
ms-support-gabjx.xyz
ms-support-gcd5d.xyz
ms-support-gc4c1.xyz
ms-support-gbwid.xyz
ms-support-gbn9x.xyz
ms-support-gbyun.xyz
ms-support-gafex.xyz
ms-support-gbsna.xyz
ms-support-gaspd.xyz
ms-support-gayws.xyz
ms-support-gaw2j.xyz
ms-support-gafeb.xyz
ms-support-gb4e6.xyz
ms-support-gbr0z.xyz
ms-support-gbljl.xyz
ms-support-gb9vj.xyz
ms-support-gbfcy.xyz
ms-support-gbi6f.xyz
ms-support-gbcpr.xyz
yes2c1.duckdns.org
ms-support-gan8p.xyz
ms-support-gakj7.xyz
ms-support-gahrb.xyz
ms-support-gaqlw.xyz
ms-support-ga2hn.xyz
v1-c4.duckdns.org
http://www.email-fix-problem.com
bitdefsukz.duckdns.org
freshtry-v1.duckdns.org
ver1-c2.duckdns.org
v1-c5.duckdns.org
ver1-c3.duckdns.org
madafaker.duckdns.org
monkeychan.duckdns.org
version-1.duckdns.org
donkeymilkman.duckdns.org
sukyomoma.duckdns.org
donkeychan.duckdns.org
chinkuchan.duckdns.org
monkeychandog.duckdns.org
I had $161.17 taken from my account on 28th June 2020 from gloessentialhelp.com. I don’t remember what dealings I’ve had with them. Thankyou kindly for letting me tell you