Page 1 of 2

Scam Page

Posted: 20 Dec 2019, 08:22
by nnnik
A scam page at autohotkey.fr is impersonating our AutoHotkey.com website.
It will download and install malware.
It seems to target players of a specific MMORPG but it might be more.
More information will follow - for now please avoid the site and warn people to not visit the site.

Re: Scam Page

Posted: 20 Dec 2019, 08:30
by swagfag

Re: Scam Page

Posted: 12 Jan 2020, 09:10
by SyntaxTerror
As for now, the website has been suspended.

Re: Scam Page

Posted: 13 Jan 2020, 10:41
by joedf
Thats good to hear :+1:

Re: Scam Page

Posted: 17 Jan 2020, 16:44
by DRocks
recently, I've been redirected to this page a few times.
Can't access forums without getting the gotcha.js page

Re: Scam Page

Posted: 17 Jan 2020, 17:14
by gregster
DRocks wrote:
17 Jan 2020, 16:44
recently, I've been redirected to this page a few times.
To the (now suspended) scam page autohotkey.fr ? Redirected from where?
DRocks wrote:
17 Jan 2020, 16:44
Can't access forums without getting the gotcha.js page
You might want to expand on that... I am not sure what gotcha.js page refers to (well, the admins might know perhaps). Or do you mean captchas?

Re: Scam Page

Posted: 17 Jan 2020, 18:19
by joedf
I don't know :b

Re: Scam Page

Posted: 17 Jan 2020, 20:51
by DRocks
Sorry guys, I mean that - just by clicking the same google bookmark for autohotkey.com which lands normally on the home page - it happens that when I click on the forum link I will get a JavaScript message in a blank webpage.
Its gotcha.js script and it says that a scam page is trying to redirect me to a fake .fr site.
But Im using that same autohotkey.com bookmark for 2 years so I suppose its not on my side?

Btw, that gotcha.js page is the reason I came to this thread. The link to this is in the page and its the only way I can get back on the forums.

Re: Scam Page

Posted: 17 Jan 2020, 21:12
by gregster
Never heard of it, never seen it, can't reproduce it. Why would you be redirected by autohotkey.com to the fake, now defunct fr-website and at the same time be warned ?
We never knew of this website before someone made us aware of it, afaik, and consequently reported it to get it taken down.

I guess, the gotcha page might get created by the the fr-site's domain provider who has taken it down after we reported it, for people who would still get there via a redirect... 🤷‍♂️ Any information there about the message's origin ? Does it say something about LWS.fr (which would be the involved domain provider) ?

The fake site's forums sections seems to have silently redirected to our forums - but perhaps still under the fr-address (possibly "just" providing compromised AHK downloads) ... so perhaps your bookmark was always corrupt :eh: (I don't know how long this scam was going on).
Btw, since when is this happening? If it started recently, around the time the page was taken down, it would make sense that you suddenly wouldn't be redirected to our forums anymore by using a fake bookmark. Which URL is in the bookmark's properties?

Anyway, what you are describing, sounds highly suspicious. In your position, I would thoroughly check my computer for malware.
Perhaps your bookmark (or browser or whatever) was altered by malicious software... something is not right, I am sure.

Re: Scam Page

Posted: 18 Jan 2020, 11:24
by tank
Ill double check everything tonight

Re: Scam Page

Posted: 18 Jan 2020, 14:33
by DRocks
I'm not able to reproduce here at my home copmputer but it happenned at work 2 times this week (using a shared bookmark on my google account which is logged in at home and at work too)

The url is exactly : https://autohotkey.com/boards/
In fact, I used this exact bookmark to reply to you right now and all was good as it usually is.

I ran malwarebytes maybe at the beginning of the week at work and there was nothing found. Not a eprfect thing but atleeast it covers most possible malwares

Re: Scam Page

Posted: 18 Jan 2020, 19:25
by gregster
That's odd. But possibly tank can spot something.

Re: Scam Page

Posted: 19 Jan 2020, 07:52
by haichen
I bookmarked https://autohotkey.com/boards/ a long time ago. It never led me anywhere else. I usually use the link several times a day.

Re: Scam Page

Posted: 20 Jan 2020, 10:16
by DRocks
It just happened when I got to work now:

Chrome Bookmark = same as before and same as at my home = https://autohotkey.com/boards/

resulting page = https://www.autohotkey.com/boards/assets/javascript/gotcha.js
content =
var msg = "Dear visitor. This domain autohotkey.fr is trying to trick you. The official domain is autohotkey.com.\n\n";
alert(msg );
//location.href = "https://www.autohotkey.com/boards/viewtopic.php?f=2&t=70926"

The computer I am usin g at work is connected to a network with our 4 work computers, otherwise everything is a windows 10 usual setup. No wierd antivirus or firewall that I know of, and nothing else than windows defender is visible. Malwarebytes reports nothing wrong

Re: Scam Page

Posted: 20 Jan 2020, 12:54
by gregster
I see. I think that page is or was meant to prevent scammy redirections to (or from ?) the .fr-website.

Why this would trigger in your case, I am not sure. I still haven't seen this page in the wild. Now that the fr-domain is blocked by the provider, it's perhaps not relevant anymore. That might be a question for our admins.

Perhaps it's a cache or proxy issue that you still see it.

Re: Scam Page

Posted: 21 Jan 2020, 03:46
by SOTE
DRocks wrote:
20 Jan 2020, 10:16
It just happened when I got to work now:

Chrome Bookmark = same as before and same as at my home = https://autohotkey.com/boards/

resulting page = https://www.autohotkey.com/boards/assets/javascript/gotcha.js
content =
var msg = "Dear visitor. This domain autohotkey.fr is trying to trick you. The official domain is autohotkey.com.\n\n";
alert(msg );
//location.href = "https://www.autohotkey.com/boards/viewtopic.php?f=2&t=70926"

The computer I am usin g at work is connected to a network with our 4 work computers, otherwise everything is a windows 10 usual setup. No wierd antivirus or firewall that I know of, and nothing else than windows defender is visible. Malwarebytes reports nothing wrong
Maybe you need to flush the DNS cache of your computer, then see if things work properly.

Re: Scam Page

Posted: 21 Jan 2020, 07:18
by tank
Ill fix this today

Re: Scam Page

Posted: 21 Jan 2020, 09:33
by DRocks
tank wrote:
21 Jan 2020, 07:18
Ill fix this today
Thanks guys have a great day

Re: Scam Page

Posted: 22 Jan 2020, 12:55
by tank
try clearing your cache and let me know if this still occurs

Re: Scam Page

Posted: 22 Jan 2020, 15:46
by DRocks
tank wrote:
22 Jan 2020, 12:55
try clearing your cache and let me know if this still occurs
I just did and it fixes it :)