Forum Discussion

LazlowRave's avatar
LazlowRave
New Contributor

A Cox branded survey scam?

First off, this wasn't just a pop-up, this re-directed my current (secured) page while using one window/tab for browsing. It "pushed" my browser to this survey screen rather than the conceptual "pop-up" in a different window/tab.  So that's concern number one.

Secondly, I've NEVER had a "pop-up" or any "survey like" page force its way onto my current browsing page in all the years of using my computer.  Security and safety is priority and to see a survey pop-up labeled as Cox (my current ISP) and my IP Address while browsing a certified DigiCert SHA2 Secure Server website, is of main concern. Kind of felt like a slap in the face to my obvious mistaken sense of caution I've used in the years past.

Question One: Is this a legit Cox Survey? If so, how do I make sure it doesn't happen again? I'm like the old guy waving his cane at the kids playing in his driveway. If it's my computer, I don't want my Internet Service Provider parking on my screen forcefully redirecting me just for a survey because I take preventative measures to block such activities yet my ISP can just override my security just for a survey?

Question Two: If this isn't a legit Cox Survey, should I put the tin-foil hat on? From my computer, I run Cox issued wireless router/modem and the Internet Service Provider(ISP) is Cox themselves and further explaining I've NEVER had my browser point me down the wrong domain path with my overly secure system security and anti-virus/malware, which would lead me to think it was caused from within the Cox ISP framework. Is the security of Cox's customer information jeopardized? Or is this just a Domain Name System routing issue that can be fixed by a DNS flush, or reconfigured router/modem? Any suggestions or help, please. 

I was browsing DigiCert SHA2 Secure Server via Chrome (Up to Date: Version 55.0.2883.75 m), and the (enclosed) screen popped up. 

Screenshot link (https://s11.postimg.org/gfnvnnutf/cox_spam.png) 

Windows 10

The link below is the link that popped up, I substituted the IP Address as "000.00.000" which is still a clickable link which grows even further concern as phishing, spam/scam.

Full Link (minus actual IP Address) 

http://www.wpvsurveys.com/?sid=isp.opt.3a6x&ow=us.ao96ho9gbr467d49.nojs&isp=Cox%20Communications%20inc.&browser=Chrome&os=Windows&region=Nebraska&city=Omaha&ip=000.00.00.000&countryname=United%20States&device=DESKTOP&brand=Desktop&model=Desktop&country=US&track=www.boltedsurvey.com&tid=0ba6f51c-279d-4a68-82c0-dc5e8b9e9e67&caid=3fc624b7-4074-4b7f-aa2a-a68cbc6a0c97&head=ret.ss.asp.ncxw9c&did=5269&voluumdata=BASE64dmlkLi4wMDAwMDAwNS0yZmI4LTQxYTEtODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLmM0ZmU5ODAwLWJjNGEtMTFlNi04MWNkLTIzZmY2ZWEwMTdjYl9fY2FpZC4uM2ZjNjI0YjctNDA3NC00YjdmLWFhMmEtYTY4Y2JjNmEwYzk3X19ydC4uSEpfX2xpZC4uYTU1ZGVlMTgtNmFhOC00ZjU2LTg5ZTktYmExMjIxMjM0MGM1X19vaWQxLi5mMjQyZmIwOC05OWY5LTRiOTUtYTY5Yi00ODA4ZmY4MTE2OTlfX29pZDIuLmNmOTIwMWRiLWYyZjEtNGExYS1hZDI4LWRlYmVlNWI2ZDYxMF9fb2lkMy4uMTliZThlOTMtYzZiYS00M2FhLTgzY2UtZDYxZjhhNzE3ZDBlX19vaWQ0Li5kMjg3Y2ZlZS1jZDkzLTRkNDctOTMyZS1iY2ViM2ZlYjJjNTVfX29pZDUuLjFiY2RlMTI0LTEwYWQtNGEwNC04YWE5LTUxNzk0N2YzYjNhZV9fb2lkNi4uMjVlYzUyMGItNjc2YS00Y2Q4LWE0ZGMtMjg3M2MwMzIyMjA5X19vaWQ3Li42NDIzMGVjYy1jMTRiLTQwMTItOTI3Mi0wNzYyNTgzZjVmZDBfX29pZDguLmU0NWIxNjMyLWM3MGUtNGVjYi04YzE0LWIwYmM1NjE4MzhhMV9fb2lkOS4uNzA2NjY2MTItMTc1ZC00ZjVjLWFlZDQtOTFiMzFlOWI3YTg4X19vaWQxMC4uNGFiNTk5MjctMmU5OC00MDIwLTk0OGItZTI3NGZhN2E2ZGM3X19vaWQxMS4uMTUyZTBkYjktNTNkMy00NTkwLThlMmItMmM0N2JkNTY3NjJkX19vaWQxMi4uZjgyZmQwYTktYzQzZi00ZjY5LTgwMzQtMjNmZGNkMjJlZjE5X19vaWQxMy4uMzhkMWY0MzktMGE0NC00MzBlLWI0NGQtZTZmNWZiMjM5NDZlX192YXIxLi41MjY5X192YXIyLi4xMzAzMV9fdmFyMy4uNDU0MTRfX3ZhcjQuLlVTX192YXI1Li5PbWFoYV9fdmFyNi4uQ2hyb21lX19yZC4uZW5naW5lXC5cc3BvdHNjZW5lcmVkXC5caW5mb19fYWlkLi5fX2FiLi5fX3NpZC4u&c1=5269&c2=13031&c3=45414&c4=US&c5=Omaha&c6=Chrome

 

1 Reply

Replies have been turned off for this discussion
  • Tecknowhelp's avatar
    Tecknowhelp
    Valued Contributor II

    Looks fake to me. Basically says it's not connected to Cox in the fine print. Was probably just some script from a page that created the pop up. I would suggest a script block or Adblock.