uploadjockey.com - Antivirus 2009
Type of advertisement.
Popup when entering the website of uploadjockey
.
Online scanner.
virus9-webscanner.com/2009/1/freescan.php?aid=77000423
Network traces.
uploadjockey.com request for popup advertisment.
CODE
<script type='text/javascript'>
//default pop-under house ad url
clicksor_enable_pop = true; clicksor_frequencyCap = -1;
durl = 'http://uploadjockey.com/popup.php';
clicksor_layer_border_color = '';
clicksor_layer_ad_bg = ''; clicksor_layer_ad_link_color = '';
clicksor_layer_ad_text_color = ''; clicksor_text_link_bg
= '';
clicksor_text_link_color = ''; clicksor_enable_text_link = false;
</script>
Let's head over to the Clicksor thus.
CODE
function clicksorpop(){if(!popedCLK)
{if(!usingXPSP2){popwinCLK=open('http://ads101.clicksor.com/serving/links.php?zone=...
CODE
GET /serving/links.php?zone=[removed]&durl=http%3A%2F%2Fuploadjockey.com%2Fpopup.php HTTP/1.1
Accept: */*
Accept-Language: en-us
~~~~~~~~~~~~~~~: ~~~~~ ~~~~~~~
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: ads101.clicksor.com
Connection: Keep-Alive
Cookie: TRUID=12168251938592
HTTP/1.1 200 OK
Date: Wed, 23 Jul 2008 15:01:36 GMT
Server: Apache/2.2.3 (Fedora)
X-Powered-By: PHP/5.1.6
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Content-Length: 1520
Connection: close
Content-Type: text/html; charset=UTF-8
<HTML>
<HEAD>
<title>.</title>
</HEAD>
<body>
<img src='http://ads101.clicksor.com/serving/tracking_id.php' width='1' height='1'>
<script language="javascript">
<!--
function maximizeWindow() {
self.blur();
if (parseInt(navigator.appVersion)>3) {
. if (navigator.appName=="Netscape") {
. //if (self.screenX>0 || self.screenY>0) self.moveTo(0,0);
.. if ( ''==0 && ''==0 ){// full page
... if (self.outerWidth < screen.availWidth)
.... self.outerWidth=screen.availWidth;
... if (self.outerHeight < screen.availHeight)
.... self.outerHeight=screen.availHeight;
.. }else{
....self.outerWidth=parseInt('');
....self.outerHeight=parseInt('');
.. }
. }else {
.. if ( ''==0 && ''==0 ){// full page
... //self.moveTo(-4,-4);
... self.resizeTo(screen.availWidth+8,screen.availHeight+8);
...}else{ //var popunder ?>
... //self.moveTo(50,50);
... var specWidth=parseInt('');
... var specHeight=parseInt('');
... if(specWidth>screen.availWidth){ specWidth= screen.availWidth; }
... if(specHeight>screen.availHeight){ specHeight= screen.availHeight; }
... self.resizeTo(specWidth+20,specHeight+8);
... //self.resizeTo(720+20,300+8);
...}
. }
}
self.blur();
}
try{
.maximizeWindow();
.self.blur();
}catch(e){}
self.location = "http://ad.byronadvertising.eu/drive/click.php?id=438";
try{
.if (navigator.appName=="Netscape") {
..if(window.opener){
...window.opener.focus();
..}
.}
}catch(e){}
// -->
</script>
</BODY>
</HTML>
From here we jump to ad.byronadvertising.eu/drive/click.php?id=438 where we encounter a obfuscated javascript.

Decoded we are redirected to ad.byronadvertising.eu/drive/scr.php? That page reveals us the location of our fake online scanner.
CODE
GET /drive/scr.php?a=754749&lang=en-us&id=438&ref= HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Accept-Language: en-us
~~~~~~~~~~~~~~~: ~~~~~ ~~~~~~~
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: ad.byronadvertising.eu
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Wed, 23 Jul 2008 15:02:30 GMT
Server: Apache
X-Powered-By: PHP/5.2.5
Set-Cookie: par=1; expires=Wed, 23-Jul-2008 15:02:30 GMT
Content-Length: 99
Keep-Alive: timeout=5, max=499
Connection: Keep-Alive
Content-Type: text/html
<script>location.href = 'http://virus-webscanner.com/soft.php?aid=000423&d=3&product=XPA';</script>
CODE
GET /soft.php?aid=000423&d=3&product=XPA HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Accept-Language: en-us
~~~~~~~~~~~~~~~: ~~~~~ ~~~~~~~
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: virus-webscanner.com
Connection: Keep-Alive
HTTP/1.1 302 Found
Date: Wed, 23 Jul 2008 15:02:31 GMT
Server: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.7a PHP/4.4.8 mod_perl/1.29 FrontPage/5.0.2.2510
X-Powered-By: PHP/4.4.8
Set-Cookie: soft=1; expires=Thu, 24 Jul 2008 15:02:31 GMT
Location: http://virus9-webscanner.com/2009/1/freescan.php?aid=77000423
Keep-Alive: timeout=10, max=500
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html
Note : The advertisment URL's have been shorted and some lines have been wrapped for visibility reasons.
virus-webscanner.com - 89.149.197.240
Website Title: XP antivirus protection - Official web site
ICANN Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Created: 2008-06-19
Expires: 2009-06-19
Updated: 2008-06-19
Name Server: NS1.MYNICK.NAME (has 1,148 domains)
Name Server: NS2.MYNICK.NAME
Name Server: NS3.MYNICK.NAME
Name Server: NS4.MYNICK.NAME
Whois Server: whois.publicdomainregistry.com
Server Type: Apache/1.3.41 (Unix) mod_ssl/2.8.31 OpenSSL/0.9.7a PHP/4.4.8 mod_perl/1.29 FrontPage/5.0.2.2510
IP Address: 89.149.197.240
IP Location - Berlin - Berlin - Netdirect
Domain Name: VIRUS-WEBSCANNER.COM
Registrant:
PrivacyProtect.org
Domain Admin ()
P.O. Box 97
Note - All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676
Websites.
- Securedstats.com
- Virus-webscanner.com
- Virus9-webscanner.com
- Windows-virus-scanner.com
ad.byronadvertising.eu - 78.159.114.116
Let's have a closer look at Byronadvertising because this is another dodgy advertising company as seen below.
ad.byronadvertising.eu - 78.159.114.116 / byronadvertising.eu - 88.214.204.40Website Title: Media Agency London UK
Meta Description: Byron Advertising is a fully recognised media agency providing online and traditional media planning and media buying services
iFrames: 1 ( Parts of page not indexable by most search engines. ) Registry Data
Created: 2008-05-21
Whois Server: whois.eu
IP Address: 88.214.204.40
IP Location - United Kingdom - Real International Business Corp
Whois Record
Domain: byronadvertising
Status: ON HOLD (*)
Registered: Wed May 21 2008
Registrant:
Please visit www.eurid.eu for webbased whois.
Agent Technical Contacts:
Phone: +1.2013775952
Fax: +1.3202105146
Email:
Registrar:
Name: PublicDomainRegistry.com
Website: www.publicdomainregistry.com
Nameservers:
ns1.hqhost.net
ns0.hqhost.net
(*) http://www.eurid.eu/en/faq#on_holdWhy is the domain name I want on hold? What does this mean?
When a domain name has a status of on hold it means that it has been registered, but is currently unavailable to be traded or transferred, pending the outcome of legal activity. Unless you are party to the legal proceedings, EURid staff may not provide you with any more information on the domain name other than that mentioned above.
whois.eu does not allow to copy records but you can check it out
here. (captha code requested).
Websites.
- I-need-love.com
- 18virgingirls.com
- 20searchonlinesite.net
- Adultxxxvideomovie1.com
- Airline333tickets.com
- Airline379tickets.com
- Allxxxpornogerlsx.com
- Asleysexygirlxcom.info
- Awmgraphics.com
- Belmondas.net
- Bestpills2008.com
- Bez-lekarstv.info
- Blogs4y.net
- Bondagekinky.com
- Bondagemeat.com
- Bondagenote.com
- Bondageworm.com
- Buycleocin.com
- Buypills2008.com
- Cialis-gl-pills.com
- Cialis-l-pills.com
- Darrambas.com
- Deliciousbigtits.com
- Derzolla.com
- Dlya-dvoih.info
- Dvizhenie-zhizn.info
- Exgirlfriendsextape.info
- Farmasearch2008.com
- Femnapks.org
- Flaxxvid.com
- Freelongsexvidsfr.com
- Freesexyassgirlsx.com
- Freshapples.info
- Fuckmodelasssexy.com
- Fullsitehost.info
- Garpy.info
- Girlnudegallaryvideox.com
- Hans2fucksexgirl.com
- Hedgecourtscouts.com
- Hotgirlpussy.net
- Hotowomensxxxgirls.com
- Housesolutionsforyou.com
- Hptallc.com
- Income-technologies.com
- Infodist1.com
- Jamie-eats.com
- Jproshin.info
- Land-to-mobile.com
- Lovespb.com
- Malosexaxxxgirls.com
- Maxstart.net
- Megapornuploadsxxx.com
- Megasexxxgerlxfr.com
- Mordasexxxuopgirl.info
- Moreaboutmen.com
- Myxtgerlsfuck.com
- Naughty-for-teens.org
- New-music-mp3.com
- Ohoosexyfuckgerlsx.info
- Oldmatureworld.com
- Onlinejobform.com
- Payday-gl-loans.com
- Payday333loans.com
- Phentermine-1-pills.com
- Phentermine-gl-pills.com
- Pills-diet-pills.com
- Platinka.com
- Polovoe-vospitanie.info
- Proekt-a.info
- Proekt-b.info
- Proekt-c.info
- Proektus.info
- Russian-history-art.net
- Russiantarot.com
- Sevaren.com
- Sexboxfreexxxgirls.com
- Sexgeshiaxgirls.info
- Sexiestgirlsintheworl.info
- Sexiestgirlsxlist.info
- Sexygirlsstripeachothe.com
- Sexyswimgirls10.info
- Sexywomenbrasxxx.com
- Sockdesign.com
- Stroitelnye-mashiny.info
- Sweetiebabes.com
- Teen-sex-free.com
- Teensgirlsf.com
- Teensssxpornocrut.com
- The1pixel.com
- Theloveis.com
- Toolsforyounow.com
- Topgadgets.info
- Trefullsexgirlsa.com
- Tri-anagram.com
- Uoisexyassmovie.com
- Uplogirlsxxxsexyass.com
- Vashi-dengi.net
- Viagra-77-pills.com
- Viagra-gl-pills.com
- Wap4ik.com
- Wasasexysgirlsmodel.com
- Wildgirlsexposedcax.info
- Wotoxxxsexwomenssite.com
- Xanax-gl-pills.com
- Xanax777pills.com
- Xgirlsblogmonster.com
- Xxxdownloadmegsexyg.com
- Xxxfreedirect.com
- Xxxgirlswosexyss.com
- Yamaha-sevastopol.com
- Youngirlfucksexsite.info
- Your-own-advisor.com
- Yourcameraguide.info
- Rusbd.com
- Autoloan2008mw.com
- Datiss79nn.com
- Debthelp2008mw.com
- Loanpayday911mw.com