Samurai V
Jun 13 2005, 07:38 AM
This is a little bizarre, so I'm not sure what to make of it.
When I was using the NASUM CGI-proxy server last night, it was running abnormally slowly, and I noticed repeated messages in the status bar that the browser was connecting with "www.boobs.com"

I don't know if the latter site is malicious or not, or if it was just an attempt to serve ads. I was unable to find anything current about it on Google, and I don't want to visit to find out if it's a harmful site.
Kimberly
Jun 13 2005, 03:51 PM
Hi Samurai V,
The site sounds bad indeed, I'll add it and see if someone complains about it.
From google search
| QUOTE |
I just went to the browser and typed in http//www.boobs.com and hit enter. To my surprise, it was not blocked and I had hit a site that takes control of the browser. Every time I closed a window, another opened up. |
Details:
www.boobs.com - 66.154.81.152
OrgName: CP Cyber Wurx
OrgID: CPCW
Address: 4334 Unit L Arrow Tree
City: St. Louis
StateProv: MO
PostalCode: 63128
Country: US
NetRange: 66.154.0.0 - 66.154.95.255
CIDR: 66.154.0.0/18, 66.154.64.0/19
NetName: CONEPUPPY-COM
Registrant:
PJ Investment Group
Suite 320 3rd Floor, Barkly Wharf
Le Caudan Waterfront
Port Louis, one
Mauritius
Registered through: GoDaddy.com
Domain Name: BOOBS.COM
Created on: 23-Jan-99
Expires on: 23-Jan-07
Last Updated on: 27-Mar-04
Administrative Contact:
Investment Group, PJ webmaster@cumshots.com
....
Domain servers in listed order:
NS1.CONEPUPPY.COM
NS2.CONEPUPPY.COM
Kim
Samurai V
Jun 14 2005, 12:10 PM
Thanks for the info, Kimberly. I wondered if I was just being paranoid, but it does sound like a malicious site.
The proxy I was using at the time was www.nasum.celebrityblog.net/cache.cgi, but I don't know for certain if they were the culprit. I have used this proxy about 10 times previously with no problems, though it's possible that they tried sleazy tactics before but were thwarted by my use of a Hosts file.
Cheers,
Samurai V
Samurai V
Jun 17 2005, 08:30 AM
Banner ads:
lfs-ads.lfshosting.co.uk
Kimberly
Jun 18 2005, 03:41 AM
Thanks, added
Kim
Samurai V
Jun 18 2005, 11:46 AM
Porn banners:
serve.pussycash.com
Kimberly
Jun 18 2005, 02:33 PM
Thanks Samurai V, added.
Kim
monk
Jun 18 2005, 06:02 PM
embracer.com - I've noticed ads being loaded from them.
MaKaVeLi
Jun 18 2005, 08:07 PM
Ads:
ads.crucialparadigm.com
Rogue spyware apps:
www.razespyware.net
razespyware.net
Kimberly
Jun 18 2005, 08:27 PM
@monk
Ads seems to be served by serve.embracer.com, no need to block the whole domain embracer.com. An accurate sample / webpage where you were hit by those ads would be welcome.
@MaKaVeLi
Thanks, added.
Kim
monk
Jun 18 2005, 08:46 PM
I saw ads from them on torrentspy.com a few weeks ago and had added embracer.com to my list in Adblock with Firefox. I just checked around there, but I didn't see any current ads from them, sorry.
Kimberly
Jun 18 2005, 11:06 PM
Thanks monk, I'll try to figure it out.
Kim
r00ted
Jun 19 2005, 06:50 AM
no idea what this site is/does...www.nice-work.de.tc
But a guy said he was posting a picture, and he said to find it there. lol. I wasn't going to go clicking a blind link, that didn't end in an image format, so I think it might be okay to block.
http://www.google.com/search?sourceid=navc...rk%2Ede%2Etc%22 only shows some guestbook site.
Im guessing it's soem sort of affiliate thing where he gets a referral or money per click....tho that's just a blind guess.
Samurai V
Jun 20 2005, 03:14 AM
Banner ads:
integration.mediaplazza.com
r00ted
Jun 20 2005, 01:59 PM
www.tqlkg.com
www.dot.tk
kasar.tk
www.kurtlardiyari.com
all related to IRC spam (Free porn at this link, etc :<). bombarded with pop ups that lead to those domain names. the "free porn" is mpeg.exe (which is actually some Litmus detection by Norton).
alien51
Jun 20 2005, 08:15 PM
This one is related to the recent 40 million accounts breach from Mastercard. Itīs a phishing scam.
See
this post for reference.
hxxp://www.mastercard-new-register.com
Samurai V
Jun 26 2005, 05:24 AM
Serves ad I-frames:
bdv.bidvertiser.com
Samurai V
Jun 26 2005, 11:03 AM
Someone I know just reported that he got a trojan from this link:
www.rlyrics.com/S%5CSteveWinwood/Valerie.asp
rlyrics.com is not currently blocked in the Hosts file.
I had no problem when I visited this site earlier, but then again, I use Firefox with Java turned off rather than IE.
Kimberly
Jun 26 2005, 01:48 PM
Samurai V,
No, problem I'll add it together with www.lyrics.com, I saw myself 2 Hijack Logs involving those sites.
Thanks r00ted and alien51, added.
Kim
Samurai V
Jun 27 2005, 06:13 AM
Banner ads:
gfx.avn.com
Samurai V
Jun 27 2005, 01:18 PM
More banner ads (too late to edit my previous post to add them):
engine.xbiz.com
www.sexy-search.com
Samurai V
Jun 29 2005, 07:35 AM
Tracking cookie:
count.mystat.pl
MaKaVeLi
Jun 29 2005, 01:38 PM
Rogue spyware apps:
www.scan-it-clean-it.com
scan-it-clean-it.com
www.deluxe.spy-kill.com
deluxe.spy-kill.com
I saw ads coming from them:
ad.admarketplace.net
www.surfinvest.org
surfinvest.org
www.decroix.net
decroix.net
ads.yonkis.com
Counter:
counter.relmaxtop.com
Kimberly
Jun 30 2005, 03:59 AM
Thanks Samurai V & MaKaVeLi, added.
Kim
Kimberly
Jun 30 2005, 04:01 AM
Thanks Samurai V & MaKaVeLi, added.
Kim
Samurai V
Jul 4 2005, 05:49 AM
Banner ads:
akamai.bizrate.com
(Also, congrats to Kimberly on the promotion to admin!)
Kimberly
Jul 4 2005, 02:07 PM
Thanks Samurai V.
akamai.bizrate.com added.
Kim
MaKaVeLi
Jul 5 2005, 07:10 PM
According to this post
http://spywarewarrior.com/viewtopic.php?p=85548#85548 this site infects you with alot of spyware if you click on the SNES link.
www.freeroms.com
freeroms.com
On a side note about 2 days ago when I updated the HOSTS file I noticed it had gone down about 2000 entries. Why was that?
Kimberly
Jul 5 2005, 09:05 PM
Hi MaKaVeLi,
I'll look that up in depth before adding them, since I didn't get anything when visiting that site.
Removal of dead servers.
http://www.bluetack.co.uk/forums/index.php?showtopic=8406| QUOTE |
| All entries have been verified on 30 June 2005, dead servers were removed, except for CWS domains. |
Kim
Samurai V
Jul 9 2005, 09:05 AM
Banner ads (advertising how to create pop-up ads, no less!):
www.robrose.biz
Kimberly
Jul 9 2005, 03:27 PM
Thanks Samurai V, added.
Kim
r00ted
Jul 12 2005, 05:13 PM
www.webforadult.com
www.ilivecam.tk
webcamfree.megaxxxhost.com
www.nostop.cn.ms
idealo.de
log3.stats24.net
images.de.vu
www.cydots.com (looks to be a hosting site? but i got it as a pop up/under when exiting 1 of the above pages)
www.adboost.de.vu
www.smartdots.com
All were related to exe links in webpages (possibly virus/trojans) and/or pop ups, etc.
Kimberly
Jul 13 2005, 03:02 PM
Thanks r00ted, added.
Kim
Samurai V
Jul 14 2005, 07:43 AM
Computer Associates reports that the following domains are used by the Win32.Alemod trojan:
ecjnoe3inwe.com
fjrewcer32.com
dkjfwekjnc4.com
alphaportal.com
Full report here
http://www3.ca.com/securityadvisor/virusin...s.aspx?id=43297
Kimberly
Jul 14 2005, 05:01 PM
Thanks Samurai V, added.
Kim
r00ted
Jul 17 2005, 02:55 AM
Got a link on ICQ to mandy.ne1.net, and all the other domain names were harvested from the source/pop ups/etc
127.0.0.1 mandy.ne1.net
127.0.0.1 ezsexx.com
127.0.0.1 ars.streamray.com
127.0.0.1 images.streamray.com
127.0.0.1 adultrealsex.com
127.0.0.1 banners.images.streamray.com
127.0.0.1 nav.images.streamray.com
127.0.0.1 fpdownload.macromedia.com
127.0.0.1 www.streamray.com
127.0.0.1 webmasters.streamray.com
127.0.0.1 models.streamray.com
127.0.0.1 sofia.ne1.net
127.0.0.1 www.Ne1.net
127.0.0.1 www.R8.org
127.0.0.1 NE1.NET
127.0.0.1 R8.ORG
64.156.213.248 (external link on 1 of these sites points to this direct ip for dl, which is level 3 Communications)
In the source of the page, StreamRay seemed to be a company, and here are the other ranges:
StreamRay DSLNET-20001206-00086:64.205.42.32-64.205.42.63
StreamRay DSLNET-20010808-00661:65.85.194.0-65.85.194.31
Kimberly
Jul 17 2005, 09:54 PM
I'll check that out r00ted, because I wonder how you were able to get the popups from a domain that has been closed.
| QUOTE |
mandy.ne1.net has been disbanded The short URL account that you have tried to access has been closed/disbanded for good by the webmaster of NE1.net.
|
Kim
r00ted
Jul 18 2005, 12:26 AM
oh wow. I guess they got shut down then. It was definately working at the time I posted

Glad to see a bad site gone none the less.
EDIT:
here's some more (totally un-related to hte above reply, and the submission before that) but:
127.0.0.1 adserver.adremedy.com
127.0.0.1 affiliates.modchipstore.com
could probably be added.
Samurai V
Jul 21 2005, 09:38 AM
Banner ads:
www.cash4fetisch.de
MaKaVeLi
Jul 26 2005, 03:43 PM
Rouge anti-spyware apps:
www.pszweb.com
pszweb.com
www.noadware.onwww.net
noadware.onwww.net
spyware-removers.browse-online.com
www.spywarecure.net
spywarecure.net
www.spyware.theservicesforu.com
spyware.theservicesforu.com
Clickbank sites:
pszweb.apatrol.hop.clickbank.net
pszweb.spywarerem.hop.clickbank.net
pszweb.panicware.hop.clickbank.net
pszweb.pcss13.hop.clickbank.net
pszweb.noadware.hop.clickbank.net
pszweb.microa2.hop.clickbank.net
pszweb.xoftspy.hop.clickbank.net
pszweb.popnuker.hop.clickbank.net
pszweb.bugdoctor.hop.clickbank.net
pszweb.microa.hop.clickbank.net
pszweb.arsenal99.hop.clickbank.net
mbrown1230.adalert.hop.clickbank.net
addrmagic.noadware.hop.clickbank.net
hx74726176.spywarerem.hop.clickbank.net
hx74726176.xoftspy.hop.clickbank.net
hx74726176.microa2.hop.clickbank.net
hx74726176.noadware.hop.clickbank.net
weth22.noadware.hop.clickbank.net
akmoney.noadware.hop.clickbank.net
Kimberly
Jul 26 2005, 05:11 PM
Thanks r00ted, Samurai V & MaKaVeLi
Added.
Kim
Samurai V
Jul 27 2005, 04:34 AM
I don't know if this can be blocked with the Hosts file, but script.weborama.fr serves an annoying pop-up-like advertisement on another site.
Kimberly
Jul 27 2005, 05:00 AM
Hi Samurai V,
Sometimes things like that can be blocked, sometimes not. Do you have a link to a page where it happens ?
Kim
MaKaVeLi
Jul 27 2005, 08:17 PM
Clickbank sites:
vtsodha.50secrets.hop.clickbank.net
vtsodha.adviediva.hop.clickbank.net
gamer11793.xoftspy.hop.clickbank.net
gamer11793.thefreecar.hop.clickbank.net
vtsodha.300dates.hop.clickbank.net
vtsodha.allasm.hop.clickbank.net
xxxxx.eckhertz.hop.clickbank.net
test4sure.dgrants.hop.clickbank.net
book94940.mp3center.hop.clickbank.net
topdateus.unicades.hop.clickbank.net
topdateus.jmareports.hop.clickbank.net
topdateus.50secrets. hop.clickbank.net
topdateus.meetwomen.hop.clickbank.net
winner.gnicom.hop.clickbank.net
www.clickbankworld.com
clickbankworld.com
www.clickbank.xbuyers.com
clickbank.xbuyers.com
www.1stpromotion.com
1stpromotion.com
www.bizzydays.com
bizzydays.com
r00ted
Jul 27 2005, 08:34 PM
aliye.tk - has links to porn exe's
ikile.net - the actual "download" site hosting the EXE files
www.randevum.com - from the source, looks to be a pay-per-click/affiliate thing
Samurai V
Jul 28 2005, 07:43 AM
QUOTE (Kimberly @ Jul 27 2005, 05:00 AM)
Hi Samurai V,
Sometimes things like that can be blocked, sometimes not. Do you have a link to a page where it happens ?
Kim
This is where I saw it before using Adblock:
http://www.egs-avatars.com/e_gs_images/div...emmes/index.phpWhen I turned off Adblock and tried to reload the page, the page wouldn't reload, which I found curious
Samurai V
Jul 28 2005, 07:45 AM
Banner ads:
media.washingtonpost.com
Kimberly
Jul 28 2005, 09:30 PM
@MaKaVeLi, thanks added.
@r00ted
www.randevum.com looks like a portal, dunno since I don't understand the language.
| QUOTE |
aliye.tk - has links to porn exe's ikile.net - the actual "download" site hosting the EXE files |
Will look up those sites, ikile.net has "normal downloads" too from what I did see in a Google search...
@Samurai V
Thanks for the link, the popup is annoying indeed
Shows up as an empty border for me since the site that serves the ads (www.smartadserver.com) is blocked. Still, adding script.weborama.fr blocked the whole popup, so it works.
Looked up my firewall log and found 2 more to block while visiting that page:
static.weborama.fr
gold.weborama.fr
Kim
Samurai V
Jul 29 2005, 05:15 AM
I'm glad the information proved to be of help. I was a little surprised that the Firefox popup blocker didn't stop the ad, but it's nice to know that the Hosts file can
Kimberly
Jul 29 2005, 05:46 AM
Same here, my popup blocker didn't stop it and my firewall that has ad-blocking features included didn't stop it neither.
Kim
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.