Help - Search - Members - Calendar
Full Version: Bad Websites
B.I.S.S. Forums > Bluetack Software > HOSTS Section > Host Submissions
Pages: 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11
Samurai V
This is a little bizarre, so I'm not sure what to make of it.

When I was using the NASUM CGI-proxy server last night, it was running abnormally slowly, and I noticed repeated messages in the status bar that the browser was connecting with "www.boobs.com" laugh.gif I don't know if the latter site is malicious or not, or if it was just an attempt to serve ads. I was unable to find anything current about it on Google, and I don't want to visit to find out if it's a harmful site.
Kimberly
Hi Samurai V,

The site sounds bad indeed, I'll add it and see if someone complains about it.

From google search
QUOTE
I just went to the browser and typed in http//www.boobs.com and hit enter. 
To my surprise, it was not blocked and I had hit a site that takes control of the browser. Every time I closed a window, another opened up.


Details:

www.boobs.com - 66.154.81.152
OrgName: CP Cyber Wurx
OrgID: CPCW
Address: 4334 Unit L Arrow Tree
City: St. Louis
StateProv: MO
PostalCode: 63128
Country: US

NetRange: 66.154.0.0 - 66.154.95.255
CIDR: 66.154.0.0/18, 66.154.64.0/19
NetName: CONEPUPPY-COM

Registrant:
PJ Investment Group
Suite 320 3rd Floor, Barkly Wharf
Le Caudan Waterfront
Port Louis, one
Mauritius

Registered through: GoDaddy.com
Domain Name: BOOBS.COM
Created on: 23-Jan-99
Expires on: 23-Jan-07
Last Updated on: 27-Mar-04

Administrative Contact:
Investment Group, PJ webmaster@cumshots.com
....

Domain servers in listed order:
NS1.CONEPUPPY.COM
NS2.CONEPUPPY.COM

Kim
Samurai V
Thanks for the info, Kimberly. I wondered if I was just being paranoid, but it does sound like a malicious site.

The proxy I was using at the time was www.nasum.celebrityblog.net/cache.cgi, but I don't know for certain if they were the culprit. I have used this proxy about 10 times previously with no problems, though it's possible that they tried sleazy tactics before but were thwarted by my use of a Hosts file.

Cheers,
Samurai V
Samurai V
Banner ads:

lfs-ads.lfshosting.co.uk
Kimberly
Thanks, added smile.gif

Kim
Samurai V
Porn banners:

serve.pussycash.com
Kimberly
Thanks Samurai V, added.

Kim
monk
embracer.com - I've noticed ads being loaded from them.
MaKaVeLi
Ads:

ads.crucialparadigm.com

Rogue spyware apps:

www.razespyware.net
razespyware.net
Kimberly
@monk

Ads seems to be served by serve.embracer.com, no need to block the whole domain embracer.com. An accurate sample / webpage where you were hit by those ads would be welcome.

@MaKaVeLi

Thanks, added.

Kim
monk
I saw ads from them on torrentspy.com a few weeks ago and had added embracer.com to my list in Adblock with Firefox. I just checked around there, but I didn't see any current ads from them, sorry.
Kimberly
Thanks monk, I'll try to figure it out.

Kim
r00ted
no idea what this site is/does...www.nice-work.de.tc

But a guy said he was posting a picture, and he said to find it there. lol. I wasn't going to go clicking a blind link, that didn't end in an image format, so I think it might be okay to block. http://www.google.com/search?sourceid=navc...rk%2Ede%2Etc%22 only shows some guestbook site.

Im guessing it's soem sort of affiliate thing where he gets a referral or money per click....tho that's just a blind guess.
Samurai V
Banner ads:

integration.mediaplazza.com
r00ted
www.tqlkg.com
www.dot.tk
kasar.tk
www.kurtlardiyari.com

all related to IRC spam (Free porn at this link, etc :<). bombarded with pop ups that lead to those domain names. the "free porn" is mpeg.exe (which is actually some Litmus detection by Norton).
alien51
This one is related to the recent 40 million accounts breach from Mastercard. Itīs a phishing scam.

See this post for reference.

hxxp://www.mastercard-new-register.com
Samurai V
Serves ad I-frames:

bdv.bidvertiser.com
Samurai V
Someone I know just reported that he got a trojan from this link:

www.rlyrics.com/S%5CSteveWinwood/Valerie.asp

rlyrics.com is not currently blocked in the Hosts file.

I had no problem when I visited this site earlier, but then again, I use Firefox with Java turned off rather than IE.
Kimberly
Samurai V,

No, problem I'll add it together with www.lyrics.com, I saw myself 2 Hijack Logs involving those sites.

Thanks r00ted and alien51, added.

Kim

Samurai V
Banner ads:

gfx.avn.com
Samurai V
More banner ads (too late to edit my previous post to add them):

engine.xbiz.com
www.sexy-search.com
Samurai V
Tracking cookie:

count.mystat.pl
MaKaVeLi
Rogue spyware apps:

www.scan-it-clean-it.com
scan-it-clean-it.com
www.deluxe.spy-kill.com
deluxe.spy-kill.com

I saw ads coming from them:

ad.admarketplace.net
www.surfinvest.org
surfinvest.org
www.decroix.net
decroix.net
ads.yonkis.com

Counter:

counter.relmaxtop.com
Kimberly
Thanks Samurai V & MaKaVeLi, added. smile.gif

Kim
Kimberly
Thanks Samurai V & MaKaVeLi, added. smile.gif

Kim
Samurai V
Banner ads:

akamai.bizrate.com

(Also, congrats to Kimberly on the promotion to admin!)
Kimberly
Thanks Samurai V. smile.gif

akamai.bizrate.com added.

Kim
MaKaVeLi
According to this post http://spywarewarrior.com/viewtopic.php?p=85548#85548 this site infects you with alot of spyware if you click on the SNES link.

www.freeroms.com
freeroms.com

On a side note about 2 days ago when I updated the HOSTS file I noticed it had gone down about 2000 entries. Why was that?
Kimberly
Hi MaKaVeLi,

I'll look that up in depth before adding them, since I didn't get anything when visiting that site.

Removal of dead servers.
http://www.bluetack.co.uk/forums/index.php?showtopic=8406
QUOTE
All entries have been verified on 30 June 2005, dead servers were removed, except for CWS domains.


Kim
Samurai V
Banner ads (advertising how to create pop-up ads, no less!):

www.robrose.biz
Kimberly
Thanks Samurai V, added.

Kim
r00ted
www.webforadult.com
www.ilivecam.tk
webcamfree.megaxxxhost.com
www.nostop.cn.ms
idealo.de
log3.stats24.net
images.de.vu
www.cydots.com (looks to be a hosting site? but i got it as a pop up/under when exiting 1 of the above pages)
www.adboost.de.vu
www.smartdots.com

All were related to exe links in webpages (possibly virus/trojans) and/or pop ups, etc.
Kimberly
Thanks r00ted, added. smile.gif

Kim
Samurai V
Computer Associates reports that the following domains are used by the Win32.Alemod trojan:

ecjnoe3inwe.com
fjrewcer32.com
dkjfwekjnc4.com
alphaportal.com

Full report here http://www3.ca.com/securityadvisor/virusin...s.aspx?id=43297
Kimberly
Thanks Samurai V, added.

Kim
r00ted
Got a link on ICQ to mandy.ne1.net, and all the other domain names were harvested from the source/pop ups/etc

127.0.0.1 mandy.ne1.net
127.0.0.1 ezsexx.com
127.0.0.1 ars.streamray.com
127.0.0.1 images.streamray.com
127.0.0.1 adultrealsex.com
127.0.0.1 banners.images.streamray.com
127.0.0.1 nav.images.streamray.com
127.0.0.1 fpdownload.macromedia.com
127.0.0.1 www.streamray.com
127.0.0.1 webmasters.streamray.com
127.0.0.1 models.streamray.com
127.0.0.1 sofia.ne1.net
127.0.0.1 www.Ne1.net
127.0.0.1 www.R8.org
127.0.0.1 NE1.NET
127.0.0.1 R8.ORG

64.156.213.248 (external link on 1 of these sites points to this direct ip for dl, which is level 3 Communications)

In the source of the page, StreamRay seemed to be a company, and here are the other ranges:
StreamRay DSLNET-20001206-00086:64.205.42.32-64.205.42.63
StreamRay DSLNET-20010808-00661:65.85.194.0-65.85.194.31
Kimberly
I'll check that out r00ted, because I wonder how you were able to get the popups from a domain that has been closed.

QUOTE
mandy.ne1.net has been disbanded
The short URL account that you have tried to access has been closed/disbanded for good by the webmaster of NE1.net.


Kim
r00ted
oh wow. I guess they got shut down then. It was definately working at the time I posted wink.gif

Glad to see a bad site gone none the less.




EDIT:
here's some more (totally un-related to hte above reply, and the submission before that) but:
127.0.0.1 adserver.adremedy.com
127.0.0.1 affiliates.modchipstore.com

could probably be added.
Samurai V
Banner ads:

www.cash4fetisch.de
MaKaVeLi
Rouge anti-spyware apps:

www.pszweb.com
pszweb.com
www.noadware.onwww.net
noadware.onwww.net
spyware-removers.browse-online.com
www.spywarecure.net
spywarecure.net
www.spyware.theservicesforu.com
spyware.theservicesforu.com

Clickbank sites:

pszweb.apatrol.hop.clickbank.net
pszweb.spywarerem.hop.clickbank.net
pszweb.panicware.hop.clickbank.net
pszweb.pcss13.hop.clickbank.net
pszweb.noadware.hop.clickbank.net
pszweb.microa2.hop.clickbank.net
pszweb.xoftspy.hop.clickbank.net
pszweb.popnuker.hop.clickbank.net
pszweb.bugdoctor.hop.clickbank.net
pszweb.microa.hop.clickbank.net
pszweb.arsenal99.hop.clickbank.net
mbrown1230.adalert.hop.clickbank.net
addrmagic.noadware.hop.clickbank.net
hx74726176.spywarerem.hop.clickbank.net
hx74726176.xoftspy.hop.clickbank.net
hx74726176.microa2.hop.clickbank.net
hx74726176.noadware.hop.clickbank.net
weth22.noadware.hop.clickbank.net
akmoney.noadware.hop.clickbank.net
Kimberly
Thanks r00ted, Samurai V & MaKaVeLi

Added. smile.gif

Kim
Samurai V
I don't know if this can be blocked with the Hosts file, but script.weborama.fr serves an annoying pop-up-like advertisement on another site.
Kimberly
Hi Samurai V,

Sometimes things like that can be blocked, sometimes not. Do you have a link to a page where it happens ?

Kim
MaKaVeLi
Clickbank sites:

vtsodha.50secrets.hop.clickbank.net
vtsodha.adviediva.hop.clickbank.net
gamer11793.xoftspy.hop.clickbank.net
gamer11793.thefreecar.hop.clickbank.net
vtsodha.300dates.hop.clickbank.net
vtsodha.allasm.hop.clickbank.net
xxxxx.eckhertz.hop.clickbank.net
test4sure.dgrants.hop.clickbank.net
book94940.mp3center.hop.clickbank.net
topdateus.unicades.hop.clickbank.net
topdateus.jmareports.hop.clickbank.net
topdateus.50secrets. hop.clickbank.net
topdateus.meetwomen.hop.clickbank.net
winner.gnicom.hop.clickbank.net
www.clickbankworld.com
clickbankworld.com
www.clickbank.xbuyers.com
clickbank.xbuyers.com
www.1stpromotion.com
1stpromotion.com
www.bizzydays.com
bizzydays.com
r00ted
aliye.tk - has links to porn exe's
ikile.net - the actual "download" site hosting the EXE files
www.randevum.com - from the source, looks to be a pay-per-click/affiliate thing
Samurai V
QUOTE (Kimberly @ Jul 27 2005, 05:00 AM)
Hi Samurai V,

Sometimes things like that can be blocked, sometimes not. Do you have a link to a page where it happens ?

Kim

This is where I saw it before using Adblock: http://www.egs-avatars.com/e_gs_images/div...emmes/index.php

When I turned off Adblock and tried to reload the page, the page wouldn't reload, which I found curious dntknw.gif
Samurai V
Banner ads:

media.washingtonpost.com
Kimberly
@MaKaVeLi, thanks added. smile.gif

@r00ted

www.randevum.com looks like a portal, dunno since I don't understand the language.
QUOTE
aliye.tk - has links to porn exe's
ikile.net - the actual "download" site hosting the EXE files

Will look up those sites, ikile.net has "normal downloads" too from what I did see in a Google search...

@Samurai V

Thanks for the link, the popup is annoying indeed skull.gif
Shows up as an empty border for me since the site that serves the ads (www.smartadserver.com) is blocked. Still, adding script.weborama.fr blocked the whole popup, so it works. biggrin.gif

Looked up my firewall log and found 2 more to block while visiting that page:
static.weborama.fr
gold.weborama.fr

Kim
Samurai V
I'm glad the information proved to be of help. I was a little surprised that the Firefox popup blocker didn't stop the ad, but it's nice to know that the Hosts file can smile.gif
Kimberly
Same here, my popup blocker didn't stop it and my firewall that has ad-blocking features included didn't stop it neither. sad.gif

Kim
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.