LimeLight Networks and connecting the dots

Often times you have to look hard to connect the dots ... however it now seems LimeLight has been affiliated with the "Innovative Marketing Group" (aka WinFixer) for some time. And as of today they are still hosting files that almost every major Antivirus/Antispyware programs detect as malware ...

Landing on the below site you can see from the Microsoft Fiddler output the parties involved including LimeLight ...

As you can see the majority are blocked (Result 502) by the HOSTS file, but you can plainly see the locations involved.

[Limelight Networks (United States) - Netrange: 69.28.128.0 - 69.28.191.255]

69.28.154.167  download.cdn.winsoftware.com
69.28.154.167  bsa.safetydownload.com
69.28.154.167  setuphost.vo.llnwd.net
69.28.154.167  cdn.drivecleaner.com
69.28.154.167  cdn.downloadcontrol.com
69.28.154.237  sec.storageguardsoft.com
69.28.154.237  software.protectdownloads.com
69.28.154.237  content.onerateld.com
69.28.154.237  locator.contentsvc.com

 

All of the above are aliases for "setuphost.vo.llnwd.net" and there is no doubt that LimeLight is serving up these files from their network. In the above example run today the download was from:

hxxp://download.cdn.winsoftware.com/files/installers/WinAntiVirusPro2006FreeInstall.exe

Here are a few more examples (URLs disabled) you can find thousands more via a Google search ...
hxxp://bsa.safetydownload.com/winpcdoctor.com/WinPCDoctor/setup_en.exe
hxxp://content.onerateld.com/antiworm2008.com/AntiWorm2008/install_en.exe
hxxp://content.onerateld.com/goldenantispy.com/GoldenAntiSpy/install_en.exe
hxxp://content.onerateld.com/avsystemcare.com/AVSystemCare/install_en.exe
hxxp://content.onerateld.com/winsecureav.com/WinSecureAv/install_en.exe
hxxp://content.onerateld.com/bestsellerantivirus.com/BestsellerAntivirus/install_en.exe

As you can see every one of the above products are Rogue/Suspect and all are detected as such ... so let's connect the dots and leave no doubt who LimeLight is dealing with ...

 Innovative Marketing, Inc.(innovativemarketing.com)
 1876 Hutson Street
 Belize City, BZ (aka: cdn.downloadcontrol.com)

 SellMoSoft (anonymbrowser.com)
 1876 Hutson Street
 Belize City, BZ

SetupAHost (locator.contentsvc.com)
Admin 2135 A des Laurentides Blvd., Suite 170
Laval, QC, H7M 4M2, CA (aka: setuphost.vo.llnwd.net)

Back in October I posted some info and the above connection, but I thought it was worth another look ...

Notice the two entries I highlighted in red above - SellMoSoft and Setup a Host ... this is the [choke] secure site that is used to purchase these bogus products. So as you can see this type activity has been going on for quite a while.

Remember the "locator.contentsvc.com" entry from above? Well back in March, Sandi Hardmeier blogged about flash ads and being redirected to these same type sites ...

hxxp://locator.contentsvc.com/sites/winantivirus.com/main/img/en/flash_world_end.swf

Even ExploitLabs posted similar info about infected ads and the redirects:

"mlb.mlb.com/index.jsp calls to ad.doubleclick.net
ad.doubleclick.net
calls to newbieadguide.com
newbieadguide.com calls to fixthemnow.com - this is where the code comes from
fixthemnow.com calls to bsa.safetydownload.com"
[emphasis mine]

Again this content is being served up by LimeLight's networks ... so I gotta ask "What are you thinking"!!
Hopefully LimeLight which seems to be a legit company, will sever their ties with Innovative Marketing Group.

Published Friday, December 07, 2007 1:28 AM by winhelp2002

Comments

# re: LimeLight Networks and connecting the dots

Friday, December 07, 2007 4:17 PM by bomfunk mc

contact me at

GvyxQN931zlcGDoV@spambox.us

please

# re: LimeLight Networks and connecting the dots

Monday, December 10, 2007 10:40 AM by Cd-MaN

LimeLight is a legitimate company. It is a CDN (Content Distribution Network) similar to Akamai, although not so big. I'm sure that any affiliation with malware is a mere oversight on their behalf.

# re: LimeLight Networks and connecting the dots

Monday, December 10, 2007 4:40 PM by winhelp2002

Cd-MaN,

I have no doubt LimeLight is a legitimate company, however it worries me how they could become affiliated with Innovative Marketing and SetUpAHost ... hopefully they will sever their ties with them ASAP.

# More malware found at Limelight Networks

Sunday, December 16, 2007 6:22 AM by Hosts News

Seems the harder I look the more malicious content is found running from Limelight Networks ... at least

# Limelight distributes hundreds of Rogue Antispyware products

Monday, December 17, 2007 5:40 AM by Hosts News

Looks like Limelight is involved in distributing hundreds of Rogue Antispyware products ... the majority

# re: LimeLight Networks and connecting the dots

Friday, December 21, 2007 1:28 AM by sam

So what is the bsa.safetydownload?  Is it something I need to remove?  My PC pops up error messages asking me to install something from them.  I have no idea who or what they are.

# re: LimeLight Networks and connecting the dots

Friday, December 21, 2007 5:14 AM by winhelp2002

Sam,

Yes it is something you should remove!

"Dealing with Unwanted Spyware and Parasites"

www.mvps.org/.../unwanted.htm

Perhaps you should contact LimeLight and ask them how to proceed ...

# re: LimeLight Networks and connecting the dots

Saturday, December 22, 2007 9:52 PM by Leslie

I also have been receiving pop ups that say critical error click balloon to fix and a website by the name of bsa.safetydownload.com address. The way it comes up it looks like a windows alert message and the page comes up replicating windows help. what should I do and how do I go about contacting this company. I stumbled upon this page when I searched 'bsa.safetydownload.com and this was the first that popped up.

# re: LimeLight Networks and connecting the dots

Sunday, December 23, 2007 12:57 AM by winhelp2002

Leslie,

Follow the instructions here:

"Dealing with Unwanted Spyware and Parasites"

www.mvps.org/.../unwanted.htm

# re: LimeLight Networks and connecting the dots

Sunday, December 23, 2007 10:15 PM by Leslie

Thank you! Alot of good information here.