<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hosts News : Innovative Marketing Group</title><link>http://msmvps.com/blogs/hostsnews/archive/tags/Innovative+Marketing+Group/default.aspx</link><description>Tags: Innovative Marketing Group</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>LimeLight Networks and connecting the dots</title><link>http://msmvps.com/blogs/hostsnews/archive/2007/12/07/1384205.aspx</link><pubDate>Fri, 07 Dec 2007 07:28:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1384205</guid><dc:creator>winhelp2002</dc:creator><slash:comments>11</slash:comments><comments>http://msmvps.com/blogs/hostsnews/archive/2007/12/07/1384205.aspx#comments</comments><description>&lt;p&gt;Often times you have to&amp;nbsp;look hard to connect the dots ... however it now seems LimeLight has been affiliated with the &amp;quot;Innovative Marketing Group&amp;quot; (aka WinFixer) for some time. And as of today they are still hosting files that almost every major Antivirus/Antispyware programs detect as malware ...&lt;/p&gt;
&lt;p&gt;Landing on the below site you can see from the Microsoft Fiddler output the parties involved including LimeLight ...&lt;/p&gt;
&lt;p&gt;&lt;img height="474" alt="" src="http://mvps.org/winhelp2002/blog/antivirussecuritypro.gif" width="519" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;As you can see the majority are blocked (Result 502) by the &lt;a class="" href="http://www.mvps.org/winhelp2002/hosts.htm" target="_blank"&gt;HOSTS file&lt;/a&gt;, but you can plainly see the locations involved.&lt;/p&gt;
&lt;p&gt;[&lt;strong&gt;Limelight Networks&lt;/strong&gt; (United States) - Netrange: &lt;a class="" title="whois info" href="http://whois.domaintools.com/69.28.154.167" target="_blank"&gt;69.28.128.0 - 69.28.191.255&lt;/a&gt;]&lt;/p&gt;
&lt;p&gt;69.28.154.167&amp;nbsp; &lt;strong&gt;download.cdn.winsoftware.com&lt;/strong&gt;&lt;br /&gt;69.28.154.167&amp;nbsp; bsa.safetydownload.com&lt;br /&gt;69.28.154.167&amp;nbsp; &lt;strong&gt;setuphost.vo.llnwd.net&lt;br /&gt;&lt;/strong&gt;69.28.154.167&amp;nbsp; cdn.drivecleaner.com&lt;br /&gt;69.28.154.167&amp;nbsp; cdn.downloadcontrol.com&lt;br /&gt;69.28.154.237&amp;nbsp; sec.storageguardsoft.com&lt;br /&gt;69.28.154.237&amp;nbsp; software.protectdownloads.com&lt;br /&gt;69.28.154.237&amp;nbsp; content.onerateld.com&lt;br /&gt;69.28.154.237&amp;nbsp; &lt;strong&gt;locator.contentsvc.com&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="226" alt="" src="http://mvps.org/winhelp2002/blog/antivirussecuritypro2.gif" width="452" border="1" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;All of the above are aliases for &amp;quot;&lt;strong&gt;setuphost&lt;/strong&gt;.vo.llnwd.net&amp;quot; and there is no doubt that LimeLight is serving up these files from their network. In the above example run today the download was from:&lt;/p&gt;
&lt;p&gt;hxxp://&lt;strong&gt;download.cdn.winsoftware.com&lt;/strong&gt;/files/installers/WinAntiVirusPro2006FreeInstall.exe&lt;/p&gt;
&lt;p&gt;Here are a few more examples (URLs disabled) you can find thousands more via a Google search ...&lt;br /&gt;hxxp://&lt;strong&gt;bsa.safetydownload.com&lt;/strong&gt;/winpcdoctor.com/WinPCDoctor/setup_en.exe&lt;br /&gt;hxxp://&lt;strong&gt;content.onerateld.com&lt;/strong&gt;/antiworm2008.com/AntiWorm2008/install_en.exe&lt;br /&gt;hxxp://&lt;strong&gt;content.onerateld.com&lt;/strong&gt;/goldenantispy.com/GoldenAntiSpy/install_en.exe&lt;br /&gt;hxxp://&lt;strong&gt;content.onerateld.com&lt;/strong&gt;/avsystemcare.com/AVSystemCare/install_en.exe&lt;br /&gt;hxxp://&lt;strong&gt;content.onerateld.com&lt;/strong&gt;/winsecureav.com/WinSecureAv/install_en.exe&lt;br /&gt;hxxp://&lt;strong&gt;content.onerateld.com&lt;/strong&gt;/bestsellerantivirus.com/BestsellerAntivirus/install_en.exe&lt;/p&gt;
&lt;p&gt;As you can see every one of the above products are Rogue/Suspect and all are detected as such ... so let&amp;#39;s connect the dots and leave no doubt&amp;nbsp;who LimeLight is dealing with ...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Innovative Marketing, Inc.(&lt;a class="" title="whois info" href="http://whois.domaintools.com/innovativemarketing.com" target="_blank"&gt;innovativemarketing.com&lt;/a&gt;)&lt;br /&gt;&amp;nbsp;1876 Hutson Street&lt;br /&gt;&amp;nbsp;Belize City, BZ (aka: &lt;strong&gt;cdn&lt;/strong&gt;.&lt;a class="" title="whois info" href="http://whois.domaintools.com/downloadcontrol.com" target="_blank"&gt;downloadcontrol.com&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;SellMoSoft (&lt;a class="" title="whois info" href="http://whois.domaintools.com/anonymbrowser.com" target="_blank"&gt;anonymbrowser.com&lt;/a&gt;)&lt;br /&gt;&amp;nbsp;1876 Hutson Street&lt;br /&gt;&amp;nbsp;Belize City, BZ&lt;/p&gt;
&lt;p&gt;SetupAHost (&lt;a class="" title="whois info" href="http://whois.domaintools.com/contentsvc.com" target="_blank"&gt;locator.contentsvc.com&lt;/a&gt;)&lt;br /&gt;Admin 2135 A des Laurentides Blvd., Suite 170&lt;br /&gt;Laval, QC, H7M 4M2, CA (aka: &lt;strong&gt;setuphost.vo.llnwd.net&lt;/strong&gt;)&lt;/p&gt;
&lt;p&gt;Back in October I &lt;a class="" href="http://msmvps.com/blogs/hostsnews/archive/2007/10/06/1234124.aspx" target="_blank"&gt;posted&lt;/a&gt; some info and the above connection, but I thought it was worth another look ...&lt;/p&gt;
&lt;p&gt;&lt;img height="541" alt="" src="http://mvps.org/winhelp2002/blog/antivirussecuritypro3.gif" width="492" border="1" /&gt;&lt;/p&gt;
&lt;p&gt;Notice the two entries I highlighted in red above - &lt;strong&gt;SellMoSoft&lt;/strong&gt; and &lt;strong&gt;Setup a Host&lt;/strong&gt; ... this is the [choke] secure site that is used to purchase these bogus products. So as you can see this type activity has been going on for quite a while.&lt;/p&gt;
&lt;p&gt;Remember the &amp;quot;&lt;em&gt;locator.contentsvc.com&lt;/em&gt;&amp;quot; entry from above? Well back in March, &lt;a class="" href="http://msmvps.com/blogs/spywaresucks/archive/2007/03/24/704666.aspx" target="_blank"&gt;Sandi Hardmeier blogged&lt;/a&gt; about flash ads and being redirected to these same type sites ...&lt;/p&gt;
&lt;p&gt;hxxp://&lt;strong&gt;locator.contentsvc.com&lt;/strong&gt;/sites/winantivirus.com/main/img/en/flash_world_end.swf&lt;/p&gt;
&lt;p&gt;Even ExploitLabs &lt;a class="" href="http://explabs.blogspot.com/2007/11/banner-ads-from-major-sites.html" target="_blank"&gt;posted&lt;/a&gt; similar info about infected ads and the redirects:&lt;/p&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;&amp;quot;mlb.mlb.com&lt;/strong&gt;/index.jsp calls to &lt;/em&gt;&lt;em&gt;&lt;strong&gt;ad.doubleclick.net&lt;br /&gt;ad.doubleclick.net&lt;/strong&gt; calls to &lt;strong&gt;newbieadguide.com&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;newbieadguide.com&lt;/strong&gt; calls to &lt;strong&gt;fixthemnow.com&lt;/strong&gt; - this is where the code comes from&lt;br /&gt;&lt;strong&gt;fixthemnow.com&lt;/strong&gt; calls to &lt;strong&gt;bsa.safetydownload.com&amp;quot;&lt;/strong&gt;&lt;/em&gt; [emphasis mine]&lt;/p&gt;
&lt;p&gt;Again this content is being served up by LimeLight&amp;#39;s networks ... so I gotta ask &amp;quot;&lt;strong&gt;What are you thinking&lt;/strong&gt;&amp;quot;&lt;strong&gt;!!&lt;br /&gt;&lt;/strong&gt;Hopefully &lt;a class="" href="http://www.limelightnetworks.com/" target="_blank"&gt;LimeLight&lt;/a&gt; which seems to be a legit company, will sever their ties with Innovative Marketing Group.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1384205" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/hostsnews/archive/tags/Innovative+Marketing+Group/default.aspx">Innovative Marketing Group</category></item></channel></rss>