April 2009 - Posts

ALERT: Malvertizement featuring Crawler

image

 

Same old same old.  The malvertizement hits the domains statcluster.com and enjoyspringtime.com (both domains have been mentioned on this blog several times).

The Adopstools results make it obvious that there is something suspicious:
http://www.adopstools.net/index.asp?section=quicklink&id=R59g0m36S016WwBW

From statcluster.com and enjoyspringtime.com we end up at crustat.com then on to either free-webscaners.com or truconv.com or olinredr2.com

From olinredr2.com to pyani.com to offer-provider.com

From trueconv.com to total-virusprotection.com

Posted by sandi with no comments
Filed under: ,

A frightening tale of computer infection and its consequences

It all started when I wanted to get more performance out of my video card. I download the latest drivers and included this virus.

Yep, that one simple act turned into an infection nightmare lasting three weeks.  I’m hoping Micky will work out exactly where he got the drivers from, and let us know (as well as warning whoever it is that is distributing the infected drivers.

The entire sorry tale is at www mickyj com / blog htm (link deliberately broken because I'm not sure that I want anybody going there yet).

To save you from the need to visit, I'll copy Micky's tale of woe verbatim.  Micky’s message to everybody is “Make sure to point out that no matter how cluey you are with IT (I have 20 years experience) these things are getting nasty.”

Reproduced with permission.

“Where have I been for almost 3 weeks? - 26 April 2009 - mickeyj.com

Virux/Virut
Keywords: PE_VIRUX.E-2, PE_VIRUX.C-2, Win32/Virut, Cryp_Virux, W32.Virut, PE_VIRUX.G-1, PE_VIRUX.F

... Offline. I am lucky enough to be one of the two people in Australia/New Zealand to have been infected with a rare strain of the Virux/Virut virus on my home PC. This is according to Trend Micro's Statistics. If you get this virus, be very afraid. It infected every EXE, SCR, DLL, HTM, HTML, ASPX file (And more). It copied itself to every USB device including my Camera flash cards and USB keys. It infected my Outlook email signatures (So I need to contact people I have emailed), Outlook stationary and more. I started seeing a pattern where infected executable files were about 20 kb larger than the originals and my internet would slow down (Due to incoming IRC connections). It was almost impossible to beat.

If I am like you, I have a whole heap of downloads on my PC that contains all my setup files. That included service packs, video drivers, scanner and printer drivers. All were infected. As I tried to reinstall my hardware I got reinfected. If I plugged in a memory card, I got reinfected. I even found the virus on my media centre and Xbox shared folders. It got everywhere. (Even played with my firmware on my router).

It all started when I wanted to get more performance out of my video card. I download the latest drivers and included this virus.

I reinstalled Windows XP Pro and all my additions at least 20 times between 26/3/09 - 16/4/09 before I finally got online again. I know this as I can no longer activate my Microsoft software. I have exceeded the install number allowed for a retail version of the product.

I got to the point of throwing out USB keys and starting to install everything fresh, from fresh downloads. Finally, I have myself back up and running (Minus all my data). Both AVG and Trend Micro could not protect me from reinfection. The virus is encrypted. It hides in space within exe files and nothing can detect is due to the encryption. Trend Micro etc can only detect it once the "exe" has started modifying other files. It happens so fast and Trend Micro and others can't clean it. I think I had 50 infections per second once the virus broke free. The virus targets all files in C:\Windows and C:\Windows\System32 first so basically, Windows becomes one big virus. It becomes especially hard to handle when AVG and Trend Micro start quarantining the virus, removing essential Windows files out of your system so ... Your system can't reboot. I also had the virus in system restore so the OS was completely tainted.

I got to the point where as soon as Trend or AVG triggered, I pressed the workstations reset button, shoved in my XP disk and started reformatting. I think my earlier mistake was trying to clean the virus. The more I tried, the more I got infected. I tried the Symantec removal tools and many others. They all did not deal with this particular strain of the virus.

If you see this virus, run away. Be very, very afraid. Format your PC. Get your files back from backups. Don't trust any files off your old system as the virus is encrypted and could be in any file. Certainly antivirus can detect this virus when it starts running, but by then, it is too late.

The virus detected was:
PE_VIRUX.E-2
PE_VIRUX.C-2
Win32/Virut
Cryp_Virux
W32.Virut
PE_VIRUX.G-1
PE_VIRUX.F

The virus downloaded and installed the following strains:
Virus.Virut.r
W32.Virut.CF
W32/Virut.n
PE_VIRUT.BO.
TROJ_VIRUX.A.

It also downloaded:
TROJ_AGENT.CHB
TROJ_MAILBOT.CN
TROJ_SMALL.NAX
TROJ_AGENT.ZNH

Google blocked my website
Keywords: Google, Website, Harm, iFrame

.. And rightly so. I have been hacked. It has been a shocking month for me thus far. My home PC covered in Viruses for the first half of the month, 1 week to breath and then my website hacked in the second half of the month.

When you Google mickyj.com you get a result that lists "This site may harm your computer" under my website. When you click the link for my website, you get a google page warning viewers not to go to my website. Obviously I wanted to find out more so I downloaded the code for my website and found 4 iFrame infections had been injected into the code.

I contacted Google Support through their help system, after fixing my website. It took a little bit to explain to them what I found, how I had cleaned it all and how the infection had likely occurred, then they "verified" and "reviewed" my website and it is up again in all it's glory. Thanks Google Guys. You were awesome. I was unable to request verification of my website through the web interface as my Domain name holder has some restrictions in place that I could not get around. The Google guys understood this and did an awesome job helping me through their help system. I can't stress enough how fantastic these guys were. Especially Johnathon at Google. you guys rock.

Website up and running, safe again on the 25th April.

New Wrinkle
Keywords: Twitter, Suspended

Twitter have blocked me for suspicious activity. 26th April Twitter suspended my account. What ?? I hope that this is related to the virus I had earlier and can be easily explained and then unblocked. This has not been a good month.

Maybe things will be better tomorrow as it is my Birthday !”

For what its worth Micky, Happy Birthday!

And… change all your passwords!

More information about the malvertizements that appeared on guardian.co.uk and electronicsnews.com.au

There are two malvertizements that I highlighted, being:

m1.au.2mdn.net/1949664/hp_300x250.swf
m1.emea.2mdn.net/989589/hp_728x90.swf

The 300x250 malvert touches hit-detect.com and measurehits.com.
The 728x90 malvert touches ydmstats.com and measurehits.com.

 

Redirects:

We go from measurehits.com to crustat.com.

From there we go to one of several different domains:

olinredr2.com/<<redacted>>
truconv.com/<<redacted>>
free-webscaners.com/<<redacted>> <--- fraudware domain

 

If a victim is redirected to olinredr2.com then they end up at pyani.com,then offer-provider.com.  offer-provider.com is a fraudware domain touting fake security software under various names such as "SpywareRemover" and "VirusRemover2009" and "AntiSpywareSolution 2009".

If a victim is redirected to truconv.com then they end up at total-virusprotection.com, another fraudware domain.

Posted by sandi with no comments
Filed under: ,

Further information regarding the malvertizements touting ebay discovered at perezhilton.com

The malvertizement redirects victims to various fraudware/scareware products via several redirects (some of the URLs change at random – victims don’t hit all of the domains listed below).

These are the URLs that are hit by the malvertizement – we have seen all of them before:

statcluster.com/crossdomain.xml
statcluster.com/c/index.php?id<<redacted>>
crustat.com/ts/in.cgi?<<redacted>>
olinredr2.com/?accs=<<redacted>>
pyani.com/in.cgi?<<redacted>>
offer-provider.com/<<redacted>>
truconv.com/<<redacted>>
justwebsecurity.com/<<redacted>>

 

Final destinations:

offer-provider.com is a fraudware domain touting fake security software under various names such as "SpywareRemover" and "VirusRemover2009" and "AntiSpywareSolution 2009".

trueconv leads to the fraudware total-virusprotection.com.

justwebsecurity.com leads to a fake "System Security" scanning page.

Posted by sandi with no comments
Filed under: ,

ALERT: Malvertizing at perezhilton.com

perezhilton.com is an extremely popular site, and the potential audience for the malvertizers is *huge*.

Kimberley and I make a great team.  I knew that there was a malvertizement being displayed on perezhilton.com, but I hadn’t been able to get definitive proof – Kimberley got it.

Check out the screenshot below – note that the referrer is perezhilton.com/page/2

Also, note that the screenshot is evidence of a GET request for f.blogads.com/www/delivery/ai.php?filename=ebay_300x250.swf&contentype=swf

image

 

Now, let’s look at the rest of the capture:

image

statcluster.com is a known bad domain – so is enjoyspringtime.com, crustat.com, olinred2.com, pyani.com and offer-provider.com.

The malvertizements have been reported to blogads.com and I have every confidence that they will be removed very quickly.

This is what the malvertizement looks like:

image

Posted by sandi with no comments
Filed under: ,

ALERT: Malvertizing at electronicsnews.com.au

image

 

Edited to fix subjectline

It is a malvertizement featuring HP (visually identical to the HP malvertizement described in my earlier article):
http://msmvps.com/blogs/spywaresucks/archive/2009/02/28/1674634.aspx

The malvertizement itself is at this URL:
m1.au.2mdn.net/1949664/hp_300x250.swf

Adopstools test results here:
http://www.adopstools.com/index.asp?section=quicklink&id=ZdWLlE0YcK7rkK5C

Yes, it is the same advert that we found on guardian.co.uk
http://msmvps.com/blogs/spywaresucks/archive/2009/04/27/1691363.aspx

The malvertizement has been reported to the appropriate parties.

Posted by sandi with no comments
Filed under: ,

ALERT: Malvertizing at guardian.co.uk

There are two of them, both featuring HP (the ads have been documented on this blog in the past).

Both advertisements are being served via 2mdn.net and have been reported to the appropriate parties.

 

m1.emea.2mdn.net/989589/hp_728x90.swf

image

 

m1.au.2mdn.net/1949664/hp_300x250.swf

 image

Posted by sandi with 2 comment(s)
Filed under: ,

ALERT: blogads.com is serving malvertizements

The malvertizements have been reported to blogads.com.

image

z.blogads.com/www/delivery/afr.php?n+a91736e9&zoneid=86&cb=INSERT_RANDOM_NUMBER_HERE

image

z.blogads.com/www/delivery/afr.php?n+aa00ce7a&zoneid=87&cb=INSERT_RANDOM_NUMBER_HERE

 

The adverts hit statcluster.com, enjoyspringtime.com and crustat.com (all known bad domains).

Posted by sandi with 1 comment(s)
Filed under: ,

Another fake Phoenix University malvertizement

image

 

This one is using the same domains as the previous version (although it should be noted that, although visually identical, this one had a different Hash to the one I looked at yesterday).

Victims end up at one of two fraudware sites, scanspywareonline.com or justwebsecurity.com.

I have written about justwebsecurity.com already, so let’s take a look at scanspywareonline.com

scanspywareonline.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS PVT. LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Created 4 March 2009
NS1H1.DNS-MANAGE.COM
NS2H1.DNS-MANAGE.COM
NS3H1.DNS-MANAGE.COM
DN4H1.DNS-MANAGE.COM

IP: 205.252.24.226 - Virginia, Herndon ,Beyond The Network America Inc

Registrant details hidden behind privacyprotect.org

 

 

 

IP address shared with 21 other sites (take a deep breath – all except for one list DIRECTI as the ICANN Registrar – seriously, you’d think that DIRECTI would have learned what to watch out for by now.

advancesoftpc.com
ICANN Registrar: ENOM INC
Registrant: Internet Marketing Ltd
Volodymyr Kushnir
Patrisa Lumumby str. 7, flat 30, Kiev
Registration service: namecheap.com

antispywarepro.net
ICANN Registrar: DIRECT INTERNET SOLUTIONS
Created 16 September 2008
Registrant details hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

kweekz.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 27 November 2006
Registrant: "admin", unused@fabrica.net.ua, Lomonosova 59, Kiev
Registration service: DNS-MANAGE.COM

netspywarescan.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 19 December 2008
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

online-spyware-scan.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 4 March 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

onlinespyscan.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

onlinespyscan.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

onlinespyscanner.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

onlinespyscanner.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

onlinespywarescanner.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 4 March 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

onlinespywaresscanner.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

onlinespywaresscanner.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM.

pcspeed-up.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 8 May 2008
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

scanforspywares.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

scanforspywares.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

scanspywareonline.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 4 March 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

smartpcsoft.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 9 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

spywareonlinescan.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

spywareonlinescanner.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 7 April 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

spywarescanonline.net
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 4 March 2009
Registrant hidden behind privacyprotect.org
Registration service: DNS-MANAGE.COM

winflashmedia.com
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 16 January 2008
Registrant: Bogdan Pankiv (software@fabrica.net.ua - note, see kweekz.com above), Gorkogo 122, apt.19, Kiev
Registration service: DNS-MANAGE.COM

Registration service used:

DNS-MANAGE.COM
ICANN Registrar: DIRECTI INTERNET SOLUTIONS
Created 1 March 2009
Registrant hidden behind privacyprotect.org

Posted by sandi with 2 comment(s)
Filed under: ,

ALERT: Malvertizement featuring Phoenix University

PLEASE TREAT ALL CONTENT FROM PERFECT-BANNER.COM WITH EXTREME CAUTION

image

 

Adopstools scan results:
http://www.adopstools.net/index.asp?section=quicklink&id=36xxrvvFRC85pkp7

Malvertizement host:
perfect-banner.com

Hits the domains statcluster.com and enjoyspringtime.com

From there to crustat.com, pnfzetnax.net (or justwebsecurity.com), then to 78.47.132.220.

-----

perfectbanner.com

ICANN Registrar: ENOM, INC.
Created 10 March 2009
NS1.PERFECT-BANNER.COM
NS2.PERFECT-BANNER.COM
NS3.PERFECT-BANNER.COM
NS4.PERFECT-BANNER.COM

IP: 89.149.244.137 - Hessen, Frankfurt Am Main, Netdirekt E.k

Shares IP with one other site, being 4netbanners.com - please treat the domain 4netbanners.com with extreme caution

Registrant:
Nexton Limited
Whois Agent
Irpinskaya 69
Kiev, 03142
UA

Registration service provided by:
Contact: director@climbing-games.com
ruler-domains.com
director@climbing-games.com has been mentioned on this blog before, in association with the fraudware domain ie-security.com:
http://msmvps.com/blogs/spywaresucks/archive/2009/02/02/1668084.aspx

Also associated with the malware domain xp-police-av.com:
http://www.precisesecurity.com/blogs/2009/02/17/xp-police-av/

-----

4netbanners.com
ICANN Registrar: KEY-SYSTEMS GMBH
Created 9 April 2009
NS1.MYDOMAIN-IN.NET
MS2.MYDOMAIN-IN.NET

IP: 89.149.244.137 - Hessen, Frankfurt Am Main, Netdirekt E.k

Registrant:
Primak Vornen (primakvornen@myself.com
Punane 34
Tallin 13619
EE
37 263 176 2334

-----

ruler-domains.com
ICANN Registrar: ENOM INC
Created 17 November 2008
NS5.NAMESERVER01.COM
NS6.NAMESERVER01.COM

IP: 78.46.88.142 - Bayern, Gunzenhausen, Hetzner

Shares IP with 12 other sites being av-cash.com, billingpayment.net, gilded-youth.com, iloveyourbrain.com, loyalbox.biz, richisoftware2.com, ruler-cash.com, ruler-dating.com, ruler-domains.com, ruler-search.com, vashkont.com, vashkontakt.com, vkontaktev.com - all domains should be treated with extreme caution.

Registrant:
Sergey Ryabov (director@climbing-games.com)
7 921 927 0961
Fax: 7 921 927 0961
Scherbakova st., 6-38
Saint-Petersburg, 197375
RU

-----

statcluster.com
ICANN Registrar: YESNIC CO. LTD
Created: 3 April 2009
NS1.STATCLUSTER.COM
NS2.STATCLUSTER.COM

IP: 174.37.196.175 - Texas, Dallas, Softlayer Technologies Inc

Registrant:
Burt N Charlesworth (burtn@mail.com)
971 Hidden Valley Road
170742
US
2129887344 (this number traces to New York, and is not owned by Burt N Charlesworth, or anybody with the same or similar surname)

-----

enjoyspringtime.com
ICANN Registrar: COMMUNIGAL COMMUNICATIONS LTD
Created 20 March 2009
DNS1.COMMUNIGAL.NET
DNS2.COMMUNIGAL.NET

IP: 38.99.168.101 - Ontario, Toronto, Psinet Inc

Registrar:
Robert Robinson (robertrobinson@mail.com)
4452 Dogwood Lane, Phoenix, 85012
602 520 553 9781

We've come across Robert Robinson before, that is the ID used to register the domain welovesandi.com (http://msmvps.com/blogs/spywaresucks/archive/2009/04/01/1683651.aspx)

-----

crustat.com
ICANN Registrar: COMMUNIGAL COMMUNICATIONS LTD
Created: 5 March 2009
DNS1.COMMUNIGAL.NET
DNS2.COMMUNIGAL.NET

IP: 94.76.213.234 - UK, Hp3-right

Shares IP with one other domain, being tldst.com

Registrant details hidden behind WHOIS privacy service

-----

pnfzetnax.net
ICANN Registrar: INTERNET INVEST, LTD. DBA IMENA.UA
Created: 20 March 2009
NS1.IMENA.COM.UA
NS2.IMENA.COM.UA

IP: 85.10.243.126 - Hetzner, Germany

Registrant:
David Armstrong (avidarms@mail.com)
1785 Haul Road
Golden Valley
55427
1 6512387511 (traces to Minneapolis, MN)

-----

justwebsecurity.com
ICANN Registrar: REGTIME LTD
Created 20 April 2009
NS1.JUSTWEBSECURITY.COM
NS2.JUSTWEBSECURITY.COM

IP: 91.212.65.55 - Ukraine, Eurohost Llc

Shares IP with three other domains, being globalsecurityscan.com, onlinebrandsecurity.com and scanprotectiononline.com (all domains should be treated with extreme caution).

Registrant:
Rene Clay (renepclay@text2re.com)
1555 Lake Floyd Circle
Chevy Chase
MD 20815
US
1 301 941 5618

Posted by sandi with no comments
Filed under: ,

Another lesson in assessing the reliability of credit references

ALERT:  Please treat any content from these domains with suspicion, and be very careful about any credit reference you receive that refers to:

yourdirectmedia.com, atlantmedia, traffichunters, olympicmedia.net ads2revenue, adsrepublic, truemedian.com, readadsolutions.com, adsmanagement.com

ALERT: Watch out for the impersonation of legitimate businesses in credit reference checks.  Details below.

-----

It is fascinating to watch the way that the people behind malvertizing do business.  It wasn't that long ago that they were inherently lazy, using the same Registrars over and over, hosting myriad malicious web sites at the same IP address, using the same name servers for multiple domains, using different combinations of the same names and email addresses over and over for WHOIS purposes, using the same templates for their fake 'advertising network' websites... redundancy was a foreign concept to them.

Even the credit references that they supplied were easy to spot as dodgy if you knew what to look for.  There was often an obvious association between different domains used by referees if we bothered to take even a cursory look at the Registrant and hosting details.

That being said, the bad guys have been changing their modus operandi with regards to trade references and it is getting harder to spot problems.  Let's have a look at some recent examples that have crossed my desk.

 

YOURDIRECTMEDIA.COM SHENANIGANS:

Yourdirectmedia.com have been caught supplying AtlantMedia as a credit referee – a referee that is easy to discredit - atlantmedia is a known bad actor.

Cite: http://msmvps.com/blogs/spywaresucks/archive/2008/12/10/1656329.aspx

atlantmedia.net used to have IP address 89.149.235.24 - Lithuania Kaunas Netdirect-uab-retrogarsas (web site currently not resolving).

A connection has been discovered between atlantmedia.net and olympicmedia.net (also offline) – its last IP was 212.95.53.164 and it used to be at IP 216.195.54.212 (atlantmedia.net used to have the IP 216.195.57.40)

Let's not forget that a connection has been drawn between traffichunters, olympicmedia and the now infamous Innovative Marketing, thanks to an email slip-up.

Cite: http://msmvps.com/blogs/spywaresucks/archive/2009/03/27/1682054.aspx


image

 

IMPERSONATION OF LEGITIMATE COMPANIES

When I first saw the name Tribalfusion listed as a referee for yourdirectmedia, my immediate reaction was "what the hell is tribalfusion doing being a referee for these guys?"  A bit of digging revealed the truth.

The referee given was "Tribalfusion, Mike Carter, 215 789 9793".  But, it just so happens that that phone number belongs to "ads2revenue", not "tribalfusion" - we know this because the number used to be on the ads2revenue web site (although the phone number has since been removed from the ads2revenue site).

ads2revenue
ICANN REGISTRAR: ENOM, INC
Date created: 12 November 2008

NS1.ADS2REVENUE.COM - 93.190.141.36
NS2.ADS2REVENUE.COM - 93.190.141.37
NS3.ADS2REVENUE.COM - 212.95.32.48
MAIL.ADS2REVENUE.COM - 212.95.32.48

IP: 212.95.32.48 - Hessen, Frankfurt Am Main - Netdirekt E.k

Dedicated Hosting

Registrant: Hidden behind WHOISGUARD

Already mentioned on spywaresucks once before - cite: http://msmvps.com/blogs/spywaresucks/archive/2009/02/28/1674707.aspx

Another referee supplied by yourdirectmedia.com was "Classmatesmedia, Rick Harris, 619 949 8952".  In this case there was nothing definitive to be discovered about the phone number, but we still have cause for concern.  As far as I know, classmatesmedia does not directly sells advertising - rather, United Online Advertising Solutions does that (uolmediagroup.com)

 

THE USE OF EXECUTIVE (AKA MANAGED, AKA SERVICED) OFFICES 

Many of us are careful to check things like phone numbers and addresses when researching potential advertisers and credit references, and that good habit is becoming more common.  Because of this it has become harder for the bad guys to use fake phone numbers and addresses.

To get around this, the bad guys are sometimes using executive offices as the contact address and phone number for credit references (and their own web sites).

ADSREPUBLIC SHENANIGANS

adsrepublic has been trying to sell advertising under pretty typical “red flag” circumstances (lots of urgency, please run ads as soon as possible etc). 

Their email message headers revealed that the email was coming from Latvia (despite the advertiser claiming to be based in Atlanta, Georgia - specifically Suite 1500, 3500 Lenox Road).  That address in Atlanta is a "virtual office":

Cite: http://www.interactiveoffices.com/search.php?id_country=1&id_state=2&id_city=3

 

The referees supplied by adsrepublic were:

truemedian.com, realadsolutions.com and adsmanagement.com

 

Let's look at the referee addresses – all are Executive/Virtual Offices:

truemedian.com - suite 300, 1800 John F Kennedy Boulevard
cite: http://jfk.yourofficeusa.com/

realadsolutions.com - Suite 700 210 Interstate North Pkwy
cite: http://www.interactiveoffices.com/officescanada.php?id_state=2&id=37

adsmanagement.com - Suite 1500, 121 south orange avenue
cite: http://orlando.youroffice.com/

 

truemedian.com
ICANN Registrar: 1 & 1 INTERNET AG
Created 30 January 2009
NS1.PANELBOXMANAGER.COM
NS2.PANELBOXMANAGER.COM

IP: 72.55.186.42 - Quebec, Montreal, Panelbox

IP shared with 506 other sites

Registrant details hidden behind 1&1 Private Registration

-----

realadsolutions.com
ICANN Registrar: 1 & 1 INTERNET AG
Created 30 January 2009
NS1.PANELBOXMANAGER.COM
NS2.PANELBOXMANAGER.COM

IP: 72.55.186.42 - Quebec, Montreal, Panelbox

IP shared with 506 other sites

Registrant details hidden behind 1&1 Private Registration

-----

adsmanagement.com
ICANN Registrar: NAMEVIEW, INC
Created 29 September 2003 <!>
NS1.HITFARM.COM
NS2.HITFARM.COM

IP: 208.87.33.150 - New Providence, Nassau, Secure Hosting Ltd

IP shared with 488,707 other sites

Registrant details currently hidden behind Whois Identity Shield

 

Now let’s look at the advertisement itself.

adsrepublic.com was offering advertising using the domain lorentrio.com - a domain that is interesting in and of itself.

lorentrio.com was registered via Directi on the 29th of March.  With WHOIS details hidden behind privacyprotect, the domain is immediately suspicious. At time of writing, the IP address for lorentrio.com is 94.75.216.152 (Amsterdam, Leaseweb).  It shares IP with the following domains:

alitasis.com, idatrinity.com, junstring.com, kernerlane.com, lacoste-ads.com, mosdao.com, namlean.com, nokia-corp.com, tornadomb.com

lacoste-ads.com and nokia-corp.com are immediate causes for concern, and make me wonder if there are (or will be) malvertizing campaigns circulated that pretend to represent Lacoste or Nokia.

nokia-corp.com was created on 14 April 2009, registered via Directi and with Registrant information again hidden behind privacyprotect.

lacoste-ads.com was created on 2 March 2009, registered via Directi and with Registrant information again hidden behind a privacy service.

Posted by sandi with no comments
Filed under: ,

ALERT: Please treat advertising at clevescene.net with extreme caution

image

 

Same old same old. A rhapsody advertisement.  Reported to clevescene

URL of malvertizement:
72.167.208.179/adserver/www/images/rhapsody728x90.swf

Adopstools results confirming malicious code:
http://www.adopstools.com/index.asp?section=quicklink&id=IN91asr1bK1W3pv3 

URLs encountered:
hitoptimist.com/crossdomain.xml

and:
hitoptimist.com/c/index.php?<<redacted>>

as well as:
statsnclick.com/?cmpid=<<redacted>>

From there we end up at:
crustat.com/ts/in.cgi?<<redacted>>

Before ending up at:
pnfzetnax.net/pro/uspremorse/

Before ending up at the fraudware site:
78.47.132.220/cr/adv/142/index.html

Posted by sandi with no comments
Filed under: ,

ALERT: Please treat advertising from letssingit.com with extreme caution

image  image  image

Note, the malvertizement was reported to “kraz”, who is apparently responsible for advertising on the letssingit.com web site, a couple of days ago via the "Advertise on letssingit” contact form.  The advertisement was immediately removed.

letssingit.com is hosting a malicious advertising featuring SWATCH as per this URL:
includes.letssingit.com/ads/SWATCH300x250.swf

Adopstools check:
http://www.adopstools.net/index.asp?section=quicklink&id=8973swVapP174q1A

The malvert hits some well known bad domains, being cosmotraf.net and welovesandi.com.

From there we bounce through various domains, including crustat.com, olinredr2.com, truconv.com, top-name.cn, pyani.com  before ending up at one of several fraudware sites including offer-provider.com and total-virusprotection.com.

Posted by sandi with no comments
Filed under: ,

Heh

image

Credit: http://xkcd.com/570/

Posted by sandi with no comments
Filed under:

ALERT: Please treat advertising from beyond.com with extreme caution

image   image

Note: the malicious SWF has been reported to beyond.com.

 

Beyond.com is displaying a malicious advertisement with this URL:
ads.beyond.com/banners/jobfox_468x60.swf

 

Adopstools test results for jobfox_468x60.swf:
http://www.adopstools.com/index.asp?section=quicklink&id=4K57pJYUj1f874Sr

"The file has a sprite/movieclip which is containing Malware actionScript code."

 

The malicious advertisement uses MovieClip.getURL to load the following URL:
measurehits.com/?cmpid=<<redacted>>

 

The measurehits.com URL redirects victims the following URL:

crustat.com/ts/in.cgi?<<redacted>>

 

Which redirects to one of several URLs:

truconv.com/?<<redacted>>
olinredr2.com/?<<redacted>>
traff-direct.com/?<<redacted>>

 

Then to domains such as:

go-uniq.com/in.cgi?<<redacted>>
top-name.cn/in.cgi?<<redacted>>
pyani.com/in.cgi?<<redacted>>

 

Eventually the victim ends up at one of several fraudware URLs, including:

removespywarethreats.com/<<redacted>>
desktoprepairpackage.com/<<redacted>>
pcantimalwaresolution.com/<<redacted>>
total-virusprotection.com/<<redacted>>
offer-provider.com/<<redacted>>

Posted by sandi with no comments
Filed under: ,

ALERT: Please treat advertising content from checkm8.com with extreme caution

Reported to checkm8.com over 9 hours ago.

Checkm8.com is serving several malicious advertisements that hijack web site visitors and redirect them to various fraudware web sites as follows.

logiagroup.checkm8.com/data/478089/HP_728x90.swf
logiagroup.checkm8.com/data/478091/HP_468x60.swf
logiagroup.checkm8.com/data/479231/HP_300x250.swf
logiagroup.checkm8.com/data/479237/HP_728x90.swf

SWF analysis via Adopstools:

adopstools.com/index.asp?section=quicklink&id=950rk4Ik9bh3WaWF
adopstools.com/index.asp?section=quicklink&id=I7c2TVDD2X6zf9I7
adopstools.com/index.asp?section=quicklink&id=1bB5k3GOLOvb5iSN
adopstools.com/index.asp?section=quicklink&id=aD6g49HnzyF8anGV

Further information:

logiagroup.checkm8.com/data/478089/HP_728x90.swf touches the following URLs:

hitoptimist.com/c/index.php?id=<<redacted>>
measurehits.com/?cmpid=<<redacted>>

logiagroup.checkm8.com/data/478091/HP_468x60.swf touches the following URLs:

hit-detect.com/c/index.php?id=<<redacted>>
measurehits.com/?cmpid=<<redacted>>

logiagroup.checkm8.com/data/479231/HP_300x250.swf touches the following URLs:

hitoptimist.com/c/index.php?id=<<redacted>>
measurehits.com/?cmpid=<<redacted>>

logiagroup.checkm8.com/data/479237/HP_728x90.swf touches the following URLs:

hitoptimist.com/c/index.php?id=<<redacted>>
measurehits.com/?cmpid=<<redacted>>

Domain details:

hitoptimist.com:
ICANN Registrar - COMMUNIGAL COMMUNICATIONS LTD
Created 10 March 2009
DNS1.COMMUNIGAL.NET
DNS2.COMMUNIGAL.NET

IP: 88.198.8.15 - Bayern - Gunzenhausen - Hetzner-rz-nbg-net

Sharing IP address with cosmotraf.net, hit-detect.com, statisticsishere.com and ydmstats.com (all domains should be treated with extreme caution)

Registrant details hiden behind WHOIS privacy service

hit-detect.com:
ICANN REGISTRAR - YESNIC CO. LTD
Created 10 March 2009
NS1.HIT-DETECT.COM (116.50.15.1 - previously HostFresh AS23898, now AS10026 - ANC Asia Netcom Corporation)
NS2.HIT-DETECT.COM (116.50.15.1 - previously HostFresh AS23898, now AS10026 - ANC Asia Netcom Corporation)
NS3.HIT-DETECT.COM (89.149.226.121 - Netdirekt)
NS4.HIT-DETECT.COM (212.117.162.90 - AS root eSolutions)

IP: 88.198.8.15 - Bayern - Gunzenhausen - Hetzner-rz-nbg-net (see above)
Previously at 195.62.37.14 - Sardegna - Olbia - Geonic.net Ltd

Registrant: Gabriel Jenks (gabrielcjenks17@mail.com) - email address associated with 3 other domains.
3515 Cooks Mine Road, NM 88101
1-505-763-5453

IMPORTANT: Let's not forget that the postcode (88101) and phone number (505-763-5453) map to Clovis, New Mexico.  I cannot find a "Cooks Mine Road" in Clovis.  Not only that, the phone number listed in the WHOIS is apparently owned by a Brian A Jones and Delinda K Jones, not a Gabriel Jenks.

Historical information re hit-detect.com:
http://msmvps.com/blogs/spywaresucks/archive/2009/03/13/1677837.aspx

measurehits.com:

Already mentioned on this blog here:
http://msmvps.com/blogs/spywaresucks/archive/2009/03/09/1676761.aspx

Now sharing IP with the following domains:

enterprisestat.net, givemystats.com, pleaselinkmeto.com, statsnclick.com, waytotheprofit.com, welovesandi.com

Posted by sandi with 1 comment(s)
Filed under: ,

HostFresh depeered?

Cool!  They join Atrivo, McColo and UkrTelegroup in the “De-peered Hall of Shame”.

Cite: http://securehomenetwork.blogspot.com/2009/03/rbn-domains-fleeing-hostfresh.html
Cite: http://www.cidr-report.org/cgi-bin/as-report?as=AS23898&view=(null)
Cite: http://www.robtex.com/as/as23898.html

 

BTW, in case you didn’t know, Brian Krebs published a report entitled “Rogue Antivirus Distribution Network Dismantled” on 20 March:

“On Monday, Security Fix profiled TrafficConverter2.biz, a program that pays affiliates handsome commissions for spreading "scareware" products like Antivirus2009 and Antivirus360. Scareware tries to frighten consumers into purchasing fake security software by pestering them with misleading and incessant warnings about threats resident on their systems.

According to a message posted at TrafficConverter2.biz and its sister sites, the program's credit card payment processor pulled the plug on them shortly after our story ran.”

Posted by sandi with 2 comment(s)
Filed under: ,

traffichunters.net – a lesson in assessing the reliability of credit references

imageIn a previous article I was able to draw a connection between Traffichunters and the infamous Innovative Marketing.

It just so happens that I have a copy of a credit application form submitted by a representative of traffichunters.  This credit application form gave the following names and phone numbers as references:

  • Olivia Davidson of MediaTraff - +1 802 281 4758
  • Stacy Wilmoth of SmartMedia24 - +1 850 764 0023
  • Kiera Anderson of AdClick Media - +1 334 239 0431

First of all, it is very important that we refresh our memory about traffichunters.net - this information will form the basis of our further investigations. 

As has been noted on this blog before, WHOIS information about traffichunters.net is currently hidden behind Moniker Privacy Services but that was not always so.  Historical WHOIS information (and this very blog) reveal that the Registrant of traffichunters.net used to be listed as:

Helen Nikolson (helen.nikolson@gmail.com)
PO Box 441
Road town
null
0000
VG

 

 

imageOk, so now that we have Ms Nikolson fresh in our memory, let's take a look at the three referees.  Basically, we are in trouble if all we do is take a quick look at the web site and perhaps make a phone call.  If we dig a little deeper things become a bit more obvious.  We need to take a look at the WHOIS details for each referee, and conduct some web searches.

*****

Kiera Anderson of AdClick Media - +1 334 239 0431
adclickmedia.net - established 3 November 2008 - web site matches in with referee and phone number

Registrant: netfinanceconsult Inc - a known pseudonym of the infamous malvertizer "Serg Moon" - he has been changing some of his domain registrations to this pseudonym

cite: http://msmvps.com/blogs/spywaresucks/archive/2008/12/09/1656228.aspx

The WHOIS information for adclickmedia.net includes the obviously fake telephone number of +1.12234567 and Fax: +1.5555555555.

hostnames sharing ip with a-records
22.116.232.72.static.reverse.ltdomains.com
boytgp.net
fbda146.amhost.net
gaypaysites.net
ns1.madresources.com

 

****

Olivia Davidson of MediaTraff - +1 802 281 4758
mediatraff.com - established 25 September 2008 - web site matches in with referee and phone number

Original registrant: Helen Nikolson (a known Innovative Marketing pseudonym)

Current registrant (change made around October last year) - David Joner, Mediatraff.

Some site content is identical to koeppelinteractive.com (koeppel was impersonated back in December 2008 by koeppelinteractive.co.uk)

cite: http://www.copyscape.com/view.php?o=33541&u=http%3A%2F%2Fwww.koeppelinteractive.com%2F&t=1237335778&s=http%3A%2F%2Fwww.mediatraff.com&w=62&c=&i=1&r=10

*****

Stacy Wilmoth of SmartMedia24 - +1 850 764 0023
smartmedia24.com - created 6 October 2008

Registrant: Helen Nikolson (a known Innovative Marketing pseudonym)

*****

So, with the benefit of this information, what conclusions can we draw from the trade references supplied by traffichunters.net?

Well, first of all we can draw a direct association between traffichunters.net, mediatraff.com and smartmedia24.com from the fact that they share/have shared a Registrant (being "Helen Nikolson").  The very fact that there is an obvious association neutralizes any benefit to be accepting such referees.  But, the connection between traffichunters and the other sites is not immediately obvious because of the way that they have manipulated the Registrant information available via WHOIS, UNLESS a web search is conducted or we have access to historical WHOIS information.  That being said, the connection between mediatraff and smartmedia24 is obvious.  We have to ask ourselves why the bad guys think they can get away with supplying mediatraff and smartmedia24 as co-referees.  Obviously, as a rule, they believe that the industry only completes the most basis of checks and takes Trade References at face value - this is a serious mistake.

Via "Helen Nikolson" we can draw an association between traffichunters.net, mediatraff.com, smartmedia24.com and the now infamous Innovative Marketing. 

Further, the remaining referee, adclickmedia.net, can be associated with the infamous "Serg Moon" pseudonym, which is long associated with malvertizing. 

We should also note that domains owned by "Helen Nikolson" have been found to be involved in facilitating malvertizing in the past.

I cannot stress enough how important it is that we NOT take references/referees at face value.  It is not enough that there is a professional looking web site available for viewing; it is not enough that somebody answers the phone using the correct business name when we call a phone number.  Friends, we are dealing with consummate professionals.  You need to complete some research, if only a Web search – and let me be honest, it may be necessary to repeat that check two, or three, months down the track, because new information may have come to light during the intervening period.  We are seeing evidence that the bad guys have developed a modus operandi where they will supply “clean” advertising for a month, two months, three months, even four months before supplying a malicious advertisement.   Remember, even if the advertisement remains live for only a few days, they can still hit a hell of a lot of computers in that time.  They don’t care if they get shut down after 24 or 48 hours – the damage has already been done – and if they got in once, you can bet they will try to get in again – they’ll simply use different names.

I understand how increased reputation checks (and re-checks) can have a negative impact on the cost of doing business but I have to ask you this - how much is your reputation worth?  Good reputations are hard to win, but very easily lost.  And, don't forget, I am always here to provide assistance and advice, and I don't charge a fee.

Posted by sandi with no comments
Filed under: ,

ALERT: malvertizement featuring Rhapsody (alternative title: Well well, they have a sense of humor….)

I’ve been taking a look-see at the latest malvertizement that has hit my desk (sourced from multiple IP addresses and received over several days) – it is a Rhapsody themed malvertizement that looks like this:

image

 

Visually the malvertizement is identical to one that was circulating at least a year ago.

The malvertizements are hitting different domains despite being visually identical, which is nothing unusual.  That being said, there is a new domain being used to facilitate a browser hijack, and I just to laugh when I saw it:

welovesandi.com

Anyway, let’s take a look-see at this new domain:

welovesandi.com
Website Title: “TotalVirusProtection” (seems they’re still not cleaning up their site code when creating new sites)

ICANN Registrar: Communigal Communications Ltd
Created: 20 March 2009
NS1.WELOVESANDI.COM
NS2.WELOVESANDI.COM
NS3.WELOVESANDI.COM
NS4.WELOVESANDI.COM

IP: 212.177.165.128 - Luxembourg, Steinsel, Root Esolutions

Shares IP address with the following domains, all of which should be treated with extreme caution:

enterprisestat.net, givemystats.com, measurehits.com, pleaselinkmeto.com, statsnclick.com and waytotheprofit.com.

Registrant:

Robert Robinson (RobertSRobinson@mail.com)
4452 Dogwood Lane
Phoenix 85012
602 5205539781

Posted by sandi with 2 comment(s)
Filed under: ,