 nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL
·AT&T U-Verse
·AT&T Midwest
| Re: Does anyone know anything about this advert? The main link redirects to http://www.eskimo.com/dsl/?gclid=CMbU0pK03pICFQhusgodDghp-w and there is a suspicious iframe near the end of that page.
iframe content is http://cdpuvbhfzz.com/dl/adv598.php and that contains obfuscated javascript. -- AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13 | |
|
  skj Welcome to the far side of reality Premium,Mod join:2002-04-04 Atlanta, GA
Host: Charter HSI/CATV Earthlink DSL Embarq ISP b2b etc Cisco
| Re: Does anyone know anything about this advert? There is a thread at CastleCops regarding: cdpuvbhfzz.com
http://www.castlecops.com/p1079008-iframe_loading_hxxp_cdpuvbhfzz_com_dl_adv598_php.html --
The foundations of character are built not by lecture, but by bricks of good example, laid day by day. | |
|
 |   nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL | Re: Does anyone know anything about this advert? Thanks for that CastleCops reference. Quite interesting. | |
|
 |  |   skj Welcome to the far side of reality Premium,Mod join:2002-04-04 Atlanta, GA
Host: Charter HSI/CATV Earthlink DSL Embarq ISP b2b etc Cisco
| Re: Does anyone know anything about this advert? Yes, it is. That thread was also posted today, so it looks like this nasty may have recently started ciruclating around the net. --
The foundations of character are built not by lecture, but by bricks of good example, laid day by day. | |
|
 |  |  |  |
 |
 |   EGeezer Go Bobcats Premium join:2002-08-04 Country! | Re: Does anyone know anything about this advert? looks like the code in that line directs the user to the aforementiond website's directory: /dl/adv598.php -- Mayors of New York come from nowhere and go nowhere. Wallace Sayre (apparently, so do governors... ) | |
|
 |  |   nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL
·AT&T U-Verse
·AT&T Midwest
1 edit | Re: Does anyone know anything about this advert? yes it does
I used "lynx -dump" to decode it, before I posted the target link in an earlier post in this thread. That's quicker than trying to do it manually.
I don't currently have a good tool for handling that obfuscated javascript, though. | |
|
 |  |  |  |
 |  |  |  |   nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL | Re: Does anyone know anything about this advert? Not sure.
I checked the stopbadware.org site for www.eskimo.com/dsl/ but it isn't listed. Other parts of eskimo.com are listed, but not the one that was used here.
I'm not seeing any warning if I try reloading the original link. | |
|
 |  |  |  |  |  |
 |  |  |   newview Ex .. Ex .. Exactly Premium join:2001-10-01 Parsonsburg, MD
| said by nwrickert :I don't currently have a good tool for handling that obfuscated javascript, though. If you're looking for a good "de-obfuscator", Net Demon does the trick. -- Ö¿Ö The Rules of Spam | Maryland's Newest Anti-Spam Law Where are we going? And what's with the hand basket? | |
|
  foxsteve Premium join:2001-12-28 Campbell, CA | cdpuvbhfzz.com has address 85.255.121.195 Found 4 websites with the IP 85.255.121.195
1) aarmrgdxrv.com 2) acdedblshd.com 3) adtctqypoa.com 4) xabmiphabh.cn | |
|
 |   nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL | Re: Does anyone know anything about this advert? Probably controlled by RBN, with domain registrations paid using stolen credit cards. | |
|
 |  |   foxsteve Premium join:2001-12-28 Campbell, CA
| Re: Does anyone know anything about this advert? Information related to '85.255.112.0 - 85.255.127.255'
inetnum: 85.255.112.0 - 85.255.127.255 org-name: UkrTeleGroup Ltd. address: UkrTeleGroup Ltd. Mechnikova 58/5 65029 Odessa Ukraine person: Andrew Sotov abuse-mailbox: mailto:abuse@ukrtelegroup.com.ua phone: +380631508855 | |
|
 |  |  |   newview Ex .. Ex .. Exactly Premium join:2001-10-01 Parsonsburg, MD
| Re: Does anyone know anything about this advert? quote: I hate block lists... maybe because I have been on the 'wrong end' of them in the past. But after careful consideration, we do recommend blocking traffic from these two netblocks:
InterCage Inc.: 69.50.160.0/19 (69.50.160.0 - 69.50.191.255) Inhoster: 85.255.112.0/20 (85.255.112.0 - 85.255.127.255)
»isc.sans.org/diary.html?storyid=997 -- Ö¿Ö The Rules of Spam | Maryland's Newest Anti-Spam Law Where are we going? And what's with the hand basket? | |
|
 |  |  |  |   Name Game Premium join:2002-07-07 North Myrtle Beach, SC
2 edits | Re: Does anyone know anything about this advert? said by newview : quote: I hate block lists... maybe because I have been on the 'wrong end' of them in the past. But after careful consideration, we do recommend blocking traffic from these two netblocks:
InterCage Inc.: 69.50.160.0/19 (69.50.160.0 - 69.50.191.255) Inhoster: 85.255.112.0/20 (85.255.112.0 - 85.255.127.255)
» isc.sans.org/diary.html?storyid=997 When I go online or search I always get a porn/spam advertising site like Jupk.com! Known Advertising Sites www.jupk.com www.ipodderx.comPossible Hostile
I have seen this happen when you type an address straight into the address bar including for www.google.co.uk and www.bbc.co.uk.
Currently known advertising websites are www.jupk.com and www.ipodderx.com but there are likely to be many more. Please contact me if you know of one.
The solution Note: I still haven't discoved what causes the hijack in the first place. If you know please contact me. First find your DNS settings Here is how you do this in Microsoft Windows XP or 2000
Go to Windows Control Panel Go to the 'Network Connections' (or 'Network and Internet Connections' then 'Network Connections') section. Find the item in this window that is your connection to the internet and double click it. If you connect though BT this may be 'BT Broadband' If you connect though a network it may be 'Local Area Connection' On the 'General' tab of the window that appears scroll down until you see the 'Internet Protocol' item and double click it. On the 'General' tab of the window that appears check which of the following is selected. Obtain DNS server address automatically Use the following DNS server addresses Next check the Settings are OK If it is the latter make a note of the two sets of numbers and search for them in the list on the right of this page. E.g. a known bad server is 85.255.113.194 If you find then in the list delete the numbers and change the setting to 'Obtain DNS server address automatically'. If you don't find them in the list this may still be the problem so email the numbers to us using the contact form below and then change the setting to 'Obtain DNS server address automatically'. Contact Me Please use this form to contact me.
(20th April 2007) I'm being overwhelmed by emails about this so please now use the new forum
Inhoster Addresses 85.255.112.0 through.. 85.255.127.255
Solve This Problem Report New Site or Report New DNS or Report Root Cause If when you use your web browser you keep on getting a site that looks like the image below your DNS settings have been hijacked and using a server at an Ukrainian company called Inhoster.
»gabrielharrison.co.uk/consultanc···_hijack/ -- Gladiator Security Forum »www.gladiator-antivirus.com/ * A fun/friendly/informative forum for the mature elder crowd »www.theover50goldengroup.net
| |
|
 |  Graycode
join:2006-04-17
·net2phone
1 edit | said by foxsteve :cdpuvbhfzz.com has address 85.255.121.195 Found 4 websites with the IP 85.255.121.195 1) aarmrgdxrv.com 2) acdedblshd.com 3) adtctqypoa.com 4) xabmiphabh.cn That IP may have been taken off line, I can't seem to connect to it.
Edit: It seems my ISP is blocking access to that IP. | |
|
 |  |   foxsteve Premium join:2001-12-28 Campbell, CA
| Re: Does anyone know anything about this advert? Requesting »85.255.121.195 .. Ok Reply received (reply time: 1782 ms) ------------------------------------ HTTP/1.1 200 OK Date: Wed, 16 Apr 2008 16:21:17 GMT Server: Apache/2.2.6 (Debian) PHP/5.2.4-2 with Suhosin-Patch X-Powered-By: PHP/5.2.4-2 Content-Length: 0 Connection: close Content-Type: text/html | |
|
 |  |  |  Graycode
join:2006-04-17
·net2phone
| Re: Does anyone know anything about this advert?My ISP, Cox, has apparently encountered them before.
Tracing route to 85.255.121.195 over a maximum of 30 hops ... 4 13 ms 9 ms 9 ms 68.12.9.85 5 18 ms 13 ms 16 ms 68.12.14.58 6 15 ms 12 ms 13 ms 68.12.14.33 7 40 ms 38 ms 38 ms 68.1.1.121 8 68.1.18.28 reports: Destination net unreachable.
Trace complete.
| |
|
 |  |  |  |   foxsteve Premium join:2001-12-28 Campbell, CA 1 edit | Re: Does anyone know anything about this advert? Error | |
|
 |  |  |  |   foxsteve Premium join:2001-12-28 Campbell, CA
| ISP SONIC has no any problem C:\....>tracert 85.255.121.195
Tracing route to 85.255.121.195 over a maximum of 30 hops .... .....................................
4 16 ms 53 ms 16 ms 200.ge-1-2-0.gw2.equinix-sj.sonic.net [64.142.0.210] 5 19 ms 17 ms 17 ms sjc-c00-pni-gbe-1-5-6.wvfiber.net [206.223.116.18] 6 17 ms 17 ms 19 ms 66.186.192.250 7 19 ms 17 ms 19 ms gw1.cernel.net [64.28.176.1] 8 * * * Request timed out. 9 * * * Request timed out. 10 * * * Request timed out. 11 * * * Request timed out. 12 * 28 ms 28 ms 85.255.121.195
Trace complete. | |
|
 |
|
 |