Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Does anyone know anything about this advert?
Search Topic:
Uniqs:
3695
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
New Spam Site Found Every Three Seconds »
« (topic move) [BT] Pickedup a Trojan  
page: 1 · 2 · 3
AuthorAll Replies


foxsteve
Premium
join:2001-12-28
Campbell, CA

reply to Graycode
Re: Does anyone know anything about this advert?

ISP SONIC has no any problem
C:\....>tracert 85.255.121.195

Tracing route to 85.255.121.195 over a maximum of 30 hops
.... .....................................

4 16 ms 53 ms 16 ms 200.ge-1-2-0.gw2.equinix-sj.sonic.net [64.142.0.210]
5 19 ms 17 ms 17 ms sjc-c00-pni-gbe-1-5-6.wvfiber.net [206.223.116.18]
6 17 ms 17 ms 19 ms 66.186.192.250
7 19 ms 17 ms 19 ms gw1.cernel.net [64.28.176.1]
8 * * * Request timed out.
9 * * * Request timed out.
10 * * * Request timed out.
11 * * * Request timed out.
12 * 28 ms 28 ms 85.255.121.195

Trace complete.


foxsteve
Premium
join:2001-12-28
Campbell, CA

1 edit
reply to Graycode
Error

Graycode

join:2006-04-17
·net2phone

reply to foxsteve
My ISP, Cox, has apparently encountered them before.

Tracing route to 85.255.121.195 over a maximum of 30 hops
...
4 13 ms 9 ms 9 ms 68.12.9.85
5 18 ms 13 ms 16 ms 68.12.14.58
6 15 ms 12 ms 13 ms 68.12.14.33
7 40 ms 38 ms 38 ms 68.1.1.121
8 68.1.18.28 reports: Destination net unreachable.

Trace complete.


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC


2 edits
reply to newview
said by newview See Profile :

quote:
I hate block lists... maybe because I have been on the 'wrong end' of them in the past. But after careful consideration, we do recommend blocking traffic from these two netblocks:

InterCage Inc.: 69.50.160.0/19 (69.50.160.0 - 69.50.191.255)
Inhoster: 85.255.112.0/20 (85.255.112.0 - 85.255.127.255)
»isc.sans.org/diary.html?storyid=997
When I go online or search I always get a porn/spam advertising site like Jupk.com!
Known Advertising Sites
www.jupk.com
www.ipodderx.comPossible Hostile

I have seen this happen when you type an address straight into the address bar including for www.google.co.uk and www.bbc.co.uk.

Currently known advertising websites are www.jupk.com and www.ipodderx.com but there are likely to be many more. Please contact me if you know of one.

The solution
Note: I still haven't discoved what causes the hijack in the first place. If you know please contact me.
First find your DNS settings
Here is how you do this in Microsoft Windows XP or 2000

Go to Windows Control Panel
Go to the 'Network Connections' (or 'Network and Internet Connections' then 'Network Connections') section.
Find the item in this window that is your connection to the internet and double click it.
If you connect though BT this may be 'BT Broadband'
If you connect though a network it may be 'Local Area Connection'
On the 'General' tab of the window that appears scroll down until you see the 'Internet Protocol' item and double click it.
On the 'General' tab of the window that appears check which of the following is selected.
Obtain DNS server address automatically
Use the following DNS server addresses
Next check the Settings are OK
If it is the latter make a note of the two sets of numbers and search for them in the list on the right of this page. E.g. a known bad server is 85.255.113.194
If you find then in the list delete the numbers and change the setting to 'Obtain DNS server address automatically'.
If you don't find them in the list this may still be the problem so email the numbers to us using the contact form below and then change the setting to 'Obtain DNS server address automatically'.
Contact Me
Please use this form to contact me.

(20th April 2007) I'm being overwhelmed by emails about this so please now use the new forum

Inhoster Addresses
85.255.112.0
through..
85.255.127.255


Solve This Problem
Report New Site or Report New DNS or Report Root Cause
If when you use your web browser you keep on getting a site that looks like the image below your DNS settings have been hijacked and using a server at an Ukrainian company called Inhoster.

»gabrielharrison.co.uk/consultanc···_hijack/
--
Gladiator Security Forum »www.gladiator-antivirus.com/
*
A fun/friendly/informative forum for the mature elder crowd
»www.theover50goldengroup.net


foxsteve
Premium
join:2001-12-28
Campbell, CA

reply to Graycode
Requesting »85.255.121.195 .. Ok
Reply received (reply time: 1782 ms)
------------------------------------
HTTP/1.1 200 OK
Date: Wed, 16 Apr 2008 16:21:17 GMT
Server: Apache/2.2.6 (Debian) PHP/5.2.4-2 with Suhosin-Patch
X-Powered-By: PHP/5.2.4-2
Content-Length: 0
Connection: close
Content-Type: text/html


newview
Ex .. Ex .. Exactly
Premium
join:2001-10-01
Parsonsburg, MD

reply to foxsteve
quote:
I hate block lists... maybe because I have been on the 'wrong end' of them in the past. But after careful consideration, we do recommend blocking traffic from these two netblocks:

InterCage Inc.: 69.50.160.0/19 (69.50.160.0 - 69.50.191.255)
Inhoster: 85.255.112.0/20 (85.255.112.0 - 85.255.127.255)
»isc.sans.org/diary.html?storyid=997
--

Ö¿Ö
The Rules of Spam | Maryland's Newest Anti-Spam Law
Where are we going? And what's with the hand basket?


foxsteve
Premium
join:2001-12-28
Campbell, CA

reply to nwrickert
Information related to '85.255.112.0 - 85.255.127.255'

inetnum: 85.255.112.0 - 85.255.127.255
org-name: UkrTeleGroup Ltd.
address: UkrTeleGroup Ltd.
Mechnikova 58/5
65029 Odessa
Ukraine
person: Andrew Sotov
abuse-mailbox: mailto:abuse@ukrtelegroup.com.ua
phone: +380631508855

Graycode

join:2006-04-17
·net2phone


1 edit
reply to foxsteve
said by foxsteve See Profile :

cdpuvbhfzz.com has address 85.255.121.195
Found 4 websites with the IP 85.255.121.195

1) aarmrgdxrv.com
2) acdedblshd.com
3) adtctqypoa.com
4) xabmiphabh.cn
That IP may have been taken off line, I can't seem to connect to it.

Edit: It seems my ISP is blocking access to that IP.


newview
Ex .. Ex .. Exactly
Premium
join:2001-10-01
Parsonsburg, MD

reply to nwrickert
said by nwrickert See Profile :

I don't currently have a good tool for handling that obfuscated javascript, though.

If you're looking for a good "de-obfuscator", Net Demon does the trick.
--

Ö¿Ö
The Rules of Spam | Maryland's Newest Anti-Spam Law
Where are we going? And what's with the hand basket?


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
reply to foxsteve
Probably controlled by RBN, with domain registrations paid using stolen credit cards.


foxsteve
Premium
join:2001-12-28
Campbell, CA
reply to nwrickert
cdpuvbhfzz.com has address 85.255.121.195
Found 4 websites with the IP 85.255.121.195

1) aarmrgdxrv.com
2) acdedblshd.com
3) adtctqypoa.com
4) xabmiphabh.cn


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC


1 edit
reply to justin
cure.txt 2,615 bytes
foulu
Contributor
Coppermine frequent
--------------------------------------------------------------------------------
Hi,

I make a php file that can sanitize the addition data from php & html file that infected with iframe things. I create it to use on one of my working site but I think release it will help more people. The script is simple, just check current folder and all sub folder for .php & .html, loop to find infect string in those files and then remove it. Anyway, use it with own will, I will not take any responsibility if you damage your site when using it.

I attach the file with this post, download and rename it to cure.php, upload to your site & run it.

------------------------------------------------------------
cure.txt (2.48 KB - downloaded 81 times.)

http://forum.coppermine-gallery.net/index.php/topic,51671.180.html

also there...
A little shell (/bin/sh) script to clean up that... Not better than capecodgal's one but very simple to use if you have shell access or /bin/sh cgi capabilities.

Use it on your web's root.

------------------------------------------------------------
nettoie_cpg.txt (0.37 KB - downloaded 32 times.)

--
Gladiator Security Forum http://www.gladiator-antivirus.com/
*
A fun/friendly/informative forum for the mature elder crowd
http://www.theover50goldengroup.net


TechSponge

join:2001-05-14
Hillside, NJ
reply to justin
BTW - I never got to click on anything on the site...i had the time to visually search for NY and NJ as served areas...and the fireworks just began.


Lanik
Lab-nik
Premium,ExMod 2002-03
join:2001-06-25
Bay Area

reply to TechSponge
said by TechSponge See Profile :

Hey Folks! Im the idiot that clicked on the cool looking Banner.
Sh!t happens, we've all made that mistake at one point or another. What's more important is how you proceed from there mainly and what lessons were learned during this exercise in patience.
--
"If it ain't broke don't fix it."


TechSponge

join:2001-05-14
Hillside, NJ

reply to justin
Hey Folks! Im the idiot that clicked on the cool looking Banner. I never click on Banners unless Im on legit sites. Thought that was safe. Guess not.
So...got back to the city to work on this PC to get it running for tomorrow.
Info: I was running spybot s&d fully patched and teatimer running. Spywareblaster installed but not "active". Symantec Corp 10, fully patched.
It created 2 folder in PROGRAM FILES. Netproject & Helper. 3 BHO's were added according to hijackthis. 2 were pointing to ieservicegate(IE Anti-Spyware - {9034a523-d068-4be8-a284-9df278be776e} - »www.ieservicegate.com/redire{...} + Extra button: (no name) - {9034a523-d068-4be8-a284-9df278be776e} - »www.ieservicegate.com/redire{...}) and 1 to netproject (sbmdl.dll).
There were a bunch of items caught by Spybot: Zlob, Smitfraud, Spylocked, win32 renos, and a few others.
As I type this, even though i would say ive done a good job cleaning...i get a few warnings from symantec in my temp ie content files for trojans (mediatubecodec[1].exe) and spybot is blocking...something.
Looks like the wipe begins. Thanks to all for all of your input. All of this is above my head. Im just a simple network guy.
-Sponge

mysec
Premium
join:2005-11-29

reply to justin
Using the link nwrickert See Profile gives, here is the exploit in action.

As the page loads, the iframe connects in the background to cdpuvbhfzz.com (see IE status bar) and almost immediately an IE error box appears:


____________________________________________________________

Meanwhile adv598.html caches:


____________________________________________________________

As soon as the user clicks to close the IE error box, the IE window closes, a new IE Blank window opens and the obfuscated code attempts to download loadadv598.exe in the background:


____________________________________________________________

The following file also caches, and the CLSID is one of several vulnerable ActiveX exploits
used in the past, but I didn't follow through to check it more.


____________________________________________________________

Conclusion

Lots of fancy footwork attempting to accomplish the same old thing: sneak in a trojan downloader,
easily prevented with proper security.



Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC
reply to rick752
Someone has Redirected my Site to cdpuvbhfzz.com-What do I do?

»forum.coppermine-gallery.net/ind···1.0.html


rick752
Premium
join:2006-01-27
New York

1 edit
reply to EGeezer
I think I have this blocked now. Thanx.
That really sucks


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!

1 edit
reply to rick752
And more here -

»www.google.com/search?q=adv598.php
Mayors of New York come from nowhere and go nowhere.
Wallace Sayre (apparently, so do governors... )


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

reply to rick752
said by rick752 See Profile :

Thanx, Name Game ... that was the 2nd verification that I was looking for.
Changing filter in ABP EasyList now.
What a nasty piece of work that stuff is..good luck Rick.
Forums » Up and Running » Security » SecurityNew Spam Site Found Every Three Seconds »
« (topic move) [BT] Pickedup a Trojan  
page: 1 · 2 · 3


Sunday, 06-Dec 04:36:03 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [124] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· Is there any true cure for, or way to prevent, a hangover? [General Questions]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Enhancement Shaman + Heirlooms, what to pick? [World of Warcraft]
· [ Professions] Northrend Herbalism and Mining Tracks [World of Warcraft]
· [Scam] Ebay Motors Scam [Spam, Scam and Phishbusters]