Today a new domain caught my eye. I though, perhaps, that it was a hijacked domain, but not. It advertises "the latest update in ED treatment", with it being a "Limited time offer". (ED, of course, being Erectial Dysfunction.)
Anyhow, the domain is healthykidsinc.com
I guess it relates.
Thursday, June 5, 2008
Ramping up.
Volume of spam over the last few days has ramped up. In addition, it looks like the captcha at geocites.com has completed failed. They have become blatant to the point of being obvious. As and example, they have completely given up on using "real sounding" domain names.
Here are a couple names as an examples.
kdoitueuryfgvavec.com
www.geocities.com/barbaraafkdxdy
Here are a couple names as an examples.
kdoitueuryfgvavec.com
www.geocities.com/barbaraafkdxdy
Tuesday, May 27, 2008
Brazen Use of Geocites.com
Should anyone forget, geocities.com is owned by Yahoo! And currently, Yahoo! is under market attack, stock market attack. As such, should not be of any wonder if the management is a bit distracted. Proof is in the names spammers are using to hijack account at geocities. Here are two (2) examples.
http://www.geocities.com/bnnmqsfqa
http://www. geocities.com/dtspdzkrzxsx
They both have their own sets of obfuscated javascript. Example below.
----
<script language="JavaScript" type="text/javascript">var pcyr='dnbwddumxrutoetjbi';var jryb=0;var zvunzgj, woqv, nueexs='581D01050D14014D14131B131A04130F5F4B2E0F1416370707040806574A180C1A0E0D1E4A1A0D074A081A0E19061C1B014B1C18070F445342500C10011D425D5A060A1518130F0C0A40011809434E515701160606150054';woqv='';var xhbgqyi;for( zvunzgj=0;zvunzgj < xhbgqyi =" unescape(">= pcyr.length ) jryb = 0;}document.write(woqv);</script>
http://www.geocities.com/bnnmqsfqa
http://www. geocities.com/dtspdzkrzxsx
They both have their own sets of obfuscated javascript. Example below.
----
<script language="JavaScript" type="text/javascript">var pcyr='dnbwddumxrutoetjbi';var jryb=0;var zvunzgj, woqv, nueexs='581D01050D14014D14131B131A04130F5F4B2E0F1416370707040806574A180C1A0E0D1E4A1A0D074A081A0E19061C1B014B1C18070F445342500C10011D425D5A060A1518130F0C0A40011809434E515701160606150054';woqv='';var xhbgqyi;for( zvunzgj=0;zvunzgj < xhbgqyi =" unescape(">= pcyr.length ) jryb = 0;}document.write(woqv);</script>
Tuesday, May 6, 2008
Check of Spam Domainsh
Here are some numbers from the latest domain check. After 38+ hours, with run ending on:
May 5, 2008 around 14:00 Pacific Time.
The webpages are responding POORLY to searchs for keywords. More on this later.
May 5, 2008 around 14:00 Pacific Time.
- Domains Checked 7958
- ALIVE 3322
- DEAD 995
- UNKNOWN 3642
- got the IP number (via ping)
- checked for ping response
- requested a webpage and checked for the response
The webpages are responding POORLY to searchs for keywords. More on this later.
Thursday, May 1, 2008
They are pulling out stops
Somewhere someone is making head way on SPAM as the URL below indicates.
In translation, google ad meter launches the link to a compromised website. The target link inturn, is either an exe with a trojan, or a redirect link to a SPAM sender, or SPAM payoff itself (like rolex of viagra).
To be clear, target link may be rotating. That is, in some cases you might get any of the three depending on the link. An exe one time, a payoff the next time, etc.
<a hef="http://www.google.com/pagead/iclk?sa=l&ai=aOthDdS&num=36269=
&adurl=http://www.ag-computer-team.de/index1.php" =
style="color:#121212; font-weight:bold;">
UPDATE 06-06-2008: To be clear on the above, the rotation is in email, not the target link. That is, the email carries the rotation, not the website.
In translation, google ad meter launches the link to a compromised website. The target link inturn, is either an exe with a trojan, or a redirect link to a SPAM sender, or SPAM payoff itself (like rolex of viagra).
To be clear, target link may be rotating. That is, in some cases you might get any of the three depending on the link. An exe one time, a payoff the next time, etc.
<a hef="http://www.google.com/pagead/iclk?sa=l&ai=aOthDdS&num=36269=
&adurl=http://www.ag-computer-team.de/index1.php" =
style="color:#121212; font-weight:bold;">
UPDATE 06-06-2008: To be clear on the above, the rotation is in email, not the target link. That is, the email carries the rotation, not the website.
Wednesday, April 30, 2008
Extreme threat on comprimised website
This link came via a google "pagead". Likely, more than one has got past me. The link redirects to an html page, which loads two (2) iframes and gives a link to and exe. No doubt the exe will load a trojan or word.
I was unable to get a copy of the exe.
http://yboats.com/video_233.php
----
UPDATE: Just after posting this the webpage was deleted. I got a copy of the webpage.
----
UPDATE 2008-05-01: The webpage has returned today.
I was unable to get a copy of the exe.
http://yboats.com/video_233.php
----
UPDATE: Just after posting this the webpage was deleted. I got a copy of the webpage.
----
UPDATE 2008-05-01: The webpage has returned today.
Sunday, April 27, 2008
Subscribe to:
Posts (Atom)