MAIN
NEW THREADS
AD SPOT

videosfarmer.com now launches a trojan
Protect-X Forum >> Cheaters & Shitlist
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies. Goto page 1, 2  Next
Author Message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 25 Jul 2007 14:57    Post subject: videosfarmer.com now launches a trojan Reply with quote

Hi,

Look out, the domain videosfarmer.com is now launching a trojan "tidy_last_validated.html" detected as VBS/Psyme.

Today the page layout has totally changed to just a bunch of big thumbs that all link to nimbleguide.com and launches a trojan when the page loads.

I've been trading w/ him for about a week since he signed up, and he was consistently sending me double the traffic back (my return stayed around 46%), which should have been my first clue. I thought he must've just been a nice guy, since he checked out here and on cheater hell... nope.

Plus, he is using Joker as a registrar - which is now becoming a big red flag for me.

Evil or Very Mad
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 25 Jul 2007 15:59    Post subject: wickedthumbs.com Reply with quote

Looks like the same guy runs wickedthumbs.com, which is also registered at Joker.

I just went to wickedthumbs.com and it looks identical to videosfarmer.com and also launches the same virus.
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 25 Jul 2007 16:04    Post subject: Reply with quote

Wait.. hang on.

Now they are both have reverted back to showing their clean TGP pages like before with no trojans.

Something weird is going on here.

Good thing I took screenshots of both domains how they looked before when they popped up the trojan virus alert.
Back to top
View user's profile Send private message
rhino



Joined: 23 Dec 2006
Posts: 70
Rank: 12

PostPosted: 25 Jul 2007 19:01    Post subject: Reply with quote

Pretty sure you're seeing a rather creative use of .htaccess... & mod rewrite

Type-ins get one presentation, trades get another Twisted Evil

Had the same issues with several trades that all had the joker.com registration, looked good in trade stats & weren't in any blacklists or marked as bad trades... end result got burnt pretty badly, so now their IP range is in my firewall iptable.

Protect-X's new reverse DNS will help while checking trades, maybe could be extended to report NS info as well? (Unfortunately it's still somewhat easy to get 1 IP per domain from some underused ISP that's willing to offer it at a premium price... and some cheat networks have deep pockets with lots of $.

Rhino
Back to top
View user's profile Send private message
max



Joined: 18 Oct 2006
Posts: 538
Rank: 38

PostPosted: 26 Jul 2007 10:50    Post subject: Reply with quote

Verbal wrote:
Good thing I took screenshots of both domains how they looked before when they popped up the trojan virus alert.


Would be great to look into this screenshots.
Both sites looks like normal TGP for me now. I've tried to reach them via trade - no success. Second trade in wickedthumbs's top even don't have wickedthumbs.com in his top (while having 80 spots) as well as 4th. Isn't strange?
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 26 Jul 2007 20:51    Post subject: Reply with quote

Hi max, I'll upload screenshots in a minute since I don't think I can attach them to my post.

You are right that both TGP's look normal right now, however, videosfarmer.com has still been sending me (apparently legit) hits for the last 24 hours even though I have blacklisted and removed his trade.

I also still appear in his toplist at the bottom (#15 - CuddleBunny) though I've sent him zero traffic for the last 24-32 odd hours.

Finally, I have spoken with one of my good traders, and he confirmed he was receiving extremely great prod from this guy too (he was trading with wickedthumbs.com and I was trading with videosfarmer.com). This guy was consistently sending me back double the traffic I was sending him no matter how much I forced.

As they say... if it sounds too good to be true.... Rolling Eyes
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 26 Jul 2007 21:07    Post subject: screenshots Reply with quote

Here are screenshots I took on the morning of 7/25/07.

On the wickedthumbs.com one I actually had just closed my virus alert pop-up window, but you can see the two domains look(ed) the same.


videosfarmer.com screenshot
All these thumbnails linked to nimbleguide.com
ie: http:// nimbleguide.com/gangbang.html?6278


wickedthumbs.com screenshot
All these thumbnails linked to adsnavigator.com
ie: http:// adsnavigator.com/gangbang.html?6278 (<- possibly an affiliate ref code?)
Back to top
View user's profile Send private message
xwild



Joined: 01 Nov 2006
Posts: 576
Rank: 35

PostPosted: 27 Jul 2007 00:20    Post subject: Reply with quote

This is good news! I do No need to be Mean, Just that i been telling Protect-x for a couple of days about that site/registerer.

Please review all the sites he has an post them here so he can be Expose.

What is the DNS number where he is Mainly Located so we can band it.

Please advise and thank you!

Your Amigo Xwild.
Back to top
View user's profile Send private message
max



Joined: 18 Oct 2006
Posts: 538
Rank: 38

PostPosted: 27 Jul 2007 08:29    Post subject: Reply with quote

Just noticed
nimbleguide.com
adsnavigator.com
have the same template and thumbs like videosfarmer.com and wickedthumbs.com on your screenshots.
Moved to ban list.
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 27 Jul 2007 15:31    Post subject: Reply with quote

Yeah xwild, I'm no longer going to trade with sites using the Joker registrar.

Also, not sure if this guy uses the same name for all his trades, but he signed up under me under the username "rowan".

Those are the only two domains I know of at the moment, so keep an eye out for this guy!

Peace,

Verbal
http://www.cuddlebunny.net/
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 28 Jul 2007 16:14    Post subject: Found another one - hornymaniac.com Reply with quote

Hi guys,

I was just checking trades and found another TGP pulling the same bullshit (it's probably the same guy):

hornymaniac.com screenshot
all links go to nimbleguide.com as well

Has anyone else seen the template in the screenshot anywhere? I'm on my home computer now so I'm pretty sure it's not just my work machine being corupt or something.


hornymaniac.com whois info:

domain: hornymaniac.com
owner: Peter Fischer
email: Whois Privacy and Spam Prevention by DomainTools.com
address: Dr. Otto Neuratgasse 1/7
city: Wien
state: --
postal-code: A-1220
country: AU
phone: +431.984838350
admin-c: CCOM-1070508 Whois Privacy and Spam Prevention by DomainTools.com
tech-c: CCOM-1070508 Whois Privacy and Spam Prevention by DomainTools.com
billing-c: CCOM-1070508 Whois Privacy and Spam Prevention by DomainTools.com
nserver: a.ns.joker.com 69.39.224.27
nserver: b.ns.joker.com 159.25.97.69
nserver: c.ns.joker.com 207.44.185.10
status: lock
created: 2007-07-05 10:49:56 UTC
modified: 2007-07-05 10:59:58 UTC
expires: 2008-07-05 10:49:56 UTC

contact-hdl: CCOM-1070508
person: Peter Fischer
email: Whois Privacy and Spam Prevention by DomainTools.com
address: Dr. Otto Neuratgasse 1/7
city: Wien
state: --
postal-code: A-1220
country: AU
phone: +431.984838350

source: joker.com live whois service
query-time: 0.040968
db-updated: 2007-07-28 16:12:08
Back to top
View user's profile Send private message
xwild



Joined: 01 Nov 2006
Posts: 576
Rank: 35

PostPosted: 29 Jul 2007 15:38    Post subject: Reply with quote

that is good news Verbal
unfortunetly allot of bad webmaster change their identity to start trading again.
Just keep and eye out for bad websites.

I used mcaffee in all my pcs to detect bad sites with trojans and spuware.

It does and excellent job for me.
Back to top
View user's profile Send private message
max



Joined: 18 Oct 2006
Posts: 538
Rank: 38

PostPosted: 30 Jul 2007 09:54    Post subject: Reply with quote

another joker site in a basket.
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 30 Jul 2007 17:05    Post subject: Re: videosfarmer.com now launches a trojan Reply with quote

Found another one.. this is getting ridiculous.

nudeswishes.com screenshot

Can anyone confirm?


EDIT: I just refreshed that domain and it looks like a normal TGP again... very sneaky.
Back to top
View user's profile Send private message
Verbal



Joined: 30 May 2007
Posts: 22


PostPosted: 30 Jul 2007 17:20    Post subject: Reply with quote

more:
mpegsarena.com screenshot

and

reallycurves.com

I'm just going to stop taking screenshots now. The point is beware of TGP's on Joker registrar. Evil or Very Mad
Back to top
View user's profile Send private message
   
This forum is locked: you cannot post, reply to, or edit topics.  This topic is locked: you cannot edit posts or make replies.
 
Jump to:  
Page 1 of 2
Goto page 1, 2  Next

 
ADVERTISEMENT

ImLive Cam Adult sponsor


Powered by phpBB © 2001, 2005 phpBB Group

Anti Bot Question MOD - phpBB MOD against Spam Bots
Blocked registrations / posts: 0 / 0