| Author |
Message |
Verbal
Joined: 30 May 2007 Posts: 22
|
Posted: 25 Jul 2007 14:57 Post subject: videosfarmer.com now launches a trojan |
|
|
Hi,
Look out, the domain videosfarmer.com is now launching a trojan "tidy_last_validated.html" detected as VBS/Psyme.
Today the page layout has totally changed to just a bunch of big thumbs that all link to nimbleguide.com and launches a trojan when the page loads.
I've been trading w/ him for about a week since he signed up, and he was consistently sending me double the traffic back (my return stayed around 46%), which should have been my first clue. I thought he must've just been a nice guy, since he checked out here and on cheater hell... nope.
Plus, he is using Joker as a registrar - which is now becoming a big red flag for me.
 |
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
Posted: 25 Jul 2007 15:59 Post subject: wickedthumbs.com |
|
|
Looks like the same guy runs wickedthumbs.com , which is also registered at Joker.
I just went to wickedthumbs.com and it looks identical to videosfarmer.com and also launches the same virus. |
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
Posted: 25 Jul 2007 16:04 Post subject: |
|
|
Wait.. hang on.
Now they are both have reverted back to showing their clean TGP pages like before with no trojans.
Something weird is going on here.
Good thing I took screenshots of both domains how they looked before when they popped up the trojan virus alert. |
|
| Back to top |
|
rhino

Joined: 23 Dec 2006 Posts: 70 Rank: 12
|
Posted: 25 Jul 2007 19:01 Post subject: |
|
|
Pretty sure you're seeing a rather creative use of .htaccess... & mod rewrite
Type-ins get one presentation, trades get another
Had the same issues with several trades that all had the joker.com registration, looked good in trade stats & weren't in any blacklists or marked as bad trades... end result got burnt pretty badly, so now their IP range is in my firewall iptable.
Protect-X's new reverse DNS will help while checking trades, maybe could be extended to report NS info as well? (Unfortunately it's still somewhat easy to get 1 IP per domain from some underused ISP that's willing to offer it at a premium price... and some cheat networks have deep pockets with lots of $.
Rhino |
|
| Back to top |
|
max

Joined: 18 Oct 2006 Posts: 538 Rank: 38
|
Posted: 26 Jul 2007 10:50 Post subject: |
|
|
| Verbal wrote: | | Good thing I took screenshots of both domains how they looked before when they popped up the trojan virus alert. |
Would be great to look into this screenshots.
Both sites looks like normal TGP for me now. I've tried to reach them via trade - no success. Second trade in wickedthumbs's top even don't have wickedthumbs.com in his top (while having 80 spots) as well as 4th. Isn't strange? |
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
Posted: 26 Jul 2007 20:51 Post subject: |
|
|
Hi max, I'll upload screenshots in a minute since I don't think I can attach them to my post.
You are right that both TGP's look normal right now, however, videosfarmer.com has still been sending me (apparently legit) hits for the last 24 hours even though I have blacklisted and removed his trade.
I also still appear in his toplist at the bottom (#15 - CuddleBunny) though I've sent him zero traffic for the last 24-32 odd hours.
Finally, I have spoken with one of my good traders, and he confirmed he was receiving extremely great prod from this guy too (he was trading with wickedthumbs.com and I was trading with videosfarmer.com ). This guy was consistently sending me back double the traffic I was sending him no matter how much I forced.
As they say... if it sounds too good to be true....  |
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
|
| Back to top |
|
xwild
Joined: 01 Nov 2006 Posts: 576 Rank: 35
|
Posted: 27 Jul 2007 00:20 Post subject: |
|
|
This is good news! I do No need to be Mean, Just that i been telling Protect-x for a couple of days about that site/registerer.
Please review all the sites he has an post them here so he can be Expose.
What is the DNS number where he is Mainly Located so we can band it.
Please advise and thank you!
Your Amigo Xwild. |
|
| Back to top |
|
max

Joined: 18 Oct 2006 Posts: 538 Rank: 38
|
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
Posted: 27 Jul 2007 15:31 Post subject: |
|
|
Yeah xwild, I'm no longer going to trade with sites using the Joker registrar.
Also, not sure if this guy uses the same name for all his trades, but he signed up under me under the username "rowan".
Those are the only two domains I know of at the moment, so keep an eye out for this guy!
Peace,
Verbal
http://www.cuddlebunny.net/ |
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
Posted: 28 Jul 2007 16:14 Post subject: Found another one - hornymaniac.com |
|
|
Hi guys,
I was just checking trades and found another TGP pulling the same bullshit (it's probably the same guy):
hornymaniac.com screenshot
all links go to nimbleguide.com as well
Has anyone else seen the template in the screenshot anywhere? I'm on my home computer now so I'm pretty sure it's not just my work machine being corupt or something.
hornymaniac.com whois info:
domain: hornymaniac.com
owner: Peter Fischer
email: Whois Privacy and Spam Prevention by DomainTools.com
address: Dr. Otto Neuratgasse 1/7
city: Wien
state: --
postal-code: A-1220
country: AU
phone: +431.984838350
admin-c: CCOM-1070508 Whois Privacy and Spam Prevention by DomainTools.com
tech-c: CCOM-1070508 Whois Privacy and Spam Prevention by DomainTools.com
billing-c: CCOM-1070508 Whois Privacy and Spam Prevention by DomainTools.com
nserver: a.ns.joker.com 69.39.224.27
nserver: b.ns.joker.com 159.25.97.69
nserver: c.ns.joker.com 207.44.185.10
status: lock
created: 2007-07-05 10:49:56 UTC
modified: 2007-07-05 10:59:58 UTC
expires: 2008-07-05 10:49:56 UTC
contact-hdl: CCOM-1070508
person: Peter Fischer
email: Whois Privacy and Spam Prevention by DomainTools.com
address: Dr. Otto Neuratgasse 1/7
city: Wien
state: --
postal-code: A-1220
country: AU
phone: +431.984838350
source: joker.com live whois service
query-time: 0.040968
db-updated: 2007-07-28 16:12:08 |
|
| Back to top |
|
xwild
Joined: 01 Nov 2006 Posts: 576 Rank: 35
|
Posted: 29 Jul 2007 15:38 Post subject: |
|
|
that is good news Verbal
unfortunetly allot of bad webmaster change their identity to start trading again.
Just keep and eye out for bad websites.
I used mcaffee in all my pcs to detect bad sites with trojans and spuware.
It does and excellent job for me. |
|
| Back to top |
|
max

Joined: 18 Oct 2006 Posts: 538 Rank: 38
|
Posted: 30 Jul 2007 09:54 Post subject: |
|
|
| another joker site in a basket. |
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
Posted: 30 Jul 2007 17:05 Post subject: Re: videosfarmer.com now launches a trojan |
|
|
Found another one.. this is getting ridiculous.
nudeswishes.com screenshot
Can anyone confirm?
EDIT: I just refreshed that domain and it looks like a normal TGP again... very sneaky. |
|
| Back to top |
|
Verbal
Joined: 30 May 2007 Posts: 22
|
|
| Back to top |
|
|
|
|
|
|
|
|
|