Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 03-11-2007, 02:42 PM   #1
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
Estdomains Is Behind The Trojan!

So I am here to bust out the people behind this... From a post on adx by DanS where he pointed out that surfers were being redirected to a codec download on assisass.com I found the domain that the codec was being downloaded from...

The domain also has other exploits so I am not going to post the url but I will post the IP...

216.255.179.125

Some investigation of this ip revealed that it resolves to an ISP called InterCage...

From an earlier post you will find that the people that discovered the trojan at the University of Minnesota discovered that the varient that they wrre analyzing was being hosted by InHosters and they determined that InHosters was being run by a crime ring from the Ukraine.

http://lists.sans.org/pipermail/unis...er/026937.html

After digging a little deeper into Intercage I discovered that they have been blacklisted and accused of many crimes... including hijacking proxies and whole netblocks...

http://spamhuntress.com/wiki/Dyakon
http://blogs.zdnet.com/Spyware/?p=752

I did a whois on the domain serving the trojan and discovered that it was registered via ESTDOMAINS... there have been many posts on adx about the onslought of cheaters that have appeared over the last few months that were registered via ESTDOMAINS... the odd thing about most of these cheaters is that the traffic doesn't necessarily look like cheater traffic... it doesn't always have alot of proxy and it generates clicks... I think it's already been posted that this trojan generates fake traffic.

And then I hit the motherload...

InHosters, Estdomains and Intercage are all the same company...
http://blogs.zdnet.com/Spyware/?p=763

Quote:
The other block listed by SANS, ?Inhoster?, appears to be the same company as Esthost - as are Critical Internet, Estdomains and Web-Namez. This netblock used also to be Atrivo?s; it?s not clear to me whether that block is operated by Esthost themselves or by Atrivo for Esthost.
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 02:45 PM   #2
JD
Too lazy to set a custom title
 
Industry Role:
Join Date: Sep 2003
Posts: 22,651
Ma.....get muh shotgun...
JD is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 02:45 PM   #3
ztik
Confirmed User
 
ztik's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Nomad
Posts: 5,196
Estdomains is behind alot of crap, no need to even post it. They are probably one of the biggest spammers on the net
__________________
.
ztik is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:08 PM   #4
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
more

http://netrn.net/spywareblog/archive...um-on-the-run/
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:17 PM   #5
Dirty F
Too lazy to set a custom title
 
Dirty F's Avatar
 
Industry Role:
Join Date: Jul 2001
Posts: 59,204
The Ukraine...what a surprise. Its really time they get their own internet over there thats cut off from the rest of the world.
Dirty F is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:20 PM   #6
Lanceman
So Fucking Banned
 
Join Date: Mar 2007
Posts: 301
Good fucking job man!!!!!

Now like what do we do?

I say lets start that coillation against this shit!

It is like the war on terror,same shit different towel head!

Until all the sponsors get there act together we as webmasters will always run this risk!

Problem is will the sponsors play ball?
Lanceman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:23 PM   #7
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
why can't you give a url to the codec download? I have my own reservations about estdomains, but an accusation needs the solid proof, or else you're leaving yourself open for banning....
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:25 PM   #8
Lanceman
So Fucking Banned
 
Join Date: Mar 2007
Posts: 301
Quote:
Originally Posted by Dirty Franck View Post
The Ukraine...what a surprise. Its really time they get their own internet over there thats cut off from the rest of the world.
I actually dont hate any part of the world in general especially where actresses can be filmed cheap!

Problem is cheater scum not Race/Religion/or region

Last edited by Lanceman; 03-11-2007 at 03:26 PM..
Lanceman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:39 PM   #9
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
Quote:
Originally Posted by borked View Post
why can't you give a url to the codec download? I have my own reservations about estdomains, but an accusation needs the solid proof, or else you're leaving yourself open for banning....
the person that bans me for this shit is complicit...

http://alexa.com/data/details/traffi...m%2Fgoanal.php

that won't take you directly to the download but will show you what the url is.
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:44 PM   #10
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
So how about the people that say they are protecting us?

http://protecty.wikispaces.com/info
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 03:47 PM   #11
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
Quote:
Originally Posted by nation-x View Post
the person that bans me for this shit is complicit...

http://alexa.com/data/details/traffi...m%2Fgoanal.php

that won't take you directly to the download but will show you what the url is.
whoever owns fresh3xvideos must read gfy then because all those links are 404ing

--edit never mind the source shows the links
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:03 PM   #12
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
just be careful nation-x - great investigative posting, but the motherload post, even following the links is still circumstantial....
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:13 PM   #13
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
Quote:
Originally Posted by borked View Post
just be careful nation-x - great investigative posting, but the motherload post, even following the links is still circumstantial....
I agree it's circumstantial... but where I live... in reality... if it smells like shit and looks like shit it's usually shit. And I don't really even give a fuck if someone wants to ban me for busting this shit out... gfy does not make my business... nor most of the motherfuckers that post here... if there is someone that has a problem with this post then they can eat a sick dick. This is serious shit.

Let's consider the enormity of this for a moment... not only is this rampant ripping off of affiliates (and more then likely programs as well)... it's a HUGE security problem... Those professors estimated that lots and lots of people were infected... it could even be millions since there are no antivirus programs that currently detect the trojan... and judging by the amount of traffic that this one install location gets I would be willing to estimate that it's POSSIBLE that more then a million machines may be infected.

Dude... that is a National Security Risk!
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:17 PM   #14
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
btw... I should mention that the codec installer doesn't show up for firefox
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:20 PM   #15
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
and really... ultimately... your posts tell me that you didn't read the mailing list post from Brian Eckman... he plainly says that the thing is controlled by InHost... Inhost = Estdomains...
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:23 PM   #16
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
Quote:
Originally Posted by nation-x View Post
... This is serious shit....
Don't get me wrong - it IS serious shit, and a lot of major players couldn't give a toss. There are some out there that are actively trying to combat this problem.

I infected a puter with the trojan, and tested it out, and in my tests the first click had a refcode changed, which stuck. If the link had no refocde in it, it appeared unchanged, but when it got the the processor, a new refcode got added.

The refcode appeared to change randomly though, which was weird.

HOWEVER - there is a current easy workaround for this trojan, and with a bit more implementation, will protect for a few more revisions. I'm not posting what the solution is on a public board, but it is a payside server-side implementation that will protect all affiliates. Funny though how some big guys don't seem to care about it
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:32 PM   #17
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
Quote:
Originally Posted by nation-x View Post
and really... ultimately... your posts tell me that you didn't read the mailing list post from Brian Eckman... he plainly says that the thing is controlled by InHost... Inhost = Estdomains...
You're very wrong - I just don't see that the evidence linking Inhosters to Estdomains is very strong....

Quote:
The other block listed by SANS, ?Inhoster?, appears to be the same company as Esthost - as are Critical Internet, Estdomains and Web-Namez. This netblock used also to be Atrivo?s; it?s not clear to me whether that block is operated by Esthost themselves or by Atrivo for Esthost.
That's a big IF....
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:42 PM   #18
cones
So Fucking Banned
 
Join Date: Feb 2007
Location: Australia
Posts: 571
Nice work man
cones is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:44 PM   #19
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
Quote:
Originally Posted by borked View Post
You're very wrong - I just don't see that the evidence linking Inhosters to Estdomains is very strong....



That's a big IF....
http://netrn.net/spywareblog/archive...um-on-the-run/
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:46 PM   #20
crockett
in a van by the river
 
crockett's Avatar
 
Industry Role:
Join Date: May 2003
Posts: 76,806
Quote:
Originally Posted by ztik View Post
Estdomains is behind alot of crap, no need to even post it. They are probably one of the biggest spammers on the net
Then why are they able to accept Epassporte and Paypal? E-gold , Moneybrokers are a few of the others. Hit them where the money is, turn it off.

I think if this is true and enuff of us bitch we can at least get epass and paypal to pull the plug on them.
__________________
In November, you can vote for America's next president or its first dictator.
crockett is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:51 PM   #21
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
Quote:
Originally Posted by nation-x View Post
(I missed that link)
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:54 PM   #22
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,167
Don't have time to read it all (read only your initial post), but because they are registered through estdomains, estdomains is behind it? Is that what you're saying?
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 04:57 PM   #23
Lanceman
So Fucking Banned
 
Join Date: Mar 2007
Posts: 301
PLEASE SEE THREAD:ANTI SPYWARE COALITION!!!!!!!

Why can't we form a group, say the " anti spyware coalition ". Why can't affiliates donate $50 a month to this and sponsors donate $500 a month.

If just 100 affiliates anti up and just 10 sponsors that is $10,000 a month. apoint a board, hire a couple full time well qualified anti spyware people to start working on this. 10K a month should hire a couple really qualified people.

the more people who join the group the lower we can reduce the fees. $50 x 100 is the same as 1000 x $5 so fees could be lowered as more people join and/or more people could be hired to work on it.

If you make even $1,000 a month what is $50 to help fight this. Sponsors, if you make millions a month what is $500 ?
Lanceman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 05:02 PM   #24
borked
Totally Borked
 
borked's Avatar
 
Industry Role:
Join Date: Feb 2005
Posts: 6,284
Quote:
Originally Posted by Lanceman View Post
PLEASE SEE THREAD:ANTI SPYWARE COALITION!!!!!!!

Why can't we form a group, say the " anti spyware coalition ". Why can't affiliates donate $50 a month to this and sponsors donate $500 a month.

If just 100 affiliates anti up and just 10 sponsors that is $10,000 a month. apoint a board, hire a couple full time well qualified anti spyware people to start working on this. 10K a month should hire a couple really qualified people.

the more people who join the group the lower we can reduce the fees. $50 x 100 is the same as 1000 x $5 so fees could be lowered as more people join and/or more people could be hired to work on it.

If you make even $1,000 a month what is $50 to help fight this. Sponsors, if you make millions a month what is $500 ?
Apparently, some of the AV companies are already onto it, which is the best we could hope for, but better in preventing future trojans would rest firmly with the sponsors. They need simply to STOP relying on refcodes and start implementing something more robust.

It's not rocket science.... yet it requires a bit of backend work, which most don't want to do, until that is enough affiliates start talking up....
__________________

For coding work - hit me up on andy // borkedcoder // com
(consider figuring out the email as test #1)



All models are wrong, but some are useful. George E.P. Box. p202
borked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 05:13 PM   #25
Lanceman
So Fucking Banned
 
Join Date: Mar 2007
Posts: 301
Anti Spyware Coalition.
PLEASE SEE THREAD AND SIGN THE FUCK UP!!!!!!!!!!!!!
Lanceman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 08:20 PM   #26
irbobo
Confirmed User
 
irbobo's Avatar
 
Industry Role:
Join Date: Dec 2005
Posts: 410
Fuck those homos... I hope someone stops them up.
__________________
irbobo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 08:28 PM   #27
Legendary_Samir
So Fucking Banned
 
Join Date: Dec 2006
Posts: 440
where is Ukraine?
Legendary_Samir is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-11-2007, 08:48 PM   #28
Tempest
Too lazy to set a custom title
 
Industry Role:
Join Date: May 2004
Location: West Coast, Canada.
Posts: 10,217
Quote:
Originally Posted by nation-x View Post
Some investigation of this ip revealed that it resolves to an ISP called InterCage...

After digging a little deeper into Intercage I discovered that they have been blacklisted and accused of many crimes... including hijacking proxies and whole netblocks...
Big surprise that intercage is involved with this.. I posted this thread a year ago.. read the last three posts.

http://www.gofuckyourself.com/showthread.php?t=573522
Tempest is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2007, 04:28 AM   #29
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
it funny how this shit has turned out to be all interconnected
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 03-12-2007, 06:16 AM   #30
nation-x
Confirmed User
 
nation-x's Avatar
 
Industry Role:
Join Date: Mar 2004
Location: Rock Hill, SC
Posts: 5,370
I am amazed at the lack of response I am seeing to these threads...
nation-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.