CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

Live Trojan (Zlob + Dnschanger) hosting sites takedown
Goto page Previous  1, 2, 3, 4, 5, 6
 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
419Eniac

Cadet
Cadet


Joined: Sep 12, 2007
Posts: 7
Location: Germany

PostPosted: Fri Sep 14, 2007 8:27 am    Post subject:
Reply with quote

JeanInMontana wrote:
I am curious as to how they will die? EST won't do anything in most cases, that is why these miscreants choose to host there.


I absolutely can't second that. Estdomains.com has turned out to be the most cooperative registrar I have ever seen. I have already killed over 80 scam sites (419 fake banks, romo escrows, mule sites, other crap) registered there. If you want to complain to Estdomains always use their ticket system at http://support.estdomains.com/index.php?_m=tickets&_a=submit , as their abuse adress bounces. The ticket system works perfectly and fast, normally they respond within an hour.

BTW: Estdomains is the name registrar not the hoster. A registrar kill is far better than a hoster kill as it prevents the fraudulent site to be rehosted on another server or on a botnet. The domain name will be suspended and removed from the DNS. That's the killing modality.

Complaint sent.



Eniac

Back to top
View users profile Send private message
JeanInMontana

Sergeant
Sergeant
Premium Member

Joined: Jun 20, 2005
Posts: 148

Premium

PostPosted: Fri Sep 14, 2007 5:52 pm    Post subject:
Reply with quote

The malicious link is still in the member profile on your website. I downloaded and scanned the codec installer and it is not that well detected right now, which makes it far more dangerous for the unsuspecting victim. It has been submitted to a forum with many malware vendors as members.

You should get rid of that member that is your spammer and that link is very bad.

Thanks for the EST tip.


_________________
MontanaMenagerie
Back to top
View users profile Send private message Visit posters website
mechBgon

Lieutenant
Lieutenant


Joined: May 13, 2007
Posts: 216

MVP

PostPosted: Fri Sep 14, 2007 6:18 pm    Post subject:
Reply with quote

419Eniac wrote:
http://forum.escrow-fraud.com/ just got spammend (Topless Paris Hilton), offending URL is
http:||about-adult.net|kingston|1125932160|1|player.php?m=bW92NC53bXY&id=1237&tpl=8

This forwards to http:||www.codec-club.com|download|videosaccess1000.exe

Both sites are registered by VERY cooperative registrar Estdomains.com and will die tomorrow.


Eniac


codec-club.com is still resolving, and so is about-adult.net. I somehow doubt Estdomains is going to take them down until after the bad guys are done with them.


_________________
Vista x64 · non-Admin account + Software Restriction Policy · Kaspersky AntiVirus 7 · Windows Firewall · full hardware DEP · 64-bit IE7 PM
Back to top
View users profile Send private message
igorb

Private
Private


Joined: Jun 09, 2007
Posts: 36
Location: USA

PostPosted: Fri Nov 23, 2007 6:23 pm    Post subject:
Reply with quote

Okay, guys I run PHSDL amd have over 1,500 verified Zlob ActiveX rediret domains on this primary database list.
http://www.phsdl.net/project_honeypot.php

Here are 22,000 searchable database domains, but only the primary subset has been varified.
The probability of all of them being of Zlob family or a variant is very high, but you may find a few false positives.
http://www.phsdl.net/search_spam_domains.php

If you need help or have a question, please let me know.

Igor Berger
PHSDL Project
Administrator

Back to top
View users profile Send private message Visit posters website
aa419_Derek

Cadet
Cadet


Joined: Sep 07, 2007
Posts: 8
Location: https://**********

PostPosted: Fri Dec 07, 2007 2:08 pm    Post subject:
Reply with quote

At the moment codec-club.com is down - no DNS server

Quote:
Domain Name: CODEC-CLUB.COM
Registrar: ESTDOMAINS, INC.
Whois Server: whois.estdomains.com
Referral URL: http://www.estdomains.com
Name Server: No nameserver
Status: ok
Updated Date: 17-sep-2007
Creation Date: 16-apr-2007
Expiration Date: 16-apr-2008

Quote:
--- DNS lookup for "www.codec-club.com", please wait...
--- contacting nameserver: a.gtld-servers.net [192.5.6.30]

DNS Server Response 3: Name Error.
com SOA
origin = a.gtld-servers.net
mail addr = nstld@verisign-grs.com
serial = 1197036393
refresh = 1800 (30 mins)
retry = 900 (15 mins)
expire = 604800 (7 days)
minimum ttl = 900 (15 mins)

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Goto page Previous  1, 2, 3, 4, 5, 6
Page 6 of 6

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer