Blog for hpHosts, and whatever else I feel like writing about ....

Wednesday, 26 March 2014

ALERT: Green Tech Software LLC

... and the crapware just keeps on a' comin'

This one was found on bayfiles.net, and yep, they're fully aware of it (impossible to miss). See if you can spot the two problems here;

Spotted it? What do you mean no!

Seriously though, the first is far more obvious than the second, for those not used to being able to spot this rubbish. See that lovely little "bar" at the top? Well that's the blatantly obvious one. This leads to utorrent.descargar.es.

The second is the download button that err - isn't. These lead to crapware from Green Tech Software LLC, via 1phads.com and fishcod.com, and guess what it actually delivers ........ Yep, "Codec Performer".

Offending URLs:

hxxp://bayfiles.net/file/Skpl/TUtckf/Black_Crusade_The_Tome_of_Excess.7z
hxxp://utorrent.descargar.es/en/down.php?p=UK-1phads
hxxp://1phads.com/afu.php?zoneid=5900
hxxp://bayfiles.net/img/download-button-orange.png
hxxp://1phads.com/uban.php?r=Tc1XgxDYp_BM-gXutIXN9MMspZxoXRS2yszKditYRtrfw7iRJ3cTj09oGH1-EfJUxjJJ_I1l5mRlgQ1Mob9jvGHLzXjdw0vJSAHcIhbfja09KBkxLi3DuPGJIcoLkNaCCpcJBDkjCoMP72bbNArxTC16Wkd4oSOhB58UQquMP729wp5mkVUoa5ipNFi1ooBY5AUMUWg94JiHoHeq8wKo3Ungr3i8HVwSWNOcJ4yRoQXRbslWdoi9dH75z7ngmfBr
hxxp://1phads.com/ck.php?oaparams=2__bannerid=85744__zoneid=4082__OXLCA=1__cb=8b22970bfc__oadest=hxxp%3A%2F%2Fwww.clkads.com%2FadServe%2Faff%3Foid%3D7526%26pid%3D2556%26subid%3D%24{SUBID}
hxxp://1phads.com/ck.php?ct=1&oaparams=2__bannerid=85744__zoneid=4082__OXLCA=1__cb=8b22970bfc__oadest=hxxp%3A%2F%2Fwww.clkads.com%2FadServe%2Faff%3Foid%3D7526%26pid%3D2556%26subid%3D%24{SUBID}
hxxp://www.clkads.com/adServe/aff?oid=7526&pid=2556&subid=4946299328
hxxp://www.fishcod.com/lp/codecperformer/?v=28&cid=4225&clickid=00002556p9087732588
hxxp://www.fishcod.com/lp/codecperformer/v28/?v=28&cid=4225&clickid=00002556p9087732588
hxxp://www.appfusu.com/download4/$rfwebpA3I0UlnA0p?v=28&cid=4225&clickid=00002556p9087732588&cert=grts


IPs:

192.121.121.44
93.189.35.250
93.189.35.248
78.140.173.146
78.140.173.147
108.168.157.82
96.45.82.133
96.45.82.5
96.45.82.197
96.45.82.69

FYI, ALL download pages on bayfiles.net display the same rubbish, leading to the same crap you really don't want anywhere near your machine.

Friday, 21 March 2014

Updated: hpHosts 21-03-2014

The hpHOSTS Hosts file has been updated. There is now a total of 421,807 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 21/03/2014 11:03
  2. Last Verified: 16/03/2014 07:00
Download hpHosts now!
http://hosts-file.net/?s=Download

Friday, 7 March 2014

Oi GoDaddy!

For the billionth time - retrain your staff so they are capable of identifying your own damn ranges!. Hint, if I send you a report, it's because the IP = YOUR ASN!, and these are checked with the various registries prior to sending. If your abuse dept/support staff (quite why the support staff reply to abuse reports instead of the abuse dept, is beyond me) are uncapable of learning something so basic - replace them with people that are, it's not rocket science.

I wish the following were a one off, but these are becoming rather frequent replies.

Customer Inquiry

Dear Sir/Madam,

Thank you for bringing this to our attention. At this time we have determined the reported website is hosted elsewhere. If you would like to take further action regarding the content on this website, we recommend you contact the hosting provider directly.

Please contact us if you have any further issues.

Regards,

Customer Security Advisors

Sunday, 16 February 2014

Misleading: Bandoo wants a go!

Got a notification about a new version of the Android x86 distro earlier and finally had a few minutes to go take a look. Going to the download page my eyes were drawn immediately to this piece of naughtiness from Bandoo;


Not that surprised given Bandoo's history, but to my recollection, this is the first time I've seen one for them in the last 6-12 months or so.

The offending URLs in this case, for those interested;

http://ads.yahoo.com/clk?3,eJydTl2PgjAQ.DW8KaG0IIbcQznEeAdGE--MvFUopVhaA.Xrfv3Vw5j4epPN7mSzM7MAhn6BwKQsJ06JpqB0vBAgBIsq8CvqjJwwDF04hZ6HAg-MYHLVOE3TOYtuUh4ifEdq77.XeADDM4wXA18F9x7N55fL52VYoUxsBvau89bB.0esvqLZg5s848.iADeujVazdfQ8m380WVz8ZO1SpJsDXG53OtskIruBOm8Tnm7XMG8w2rULL48P1-X6qXwbjWqtjxbElpuY0kS4Wml0olLwoITiWO-bc9cJF06KivZjMu65NlMdqexVwYmwmVJM0FNPu0JJTaW2C9UaL0ZKRnVvGK86CyanTlgwfomrVa-5ZDZrVXkStH8oOXuRV1xQM4DjewHwTfcRcBwwQRCgwZ201L62wnL9-wuES2oCY.MK7Y4d743aP3N6MbuCyDMxpr4gkv3d.AL4BKVg,
http://cnct.tlvmedia.com/ckl.php?s=1&c=3FxtALLLGgBynnkBAAAAAL.bVQAAAAAAAgAEAAIAAAAAAP8AAAABGGwwKwAAAAAA4MlTAAAAAACtZm0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADoUBEAAAAAAAIAAwAAgD8AwSD5PEQBAAAAAAAAAGQ3MTBjMTM0LTk3NWYtMTFlMy1iZDEzLWZmZjliYzdiMDlhNQAAAAAAAAA=,eJxLjfIqKg1yzMqNCA1Lj0j0z.ZwqYqILPK0TEwuy6.wiDBJ19UFAPDEDJk=&t=50164&d=2326173&hp=subid&r=http%3A%2F%2Flp.jzip.com%2F%3Flpid%3D1687%26appid%3D170
http://lp.jzip.com/?lpid=1687&appid=170&subid=CN_A100601175459816722
http://download.jzip.com/jZipSetup.exe

Ad image: http://content.yieldmanager.edgesuite.net/atoms/d7/e2/5a/92/d7e25a92fa4b89c1814c7484c668020b.gif


If you're so inclined, you'll be wanting to blackhole;

94.31.0.0/24

Hostnames:

22search.bearshare.com
22search.imesh.com
adoresearch.com
amusingcool.com
amusingfunny.com
amusingwink.com
amusingwow.com
animationbest.com
animationfaces.com
animationfine.com
animationfresh.com
animation-jet.com
animationsbest.com
animationsgoodness.com
animations-hip.com
animationssmile.com
animationsworth.com
animationtop.com
app1.imesh.com
avatarscool.com
avatarsfun.com
avatarsplay.com
awesemoticons.com
awesome-emoticons.com
banddo.com
bandoo.com
bandoo11.com
bandoo12.com
bandoo13.com
bandoo14.com
bandoo15.com
bandoo16.com
bandoo17.com
bandoo18.com
bandoo19.com
bandoo2.com
bandoo20.com
bandoo3.com
bandoo8.com
bandoobe.com
bandooinvite.com
bandooo.com
banner.bearflix.com
banners.ilivid.com
bar.bearshare.com
bar.fantastigames.com
bar.imesh.com
bar.jzip.com
bar.lphant.com
bar.searchqu.com
bar.shareazaweb.com
bearflix.com
bearshare.com
bearshare.net
bearshare.org
bestamusing.com
bestcomical.com
best-emoticons.com
blog.bearshare.com
blog.imesh.com
blog.koyotesoft.com
blogdynprod.bearshare.com
blogdynprod.imesh.com
box.imesh.com
bullvid.com
captainemoticons.com
captainwinks.com
cartoonboss.com
cartoonbosses.com
cartooncaptains.com
cartoonchief.com
cartoonpalaces.com
cartoonschief.com
cartoonsfactory.com
cartoonslord.com
cartoonswizard.com
cddb.bearshare.com
cddb.imesh.com
cddb.lphant.com
cddb.shareazaweb.com
cearch.bearshare.com
cearch.imesh.com
centralcartoons.com
centralemoticons.com
checkmsi.com
checkrealtime.com
chiefsmilies.com
chiefwinks.com
comicalbest.com
comicalemoticon.com
comicalfaces.com
comicalfine.com
comicaltop.com
comicalwink.com
connectionmsi.com
connectionrealtime.com
connectiontraffic.com
content.bandoo.com
coolamusing.com
coolemoticon.com
coolworth.com
cute-emoticons.com
de.bearshare.com
directoryrealtime.com
disco1.bearshare.com
disco1.imesh.com
disco2.bearshare.com
disco2.imesh.com
disco3.bearshare.com
disco3.imesh.com
disco4.bearshare.com
disco4.imesh.com
disco5.bearshare.com
disco5.imesh.com
dj.djboxservice.com
dm.mlstat.com
download.bandoo.com
download.bandooo.com
download.bearflix.com
download.bearshare.com
download.bullvid.com
download.cdn.koyotelab.net
download.cdn4.bearshare.com
download.downloadquick.net
download.downloadsetup.net
download.expressdownload.net
download.facewinks.com
download.free-video-downloader.net
download.ftalk.com
download.fuzezip.com
download.ilivid.com
download.imesh.com
download.inmind.com
download.jzip.com
download.kingtranslate.com
download.koyotesoft.com
download.linkeyproject.com
download.lphant.com
download.savevid.com
download.shareazaweb.com
download.sharelive.net
download.windows8startbutton.com
download-free-video.com
downloadquick.net
downloads.ilivid.com
downloadsetup.net
eee.bearshare.com
email.imesh.com
emoticonbest.com
emoticonboss.com
emoticoncentral.com
emoticonchief.com
emoticonchiefs.com
emoticoncool.com
emoticonfunny.com
emoticongreat.com
emoticonmaster.com
emoticonmasters.com
emoticonsace.com
emoticons-amazing.com
emoticonsbest.com
emoticonscool.com
emoticonsfaces.com
emoticonsgreat.com
emoticonsopen.com
emoticonspace.com
emoticons-pad.com
emoticonssmile.com
emoticonstop.com
emoticonsuniverse.com
emoticonsunreal.com
emoticonsweet.com
emoticonswizard.com
emoticonsworth.com
emoticontop.com
emoticonwizard.com
emoticonwizards.com
emoticonwow.com
emotikons-pc.com
emotikonster.com
emotikons-town.com
emotikonz.com
es.bearshare.com
es.lphant.com
excellentanimation.com
excellentemoticons.com
excellentwow.com
expressdownload.net
extensions.ftalk.com
extensions.ftalkconnect.com
extensions.ftalking.com
extremesmiley.com
facebook.comsearch.imesh.com
facesanimations.com
facesbest.com
facesfresh.com
facessmile.com
facessweet.com
facesworth.com
facewinks.com
facez-direct.com
facez-house.com
facez-log.com
facez-pc.com
facez-rocket.com
facez-topia.com
facez-toyou.com
facezunique.com
facez-volt.com
fantasticavatars.com
fantasticemoticon.com
fantasticemoticons.com
fantasticsmiley.com
fantasticsmileys.com
fantasticwink.com
fantasticwinks.com
fantastigames.com
featurebest.com
featurecool.com
featureemoticon.com
featureemoticons.com
featuregreat.com
featuresuper.com
featurewink.com
featurewinks.com
featurewow.com
ffupdate.bearshare.com
ffupdate.bearshare.com
ffupdate.bullvid.com
ffupdate.cdn.bandoobe.com
ffupdate.cdn.bn-update-download.com
ffupdate.cdn.imeshbe.com
ffupdate.cdn.koyotebe.com
ffupdate.ftalk.com
ffupdate.fuzezip.com
ffupdate.ilivid.com
ffupdate.imesh.com
ffupdate.jzip.com
ffupdate.kingtranslate.com
ffupdate.koyotesoft.com
ffupdate.lphant.com
ffupdate.savevid.com
ffupdate.shareazaweb.com
fineemoticon.com
fineemoticons.com
finesmileys.com
finesweet.com
finewinks.com
flashgreat.com
flashunreal.com
flixbanner.bearshare.com
flixbanner.shareazaweb.com
forums.imesh.com
forums.shareaza.com
fr.bearshare.com
freemail.imesh.com
free-music.imesh.com
free-video-downloader.net
freshamusing.com
freshanimations.com
freshcomical.com
freshemoticon.com
freshfeature.com
freshsmileys.com
ftalk.com
ftalkchatting.com
ftalkconnect.com
ftalkfb.com
ftalkvideochat.com
fularo.com
funaces.com
funemoticon.com
fun-emoticons.com
funnyfeature.com
funnyfine.com
funnysweet.com
funpalaces.com
fuzezip.com
g.bearshare.com
g.imesh.com
getanimations.com
gimesh.com
go.imesh.com
goo.imesh.com
goodnessemoticons.com
goodnessfeature.com
goodnesstop.com
goodnesswink.com
goodnesswinks.com
goog.imesh.com
googl.imesh.com
google.bearflix.com
google.bearshare.com
google.com.bearshare.com
google.imesh.com
goolrarch.imesh.com
greatcomical.com
greatemoticon.com
greatemoticons.com
great-emoticons.com
greatwink.com
gwww.bearshare.com
help.bearshare.com
help.lphant.com
home.jzip.com
httpswww.bearshare.com
httpwww.bearshare.com
httwww.bearshare.com
htwww.bearshare.com
hwww.bearshare.com
icon-special.com
iconz-touch.com
i-facez.com
i-icons.com
i-icons-blast.com
i-iconsteel.com
i-iconz.com
ikons-century.com
ikons-specials.com
ilivid.com
images.ilivid.com
imageupload.bearshare.com
imageupload.imesh.com
imageupload.lphant.com
imageupload.shareazaweb.com
imap.imesh.com
imesh.com
imesh.net
imeshbe.com
inmind.com
internetmsi.com
ip.ilivid.com
ip.imesh.com
isatap.imesh.com
isearch.fantastigames.com
it.bearshare.com
jzip.com
jzip.com
kingtranslate.com
koyotebe.com
koyotelab.net
koyotesoft.com
lb.bearshare.com
limewire.bearshare.com
linkeyproject.com
listmsi.com
listrealtime.com
lp.bearshare.com
lp.bullvid.com
lp.downloadquick.net
lp.downloadsetup.net
lp.expressdownload.net
lp.free-video-downloader.net
lp.ftalk.com
lp.fuzezip.com
lp.ilivid.com
lp.ilivid.com
lp.imesh.com
lp.jzip.com
lp.kingtranslate.com
lp.koyotelab.net
lp.koyotesoft.com
lp.lphant.com
lp.shareazaweb.com
lp.sharelive.net
lphant.com
lphant.net
m.bearshare.com
mail1.bearshare.com
mail2.bearshare.com
mail3.bearshare.com
mail4.bearshare.com
masteremoticons.com
mastersmilies.com
me.bearshare.com
mediabar.bearshare.com
mediabar.imesh.com
mlstat.com
mp3.bearshare.com
msicheck.com
msiconnection.com
ms-iconz.com
msidirectory.com
msirealtime.com
msitraffic.com
music.bearshare.com
musiclab.co.il
musiclab-llc.com
mx.imesh.com
niceamusing.com
niceanimations.com
niceemoticon.com
nicesmileys.com
niceworth.com
nl.bearshare.com
openavatars.com
openemoticon.com
openemoticons.com
opensmileys.com
people-roulette.com
pics.bearshare.com
pics.imesh.com
pics.shareazaweb.com
pl.bearshare.com
playavatars.com
playemoticons.com
playsmiley.com
playsmileys.com
playwinks.com
plentyofavatars.com
plentyofemoticons.com
plentyofsmileys.com
pointemoticon.com
pointemoticons.com
pop.imesh.com
pop3.imesh.com
preved.bandoobe.com
preved.checkmsi.com
preved.checkrealtime.com
preved.connectionmsi.com
preved.connectionrealtime.com
preved.connectiontraffic.com
preved.directorymsi.com
preved.directoryrealtime.com
preved.imeshbe.com
preved.internetmsi.com
preved.koyotebe.com
preved.listmsi.com
preved.listrealtime.com
preved.mmp.imesh.com
preved.msicheck.com
preved.msiconnection.com
preved.msidirectory.com
preved.msirealtime.com
preved.msitraffic.com
preved.programinternet.com
preved.programmsi.com
preved.programrealtime.com
preved.realtimedirectory.com
preved.realtimemsi.com
preved.realtimeprogram.com
preved.systemmsi.com
preved.systemrealtime.com
preved.trafficmsi.com
primesmilies.com
primewinks.com
program.ilivid.com
programinternet.com
programmsi.com
programrealtime.com
providers.ilivid.com
pt.bearshare.com
realemoticons.com
realtimedirectory.com
realtimemsi.com
realtimeprogram.com
relay.imesh.com
search.bearflix.com
search.bearshare.com
search.bearshare.net
search.fantastigames.com
search.ilivid.com
search.imesh.com
search.imesh.net
search.jzip.com
search.lphant.com
search.lphant.net
search.mlstat.com
search.searchqu.com
search.shareazaweb.com
search.shareazaweb.net
searchnu.com
searchqu.com
searchsheet.com
secure.imesh.com
secure.lphant.com
secure.shareazaweb.com
secured.bearshare.com
service.bandoobe.com
service.checkmsi.com
service.checkrealtime.com
service.connectionmsi.com
service.connectionrealtime.com
service.connectiontraffic.com
service.directorymsi.com
service.directoryrealtime.com
service.imeshbe.com
service.internetmsi.com
service.koyotebe.com
service.listmsi.com
service.listrealtime.com
service.msicheck.com
service.msiconnection.com
service.msidirectory.com
service.msirealtime.com
service.msitraffic.com
service.programinternet.com
service.programmsi.com
service.programrealtime.com
service.realtimedirectory.com
service.realtimemsi.com
service.realtimeprogram.com
service.systemmsi.com
service.systemrealtime.com
service.trafficmsi.com
shareaza.com
shareazaweb.com
sharelive.net
smileanimations.com
smilecomical.com
smilewinks.com
smileygreat.com
smileyopen.com
smileypalace.com
smileysbest.com
smileyscool.com
smileysfeature.com
smileysfine.com
smileysgreat.com
smileysopen.com
smileysplay.com
smileyssweet.com
smileystop.com
smileysunreal.com
smileyswink.com
smileysworth.com
smileyunreal.com
smileywizard.com
smiliesace.com
smiliesfactory.com
smiliesmaster.com
smiliespoint.com
smiliesspot.com
smiliesuniverse.com
smtp.imesh.com
smtp1.bearshare.com
smtp2.bearshare.com
smtp3.bearshare.com
smtp4.bearshare.com
songs.bearshare.com
special-icons.com
spicyemoticons.com
spicywinks.com
startpage.comsearch.imesh.com
stats2.ilivid.com
supercomical.com
superemoticon.com
superlaughable.com
superwinks.com
sweetcomical.com
sweetemoticon.com
sweetexcellent.com
sweetfeature.com
sweetfunny.com
symbol-special.com
systemmsi.com
systemrealtime.com
t.imesh.com
topamusing.com
topemoticon.com
top-emoticons.com
totalanimations.com
tr.bearshare.com
tra.imesh.com
trafficmsi.com
tran.imesh.com
tranl.imesh.com
tranla.imesh.com
tranlat.imesh.com
tranlate.imesh.com
triggers.wp.bandoo.com
u00252fwww.imesh.com
ultimatefeature.com
ultimatesweet.com
ultimatewink.com
unique-facez.com
unrealavatars.com
unrealemoticons.com
unrealsmiley.com
unrealwink.com
unrealwinks.com
update.bearshare.com
update.jzip.com
update.jzip.com
update.shareaza.com
w.ilivid.com
wa.bearshare.com
wa.imesh.com
wa.lphant.com
wa.shareazaweb.com
wiki.shareaza.com
windows8startbutton.com
winkaces.com
winkboss.com
winkchief.com
winkcomical.com
winkcool.com
winkextreme.com
winkfeature.com
winkfine.com
winkfree.com
winkfresh.com
winkopen.com
winkpalace.com
winkpalaces.com
winkplaces.com
winkpoint.com
winksace.com
winksbest.com
winksboss.com
winkscaptain.com
winkscetral.com
winkscomical.com
winkscool.com
winksextreme.com
winksfeature.com
winksfine.com
winksfresh.com
winksfun.com
winksgreat.com
winkslaughable.com
winksmaster.com
winksopen.com
winkspalace.com
winksplay.com
winkssmile.com
winksspace.com
winksspot.com
winkssweet.com
winkstop.com
winks-top.com
winksuniverse.com
winksunreal.com
winksweet.com
winkswizard.com
winkultimate.com
winkuniverse.com
winkunreal.com
winkwizards.com
wizardemoticons.com
wizardsmilies.com
worthanimation.com
worthanimations.com
worthbest.com
worthcool.com
worthemoticon.com
worthemoticons.com
worthfaces.com
worthfeature.com
worthfresh.com
worthgreat.com
worthsmile.com
worthsmileys.com
worthsweet.com
worthwinks.com
wowamusing.com
wowanimations.com
wowemoticon.com
wowemoticons.com
wowgoodness.com
wowsmileys.com
wowwinks.com
wp.bandoo.com
ww.bearshare.com
ww.ilivid.com
ww.imesh.com
ww1.imesh.com
www.adoresearch.com
www.bandoo.com
www.bearshare.com
www.bearshare.net
www.bullvid.com
www.earch.imesh.com
www.flv.comwww.ilivid.com
www.flv.cowww.ilivid.com
www.flv.cwww.ilivid.com
www.flvwww.ilivid.com
www.flwww.ilivid.com
www.ftalk.com
www.fwww.ilivid.com
www.ilivid.com
www.imesh.com
www.imesh.net
www.kingtranslate.com
www.kingtranslate.com
www.koyotelab.net
www.koyotesoft.com
www.lphant.com
www.m.imesh.com
www.mlstat.com
www.mlstat.com
www.searchnu.com
www.searchnu.com
www.searchqu.com
www.searchsheet.com
www.shareaza.com
www.shareazaweb.com
www.sharelive.net
wwww.bearshare.com
wwww.ilivid.com
wwww.imesh.com
wwwww.ilivid.com
wwwwww.ilivid.com
xn--ch-p0ca8000g8k2g.bearshare.com
xn--ch-qed879d7q4n2x8c.bearshare.com
yluviwww.imesh.com
yluvizrealwww.imesh.com
yluvizreawww.imesh.com
yluvizrewww.imesh.com
yluvizrwww.imesh.com
yluvizwww.imesh.com
yluvwww.imesh.com
yluwww.imesh.com
ylwww.imesh.com
ywww.imesh.com

Spyware Sucks: Dear Google and Microsoft

This alert appeared in Google Chrome today. I have no idea why. Dear Google: how am I meant to know if this is a “real” Skype extension? There’s no information about the provider/developer on that screen and if I close the dialogue because I don’t want to install something unexpected unless I know it is legit I lose the opportunity to install (there’s nothing in the Extensions window – even disabled – and the prompt to enable disappears from the Customize dropdown).


Read more http://msmvps.com/blogs/spywaresucks/archive/2014/02/15/1985636.aspx