Spyware Warrior Spyware Warrior
Help with Spyware, Hijacking & Other Internet Nuisances
 
FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

bestnotospy.net DANGEROUS SPAM

 
Post new topic   Reply to topic    Spyware Warrior Forum Index -> Spyware/Adware in the News
View previous topic :: View next topic  
Author Message
YUGWEN
Warrior


Joined: 17 Jun 2004
Last Visit: 23 Apr 2007
Posts: 121
Location: Oregon

PostPosted: Thu Feb 24, 2005 10:24 am    Post subject: bestnotospy.net DANGEROUS SPAM Reply with quote

I have been working about 20 hours a week JUST on getting keywords and domains added to SPAM filters. One such SPAM message that I opened was so sneaky that it NAILED me. I should have known better, but I was in such a speed production mode of grabbing and inputting data that I let my guard down...

In a SPAM message there is a delayed "pop up" within the SPAM that poses as a mail error. (it is actually just an image link file but it downloads delayed so that it appears to "pop up") It exactly matches something you would see and just click on to close. Which, of course, I did. I normally move slow enough to notice a cursor change, but not this time... When I clicked on the red "X" it imediately hijacked me out to its website. SPAM/spyware/adware = virus! Mad I immediately closed the window before it could finish loading, but now I have to scan this system for EVERYTHING... Sad

This is something to watch out for, and should NOT be legal in any way shape or form! This is a 100% deceptive attack against everyone they send the message to. I am going to send this message to the authorities and see if they can slap these creeps down...

Watch out for these guys and their nasty tricks... bestnotospy.net Mad Mad Mad
_________________
Absorb what is useful
Back to top
View user's profile Send private message
MadameX
Site Admin


Joined: 12 Jul 2004
Last Visit: 27 Apr 2008
Posts: 1438

PostPosted: Thu Feb 24, 2005 10:34 am    Post subject: Reply with quote

Thanks for the heads up, Yugwen! Big Thumb Up
_________________
CARMA
Back to top
View user's profile Send private message Visit poster's website
YUGWEN
Warrior


Joined: 17 Jun 2004
Last Visit: 23 Apr 2007
Posts: 121
Location: Oregon

PostPosted: Thu Feb 24, 2005 12:20 pm    Post subject: Update- myspyzone.com same deal! Reply with quote

I don't know who the paretn company for this stuff is, but I am sure it is creating a HEAP of victims. I don't know what it does, but I can only imagine what they do to the people that the con into going to their website... Shocked

myspyzone.com is using the exact same SPAM tactic as in the message above, so they are probably the exact same thing... I'm sure there are going to be more, so I will just edit this message and add their names to it if I see them. If anyone knows who is behind this please let me know. I am afraid to fully follow the link on a Windows machine, even as protected as I try to keep them... Rolling Eyes I think I will forward one of these messages to my Yahoo account and then go to it on my OS 8.6 Mac... That ought to slap down any of their nasty plans Laughing Laughing Laughing

I hope everyone is having more fun than I am Rolling Eyes

SPAM, Spyware, Adware, Viruses... Oh my!
_________________
Absorb what is useful
Back to top
View user's profile Send private message
3162
Honorary Site Admin


Joined: 31 Mar 2004
Last Visit: 04 May 2009
Posts: 4452

PostPosted: Thu Feb 24, 2005 12:42 pm    Post subject: Reply with quote

Yugwen, could you fwd one to me as well?
Send it to 3162 -at- spywarewarior.com
Thanks Wink
_________________
Proud member of the Chest Zipper Club!
Back to top
View user's profile Send private message
Chao284
Warrior


Joined: 06 Sep 2004
Last Visit: 09 Dec 2013
Posts: 220
Location: Bremerton, WA

PostPosted: Thu Feb 24, 2005 11:07 pm    Post subject: Reply with quote

Guys before making any new things, I beleve there is a connection to the new URL and to this virant wich is the same of coruse,

Spy-Control spy-control.com
spyware-list.info installs Searchmeup parasite (1); unconscionable license terms; dubious implied endorsement (1); Ad-ware knockoff (1); same app as Ad-Eliminator
Back to top
View user's profile Send private message
Scaramouche
Malware Expert


Joined: 06 Jul 2004
Last Visit: 03 May 2006
Posts: 141
Location: Manila, Philippines

PostPosted: Fri Feb 25, 2005 2:18 am    Post subject: Reply with quote

These guys are starting to pop up constantly for me from my 'research' vx2 infection. I think it's really sad that supposed spyware companies actually use SPYWARE-GENERATED POPUPS to flog their product. It's like shooting someone in the leg to try and sell them a bullet-proof vest. It also pitches Spyware Stormer, Privacy Defender, Spyware Nuker, BulletProof Anti Spy, and 'spyware ferret'. Ad rotations change usually every couple of days so it ends up being a 'who's who of rogue anti-spyware'.
_________________
---
My comments represent my own opinions and research.
Back to top
View user's profile Send private message Yahoo Messenger
eburger68
SWW Distinguished Expert


Joined: 23 Jun 2004
Last Visit: 18 Nov 2008
Posts: 575
Location: Clearwater, FL

PostPosted: Fri Feb 25, 2005 4:05 am    Post subject: Reply with quote

Scaramouche:

Do you have screenshots of those pop-ups? URLs for the pages that pop up? If so, send them to me and I'd be happy to add that description to the rogue/suspect list.

Best,

Eric L. Howes
Back to top
View user's profile Send private message Send e-mail Visit poster's website
Moore
Moderator


Joined: 31 May 2004
Last Visit: 16 Jun 2014
Posts: 758
Location: °°.MooreLand.°°

PostPosted: Fri Feb 25, 2005 7:38 am    Post subject: Reply with quote

Wow , you hit the jackpot on these guys YUGWEN .. Twisted Evil

This list of domains might help you block the rest of their garbage.

Lets all block them hey.. Looks like a few good entries for Spyware blocklists , Hosts and IE spyads I think Wink


bestnotospy.net:82.114.48.64-82.114.48.64

bestnotospy.net
SPY-CONTROL.COM

82.114.48.0-82.114.48.255
Taurus Telecom interconnect block #48
Moscow, Russia
Russian Federation

Website Status: Active
Reverse IP: Web server hosts 160 websites
IP Address: 82.114.48.64
IP Location: - Taurus-block

Name Server: NS7.WDRHOSTING.COM NS4.BIGHOSTSOLUTIONS.COM
ICANN Registrar: TUCOWS INC.
Created: 14-dec-2004
Expires: 14-dec-2005
Status: ACTIVE

Registrant:
kozlu i companiya
po box 4567
kiev, ua 65000
UA

Domain name: SPY-CONTROL.COM

Administrative Contact:
kozlodoev, ivan
po box 4567
kiev, ua 65000
UA
+38.0503106754

Registrar of Record: TUCOWS, INC.
Record last updated on 30-Jan-2005.
Record expires on 14-Dec-2005.
Record created on 14-Dec-2004.

Domain servers in listed order:
LAYER1.MORPHEUS-SPYWARE.INFO
NS7.WDRHOSTING.COM 222.223.134.244
LAYER2.MORPHEUS-SPYWARE.INFO
NS4.BIGHOSTSOLUTIONS.COM 218.7.120.118

Blacklisted here :
http://www.joewein.de/sw/bl-log-2005-02-13.htm

Quote:
morpheus-spyware.info (bl=2005-02-13, rogue-ns=layer1.morpheus-spyware.info, created=2004-11-10)



A few garbage links pages I found googleing ^ morpheus spyware info name :

Code:
hxxp://www.spyware-links.com/morpheus-spyware/morpheus-spyware.html
hxxp://www.web-search-links.com/search.php?qq=spyware
http://www.livesearching.com/search.php?id=15&q=spyware



Domain status: ACTIVE

160 domains found on 82.114.48.64

As Suzi often says , dont click the links ! .. Razz

Code:
www.1st-fightpy.net
www.1stspyzone.com
www.4spy-control.com
www.A5p5.com
www.Aim-spyware.info
www.Aimspyware.info
www.Bestnotospy.net
www.Bestspy-control.com
www.Better-notospy.net
www.Betternotospy.net
www.Block-spyware.info
www.Buy-notospy.net
www.Delete-spyware.info
www.Deletespyware.info
www.Free-kazaa-spyware.info
www.Free-pc-spyware-ware.info
www.Freekazaaspyware.info
www.Freepcspywareware.info
www.Freespywareware.info
www.Gcardusa.info
www.Gcardvista.info
www.Gcfive.info
www.Gcfour.info
www.Gcone.info
www.Gctousanow.info
www.Gctwo.info
www.Gcusa.info
www.Gcusaone.info
www.Gcusatwo.info
www.Gcvista.info
www.Gcvistanow.info
www.Gr33ncardvisa.com
www.Greencardboard.info
www.Greencardvista.info
www.Greencboard.info
www.Greencusa.info
www.Greencvista.info
www.Kazaa-no-spyware.info
www.Kazaanospyware.info
www.M1p2.com
www.Morpheus-spyware.info
www.Morpheusspyware.info
www.My-us-visa.com
www.My-visa-to-usa.com
www.Mydvblue.info
www.Mydvboard.info
www.Mydvdream.info
www.Mydvforever.info
www.Mydvgreen.info
www.Mydvlottery.info
www.Mydvone.info
www.Mydvred.info
www.Mydvwin.info
www.Mygcboard.info
www.Mygcone.info
www.Mygcten.info
www.Mygctousa.info
www.Mygcusa.info
www.Mygcvista.info
www.Myspyzone.com
www.Myusavisa.org
www.Myusgc.com
www.Myusgreencardtousa.com
www.Myusvisa.org
www.Myvisatousa.com
www.Onegcboard.info
www.Onegreencard.com
www.Spy-control.com
www.Spy-control.net
www.Spyware-finder.info
www.Spyware-list.info
www.Spyware-software.info
www.Spywarefinder.info
www.Spywarelist.info
www.Spywareremove.info
www.Spyzone-time.com
www.Spyzone4all.com
www.Spyzonetown.com
www.Twogreencard.com
www.Usa-vista.com
www.Usabis.com
www.Usabis.org
www.Usagis.org
www.Usavisit.org
www.Usavista.org
www.Usvista.org
www.Visa-to-usa.org
www.Visaforme.org
www.Visita-usa.com
www.Win-a-green-card.com
www.Win-a-greencard.org
www.Win-usa-green-card-today.com
www.Win-usa-green-card.com
www.Winagc.com
www.Fightpyco.net
www.Fightadware.net
www.Fightpyclub.net
www.Fightpycity.net
www.Every-spy-control.com
www.Dv-eight.info
www.Dv-five.info
www.Dv-four.info
www.Dv-nine.info
www.Dv-one.info
www.Dv-seven.info
www.Dv-six.info
www.Dv-ten.info
www.Dv-three.info
www.Dv-two.info
www.Gc-eight.info
www.Gc-five.info
www.Gc-four.info
www.Gc-nine.info
www.Gc-one.info
www.Gc-seven.info
www.Gc-six.info
www.Gc-ten.info
www.Gc-three.info
www.Gc-two.info
www.Anti-spyware-protection.net
www.Adios-spyware.info
www.Cancel-spyware.info
www.Clean-spyware-now.com
www.Clean-spyware.info
www.Counter-spy.info
www.Crushspyware.net
www.Eliminateadware.net
www.Killspywarenow.net
www.Remove-spyware-now.info
www.Spy-block.info
www.Spy-control-now.com
www.Spy-crumble.net
www.Spy-deleter.info
www.Spy-destroyer.com
www.Spy-disposer.com
www.Spy-eradicator.net
www.Spy-eraser.com
www.Spy-exclude.info
www.Spy-negate.info
www.Spy-police.net
www.Spyabolish.com
www.Spyarrest.info
www.Spybanner.info
www.Spycleaner.info
www.Spyclear.net
www.Spyguard.info
www.Spykiller-123.com
www.Spyneutralizer.info
www.Spynuke.info
www.Spyware-crusher.net
www.Spyware-exterminator.com
www.Spyware-go-away.info
www.Spyware-smasher.com
www.Spywarecleanser.info
www.Spywareprotector.info
www.Spywareremovenow.com
www.Spywareslayer.net
www.Stop-spyware-now.info
www.Wipe-out-spyware.info


<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
_________________
| Stop Malvertising | Outpost | Blocklist Pro | Hosts |
Back to top
View user's profile Send private message Visit poster's website
Scaramouche
Malware Expert


Joined: 06 Jul 2004
Last Visit: 03 May 2006
Posts: 141
Location: Manila, Philippines

PostPosted: Fri Feb 25, 2005 12:15 pm    Post subject: Reply with quote

eburger68 wrote:
Scaramouche:

Do you have screenshots of those pop-ups? URLs for the pages that pop up? If so, send them to me and I'd be happy to add that description to the rogue/suspect list.

Best,

Eric L. Howes


Eric -

I'd be glad to. Unfortunately I'm leaving for a holiday this weekend but I'm sure that I'll have a nice crop of pop-ups to send you when I get back Monday night (Sunday your time most likely).
_________________
---
My comments represent my own opinions and research.
Back to top
View user's profile Send private message Yahoo Messenger
Scaramouche
Malware Expert


Joined: 06 Jul 2004
Last Visit: 03 May 2006
Posts: 141
Location: Manila, Philippines

PostPosted: Mon Feb 28, 2005 10:21 pm    Post subject: Reply with quote

Eric -

They've changed the ad catalogue again so I wasn't able to get all of the providers this time around but here's the four I did find. Unfortunately the BPS one doesn't have a traceable URL in it but I'll probably get an Ethereal dump for that.








_________________
---
My comments represent my own opinions and research.
Back to top
View user's profile Send private message Yahoo Messenger
Scaramouche
Malware Expert


Joined: 06 Jul 2004
Last Visit: 03 May 2006
Posts: 141
Location: Manila, Philippines

PostPosted: Tue Mar 01, 2005 3:34 am    Post subject: Reply with quote

Here's another one just came up for privacy defender


_________________
---
My comments represent my own opinions and research.
Back to top
View user's profile Send private message Yahoo Messenger
radio
Moderator & HJT Expert


Joined: 21 May 2004
Last Visit: 05 Aug 2011
Posts: 260

PostPosted: Tue Mar 22, 2005 6:11 am    Post subject: Reply with quote

<<bump>>


I've noticed a lot of SPAM activity for this group again in the last couple of days on our mailserver, coming from spambots


they're pointing to a differnet IP# now

Quote:
141 domains found on 82.114.48.65
Showing all 141.

Website
www.1st-fightpy.net
www.1stspyzone.com
www.4spy-control.com
www.A5p5.com
www.Adios-spyware.info
www.Aim-spyware.info
www.Aimspyware.info
www.Bestnotospy.net
www.Bestspy-control.com
www.Better-notospy.net
www.Betternotospy.net
www.Block-spyware.info
www.Buy-notospy.net
www.Delete-spyware.info
www.Deletespyware.info
www.Dv-eight.info
www.Dv-five.info
www.Dv-four.info
www.Dv-nine.info
www.Dv-one.info
www.Dv-seven.info
www.Dv-six.info
www.Dv-ten.info
www.Dv-three.info
www.Dv-two.info
www.Every-spy-control.com
www.Fightadware.net
www.Fightpycity.net
www.Fightpyclub.net
www.Fightpyco.net
www.Free-kazaa-spyware.info
www.Free-pc-spyware-ware.info
www.Freekazaaspyware.info
www.Freepcspywareware.info
www.Freespywareware.info
www.Gc-eight.info
www.Gc-five.info
www.Gc-four.info
www.Gc-nine.info
www.Gc-one.info
www.Gc-seven.info
www.Gc-six.info
www.Gc-ten.info
www.Gc-three.info
www.Gc-two.info
www.Gcardusa.info
www.Gcardvista.info
www.Gcfive.info
www.Gcfour.info
www.Gcone.info
www.Gctousanow.info
www.Gctwo.info
www.Gcusa.info
www.Gcusaone.info
www.Gcusatwo.info
www.Gcvista.info
www.Gcvistanow.info
www.Gr33ncardvisa.com
www.Greencardboard.info
www.Greencardvista.info
www.Greencboard.info
www.Greencusa.info
www.Greencvista.info
www.Kazaa-no-spyware.info
www.Kazaanospyware.info
www.M1p2.com
www.Morpheus-spyware.info
www.Morpheusspyware.info
www.My-us-visa.com
www.My-visa-to-usa.com
www.Mydvblue.info
www.Mydvboard.info
www.Mydvdream.info
www.Mydvforever.info
www.Mydvgreen.info
www.Mydvlottery.info
www.Mydvone.info
www.Mydvred.info
www.Mydvwin.info
www.Mygcboard.info
www.Mygcone.info
www.Mygcten.info
www.Mygctousa.info
www.Mygcusa.info
www.Mygcvista.info
www.Myspyzone.com
www.Myusgc.com
www.Myusgreencardtousa.com
www.Myvisatousa.com
www.Onegcboard.info
www.Onegreencard.com
www.P2u1.com
www.Spy-control-now.com
www.Spy-control.com
www.Spy-control.net
www.Spy-crumble.net
www.Spy-deleter.info
www.Spy-destroyer.com
www.Spy-disposer.com
www.Spy-eradicator.net
www.Spy-eraser.com
www.Spy-exclude.info
www.Spy-negate.info
www.Spy-police.net
www.Spyabolish.com
www.Spyarrest.info
www.Spybanner.info
www.Spycleaner.info
www.Spyclear.net
www.Spyguard.info
www.Spykiller-123.com
www.Spyneutralizer.info
www.Spynuke.info
www.Spyware-crusher.net
www.Spyware-exterminator.com
www.Spyware-finder.info
www.Spyware-go-away.info
www.Spyware-list.info
www.Spyware-smasher.com
www.Spyware-software.info
www.Spywarecleanser.info
www.Spywarefinder.info
www.Spywarelist.info
www.Spywareprotector.info
www.Spywareremove.info
www.Spywareremovenow.com
www.Spywareslayer.net
www.Spyzone-time.com
www.Spyzone4all.com
www.Spyzonetown.com
www.Stop-spyware-now.info
www.Twogreencard.com
www.Usa-vista.com
www.Usabis.com
www.Usagis.org
www.Visita-usa.com
www.Win-a-green-card.com
www.Win-usa-green-card-today.com
www.Win-usa-green-card.com
www.Winagc.com
www.Wipe-out-spyware.info

_________________
PcPitstop Forums
Back to top
View user's profile Send private message Visit poster's website
Moore
Moderator


Joined: 31 May 2004
Last Visit: 16 Jun 2014
Posts: 758
Location: °°.MooreLand.°°

PostPosted: Tue Mar 22, 2005 7:51 pm    Post subject: Reply with quote

Good catch Radio , thanks for the update.. Cool
_________________
| Stop Malvertising | Outpost | Blocklist Pro | Hosts |
Back to top
View user's profile Send private message Visit poster's website
webhelper
SWW Expert


Joined: 11 Apr 2004
Last Visit: 16 Jul 2011
Posts: 1090

PostPosted: Tue Mar 22, 2005 8:24 pm    Post subject: Reply with quote

Moore wrote:
Good catch Radio , thanks for the update.. Cool


Yes good catch and you will notice the IPs of most:
82.114.48.65
Our favorite Russian Federation IP blocks.
_________________
Wächter der Geschichten:
http://www.webhelper4u.com/thewatcher.html
Member of ASAP Since 2004
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Spyware Warrior Forum Index -> Spyware/Adware in the News All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group