You are not logged in.

#1 2010-01-17 2:12 pm

poultryexcuse
Member
Registered: 2009-09-08
Posts: 96

Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

About a week+ ago, we noticed a Guest with at least 10 different connections to our forum; all the same Netherlands IP#, all different UserAgents.  My first thought was "I bet this isn't just benevolent experimentation/curiosity."

About 3 days ago Admin spammed our members emails; today ROOT blasted PMs.

Payload was a "helpful" notice about virus infection with a link to click for help.


"Status: Banned
Join Date: 01-17-10
Important message from the forum administration
Dear, *****;***;****;*****!

A virus alert was noticed on your computer.
We highly recommend you to check your computer and perform online virus check at our site immediately: hxxp://antivirus.effectmeds.com/Baja...ghttrain;Marty Cortez;gointomex
----------------------------------------------------
Sincerely, Forum Administration TalkBaja.com - Baja Mexico Travel, Living and Retirement - Powered by vBulletin. "


http://www.stopforumspam.com/ipcheck/217.23.14.67

Reverse DNS from ROOT email domain antivir-labs.com
http://www.stopforumspam.com/search.php … 72.225.209

Reverse DNS from payload domain effectmeds.com
http://samspade.org/whois/91.215.170.11


Deleted ROOT's messages and an acknowledgement briefly flashed something like "37 messages deleted; 187 receipts deleted"...

Our Max Recipients and Throttle Quantity for Registered Users PMs are both set to 2...

We've got "Can Email Members" and "Can Use Email to Friend" set to yes for this group; maybe we should change that.


Anybody else seen this?

Offline

#2 2010-01-17 2:44 pm

pedigree
uıɐbɐ ʎɐqǝ ɯoɹɟ pɹɐoqʎǝʞ ɐ buıʎnq ɹǝʌǝu ɯ,ı
From: Londonderry
Registered: 2008-04-16
Posts: 4,445

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

I just editted your url to remove the link to them, giving them a pingback

Offline

#3 2010-01-17 3:56 pm

insektenfang
Member
From: UK
Registered: 2009-04-17
Posts: 392
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

TalkBajaBoys wrote:

Anybody else seen this?

I didn't let it get that far. IP address banned on registration.


insektenfang plants
carnivorous plant nursery

Offline

#4 2010-01-17 4:06 pm

ih8spam
Member
Registered: 2009-03-25
Posts: 266

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

I haven't seen it,
but ironically enough.... 2 days ago I added the name "ADMIN" to my reserved names list to prevent anyone from trying to impersonate me, and sending out a message like the one you got .

and I am guessing that "LadyROOT" was a bot, so it was sending out many PMs one at a time, so the limit on PM recipients wouldn't matter much .


"Two years from now, spam will be solved."
Bill Gates, founder of Microsoft, 2004

Offline

#5 2010-01-17 4:54 pm

MartinV
Member
Registered: 2009-05-21
Posts: 39

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

The Dutch IP is a data center, a host to a bunch of webservers. As a rule, when a spammer registers and the IP is in a data center like this one is, I block the whole data center. I assume that real people who register at our forum will come from an ISP and not from a data center. In this case in .htaccess it says for this range:
deny 217.23.0.0/20

Sometimes the whois info will tell whether an ip-block solely belongs to a data center, it is not always obvious. When in doubt I google the owner of the ip range. In this case it was easy to determine because I am from the Netherlands too.

I had a registrant at our forum last month from a different IP but from the same data center:
http://www.stopforumspam.com/search?q=217.23.6.233
Other IP's from the same data center as a source of spam reported at stopforumspam:
217.23.14.67
217.23.6.129
217.23.6.233
217.23.3.223
217.23.8.135
217.23.7.95
217.23.6.71
217.23.7.163
217.23.6.66

Offline

#6 2010-01-18 10:00 am

poultryexcuse
Member
Registered: 2009-09-08
Posts: 96

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

pedigree wrote:

I just editted your url to remove the link to them, giving them a pingback

Oops; thank you.  I don't entirely understand what that means(search engine listing?), but no matter.

I just help moderate a bit and have very close to zero technical understanding.

We've since used Promotion to limit the PM/email ability to 10 posts/30 days membership; considering vbStopForumSpam, but have just been looking up/submitting manually so far.

Thanks for the tips, gang.

Offline

#7 2010-01-20 10:02 am

ih8spam
Member
Registered: 2009-03-25
Posts: 266

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

LadyROOT showed up on my board early this morning .

------------------------------------------------
217.23.14.67    Wed Jan 20, 2010 3:12 am    Attempted spam-bot registration
Username: LadyROOT
E-mail: ilmenit603@antivir-labs.com
Reported successfully
-------------------------------------------------

but she wont be PMing anyone, since my board puts all bots into a member group that has no posting or PM privileges . 4.gif


"Two years from now, spam will be solved."
Bill Gates, founder of Microsoft, 2004

Offline

#8 2010-01-25 2:53 pm

insektenfang
Member
From: UK
Registered: 2009-04-17
Posts: 392
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

Hmm..

I recently submitted entries for both an AdminLady and a trueLadyAdmin

On checking the "My Spammers" list and plugging the IP addresses into the search function, both entries appear to have evaporated from the database.

Explanation anyone?


insektenfang plants
carnivorous plant nursery

Offline

#9 2010-01-27 1:04 pm

insektenfang
Member
From: UK
Registered: 2009-04-17
Posts: 392
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

insektenfang wrote:

Explanation anyone?

I'll take that as a 'No' then... and re-enter the data. hmm


insektenfang plants
carnivorous plant nursery

Offline

#10 2010-02-02 12:01 pm

RFiend
Member
From: Dallas, Texas
Registered: 2008-11-13
Posts: 35
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

We had 'LadyROOT' on one of our forums, with the helpful message from Admin about infected computers going out in PMs to 200 of our members.

That was about 2 weeks ago, and I added it into the SFS database when it happened.  Unfortunately, the SMF forum does NOT have an option to delete all PMs sent by a member when you delete the account, only forum posts.  I went into the SQL database and did a Search & Replace to de-toxify the links and message.

Looking at that IP again, I only see 3 entries now.  There were a BUNCH more 2 weeks ago,
http://i47.tinypic.com/1zprtbl.jpg

Here's the message, so that they don't get a Google hit on the domain:
http://i47.tinypic.com/2sbrinb.jpg

Last edited by RFiend (2010-02-02 12:10 pm)

Offline

#11 2010-02-02 12:40 pm

CK9
Member
Registered: 2010-02-02
Posts: 1
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

Hi there.

We had that one ourselves not that long ago.  The username sent up a red flag with me instantly.  Lucky for us, the first person to get hit with the PM was on at the same time and sent out a warning to everyone through our shoutbox at the top of the forum.

Offline

#12 2010-02-07 3:15 pm

insektenfang
Member
From: UK
Registered: 2009-04-17
Posts: 392
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

OK... now I'm starting to feel paranoid/suspicious etc.

This one has now disappeared from the database for a second time -

188.72.225.209

testament440@mail.antivir-labs.com

trueLadyAdmin



hmm


insektenfang plants
carnivorous plant nursery

Offline

#13 2010-02-07 3:31 pm

pedigree
uıɐbɐ ʎɐqǝ ɯoɹɟ pɹɐoqʎǝʞ ɐ buıʎnq ɹǝʌǝu ɯ,ı
From: Londonderry
Registered: 2008-04-16
Posts: 4,445

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

Hmm, then someone is removing it via the removal page.  I might have to change that page to not remove that IP

edit : Ive just updated the removal script to allow for permanent bans, a guess what the first IP was smile

http://www.stopforumspam.com/api?ip=188.72.225.209

... now shows 130 hits

Offline

#14 2010-02-07 6:54 pm

insektenfang
Member
From: UK
Registered: 2009-04-17
Posts: 392
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

Thanks.

It does make one wonder just how many spammers we have as members here.


insektenfang plants
carnivorous plant nursery

Offline

#15 2010-02-07 7:32 pm

MysteryFCM
Member
From: Tyneside, UK
Registered: 2008-01-16
Posts: 605
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

I was actually going to blog about 188.72.225.209 earlier, but decided not to.

The reason? This silly little spambot, which FYI, is from a NetDirekt range (surprise surprise), decided it would be fun to register at the Malwarebytes forums, and spam via PM.

I didn't receive a copy of the spam (guess the spammer doesn't like me much sad), but one of my friends did, and it contained;

Dear, {USERNAME}!

A virus alert was noticed on your computer. 
We highly recommend you to check your computer and perform online virus check at our site immediately: http://security-tool2010.net/{USERNAME}
----------------------------------------------------
Forum Administration forums.malwarebytes.org.

You've already guessed the "Forum Administration ...." part of their PM is absolute rubbish (pat yourself on the back ....). I followed the URL to see what lovely malicious goodness I'd get, and the path it took was;

1. http://security-tool2010.net/online-scanner/
2. http://security-tool2010.net/online-scanner/pccoin/out.php
3. http://89.248.171.48/hitin.php?&affid=16210
4. http://89.248.171.48/index.php?affid=16210

With the payload being;

http://89.248.171.48/3_334d3f.php?affid=16210

The IP that provides the payload is on a well known Ecatel range (how nice, Ecatel and Netdirekt working together to infect you ....). Just some of the malicious domains this IP is known to have hosted includes;

protectyoursystemnowonline.com
yoursecuritytodayonline.com
createyoursecurityonline.com
commercialssecuritytoolstore.com
infosecuritysite.com
yoursecuritytodayblog.com
bestcommercialssecuritytool.com
mycommercialssecuritytool.com
commercialssecuritytools.com
createwesupport.com
yoursupportnow.com
commercialssecuritytooltoday.com
ursupporttoday.com
infosecuritytoday.com
ursecuritytoday.com
freeyoursecuritytoday.com
theyoursecuritytoday.com
createyoursecuritytoday.com
createyoursafety.com
imageinfosecurity.com
albuminfosecurity.com
censusinfosecurity.com
makeursecurity.com
freecreateyoursecurity.com
adsupporttool.com

Spammer is listed on 3 blacklists thus far;

http://temerc.com/Check_Spammers/?ip=188.72.225.209


Regards
Steven Burn
Ur I.T. Mate Group / hpHosts
it-mate.co.uk / hosts-file.net

Offline

#16 2010-02-09 3:10 pm

insektenfang
Member
From: UK
Registered: 2009-04-17
Posts: 392
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

pedigree wrote:

151 hits as of now, so I'd say SFS is spoiling their little game somewhat. wink


insektenfang plants
carnivorous plant nursery

Offline

#17 2010-03-02 3:07 pm

poultryexcuse
Member
Registered: 2009-09-08
Posts: 96

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

Guy's back.

Around 150 guest connections;

I happened to whois this IP; it's the same as the hostname(alone) displays on most of the rest.

http://ip-address-lookup-v4.com/lookup. … .102.63.60
http://www.stopforumspam.com/search.php?q=94.102.63.60

/hosted-by-dot-ecatel-dot-net

all different/bogus userstrings

all looking at/doing different things.

Offline

#18 2010-11-26 9:12 pm

ih8spam
Member
Registered: 2009-03-25
Posts: 266

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

Hate to resurrect an ancient thread, but LadyROOT is STILL at it ! LOL

The bot tried to log into my board today, even though it's account was deleted a looong time ago, and there is a fresh bunch of submissions to SFS today (put "LadyROOT" in the search box) .

so if you have been a member here for less than a year, read this thread, and ban any fake admin accounts on your forum ASAP .


"Two years from now, spam will be solved."
Bill Gates, founder of Microsoft, 2004

Offline

#19 2010-11-27 10:06 am

scottinaz
Member
From: Southern California
Registered: 2010-07-29
Posts: 74
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

ih8spam wrote:

Hate to resurrect an ancient thread, but LadyROOT is STILL at it ! LOL

The bot tried to log into my board today, even though it's account was deleted a looong time ago, and there is a fresh bunch of submissions to SFS today (put "LadyROOT" in the search box) .

so if you have been a member here for less than a year, read this thread, and ban any fake admin accounts on your forum ASAP .

Why does it show this person as from different countries ?  Proxy ?

Offline

#20 2010-11-27 11:53 am

insektenfang
Member
From: UK
Registered: 2009-04-17
Posts: 392
Website

Re: Netherlands Multiple UserAgents; "Lady Admin/LadyROOT" usernames

Botnet I imagine.


insektenfang plants
carnivorous plant nursery

Offline

Board footer

Powered by FluxBB