MacHouse video tutorials for Mac search engine optimization Spam database Web Hosting providers Web Hosting review web hosting providers MacHouse Help

September 25, 2008

Multiple Porn-Attacks on Moodle-Installed Websites, Leading Internet Users to Fake Porn Website at HOT-PORNTUBE-08.COM - Part 2

Filed under: Internet security — Administrator @ 1:03 pm
Posted about 1 years and 11 months ago

anti spam






TOKYO (MacHouse) - As we reported earlier, as many as 72 websites that have a free open-source course management system package called Moodle have been exploited with spam profiles, which lead Internet users to a fake porn website. Many spam-exploited websites are those of academic institutions.





Moodle porn spam exploitation
Screenshot 01 - Source: upd.edu.ph
  Moodle porn spam exploitation
Screenshot 02 - Source: MacHouse Domain Lookup
  Moodle porn spam exploitation
Screenshot 03 - Source: HiVelocity Hosting






Clicking on any of the sexually-explicit images at a Moodle profile like the one shown in Screenshot 01 forwards one to a fake porn website hosted at the domain of hot-porntube-08.com. This is where you will be forced to download a suspicious file titled xcodec.143.exe, zcodec.1036.exe or another.

So what do we know know about the fake porn website hosted at the domain of hot-porntube-08.com? Looking at its domain registration, there is little information that we can collect. It appears that the domain was registered in September 20. (See Screenshot 02.) So it’s relatively new. In the meantime, we know where this fake porn website is possibly hosted. It’s probably hosted in Tampa, Florida. We mentioned the name of one hosting company located in Tampa back in August, right? It’s NOC4Hosts or HiVelocity Hosting. (Screenshot 03 shows the index page of HiVelocity Hosting’s website.) They were the host of a fake PornTube website found at the domain of tube-viewer.com.

Likewise, there is little information to collect on the domain of softportalforfun08.net. This is the domain associated the website distributing suspicious files including xcodec.141 and others. The domain was registered in September 25. (See Screenshot 04.) So it’s quite new. And the website hosted at this domain also appears to be harbored by HiVelocity Hosting.





Moodle porn spam exploitation
Screenshot 04 - Source: MacHouse Domain Lookup
  Moodle porn spam exploitation
Screenshot 05 - Source: MacHouse Domain Lookup
  Moodle porn spam exploitation
Screenshot 06 - Source: netdirekt.de






There is one more domain. The domain of superkri.info is used to redirect Internet users to the fake porn website at hot-porntube-08.com. Screenshot 05 shows the domain registration of superkri.info. It looks like the domain was registered in June, 2008. So it’s not totally new. And the address is in Tashkent, Uzbekistan, which draws some suspicion on credibility. Anyway, there may be a website associated with this domain since Internet users are redirected to the porn website at hot-porntube-08.com. It appears that a German web hosting company knows something about a redirection website associated with superkri.info. netdirekt is behind many malicious websites we have found this year. (Screenshot 06 shows the index page of netdirekt’s website.) And a website at the domain of superkri.info also appears to be hosted by this German company.






Click on the button to watch a documentation video. VTC
Click on the button to watch more documentation videos. VTC






References:

Multiple Porn-Attacks on Moodle-Installed Websites, Leading Internet Users to Fake Porn Website at HOT-PORNTUBE-08.COM - Part 1
Singapore’s Ngree Ann Polytechnic’s Website Exploited and Used As Redirection Point to Send Internet Users to Fake PornTube Website
A Large Chain of Pharmacy Exploitation Affecting Dozens of University Websites Through Open-Source Script
Pharmacy Spam Exploitation at St. Louis University Medical School Again…





********** ********** ********** ********** ********** ********** ********** **********

MacHouse is not funded by tax payers' money. We have limited resources. We also need time to sleep and eat just as others. So we will not act as the International police to contact all victims of website abuse. All you have to do is to subscribe to spam messages and spam posts. If we can, why don't you?







Leave a Reply


You are prohibited from posting comments merely to advertise your website. Please read Rules and About This Blog at the top menu bar for more information.

Because of spam-comment criminals, we are forced to manually moderate every comment that you may post. Your comment will appear only after we review and then approve it. It will take us several hours at most to review it.

Please note that all one-sentence comments will be automatically rejected as an anti-spam measure.

Subscribe without commenting