CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

archiveutility.com

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
chrisretusn

Private
Private
Premium Member

Joined: Sep 08, 2004
Posts: 41
Location: Philippines
Premium

PostPosted: Wed Apr 23, 2008 6:18 am    Post subject: archiveutility.com
Reply with quote

I used a rather old URL I had saved to go to IZSoftware to download IZArc and was redirected to what I suspect to be a malware distribution site.

redirected URL: hxxp://www.izsoft.dir.bg/


suspect URL: hxxp://archiveutility.com/

Yes I know current URL for IZSoftware.

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Wed Apr 23, 2008 6:29 am    Post subject:
Reply with quote

dir.bg appears to be a free hosting service, so it may be that the original owner dropped the "izsoft" uname and someone else picked it up.

on the surface, archiveutility.com appears to be a parked domain with lots of advertising.

did you have any specific reason to suspect malware?

by the way, I did not know the current url for izsoftware.
apparently it is
http://www.izarc.org/
although it can also be downloaded from download sites such as
http://www.snapfiles.com/publishers/izsoftware/index.html

Back to top
View users profile Send private message
chrisretusn

Private
Private
Premium Member

Joined: Sep 08, 2004
Posts: 41
Location: Philippines
Premium

PostPosted: Wed Apr 23, 2008 8:38 am    Post subject:
Reply with quote

brewt wrote:
dir.bg appears to be a free hosting service, so it may be that the original owner dropped the "izsoft" uname and someone else picked it up.
OK, make sense.

Quote:
on the surface, archiveutility.com appears to be a parked domain with lots of advertising.
Just read up on parked domain at Wikipedia. I was not aware that a parked domain could be used this way. Seems pretty dishonest.

Quote:
did you have any specific reason to suspect malware?
Only that the site redirected from what was IZSoftware, the old IZSoftware site (verified via Wayback Machine) did start to load, and then, abruptly redirected to archiveutily.com. Seems like a site like this is up to no good. Felt it better to report just incase.

Quote:
by the way, I did not know the current url for izsoftware.
apparently it is
http://www.izarc.org/
although it can also be downloaded from download sites such as
http://www.snapfiles.com/publishers/izsoftware/index.html

Thanks, actually I said I knew the current URL. Smile

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Wed Apr 23, 2008 3:16 pm    Post subject:
Reply with quote

chrisretusn wrote:
Thanks, actually I said I knew the current URL. :)
Right.
Although you knew the URL, I didn't, and I assumed that there might be others who also didn't know the URL.

The link is included as a courtesy to anyone who might stumble upon this thread and desire the official link.

Back to top
View users profile Send private message
chrisretusn

Private
Private
Premium Member

Joined: Sep 08, 2004
Posts: 41
Location: Philippines
Premium

PostPosted: Thu Apr 24, 2008 1:32 am    Post subject:
Reply with quote

Makes sense, should have thought of that myself, thanks. Smile

So you don't think there is any real problem with that site?

I does look like the site is in place to lead the unaware to many questionable scam sites to take their money and/or get their information.

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Thu Apr 24, 2008 6:22 am    Post subject:
Reply with quote

I wasn't able to find any scam sites in my cursory examination.

that widgetbucks site they link to looks like a waste of space on the internet, but I didn't see any links to outright fraudulent like phishing, malware, money mule, fake drugs, etc.

Overall, it looks like a site I would avoid, but possibly benign.

Did you find anything I missed?

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5869

MIRT Premium

PostPosted: Fri Apr 25, 2008 8:44 pm    Post subject:
Reply with quote

I couldn't find any malware either.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
chrisretusn

Private
Private
Premium Member

Joined: Sep 08, 2004
Posts: 41
Location: Philippines
Premium

PostPosted: Sat Apr 26, 2008 10:44 am    Post subject:
Reply with quote

brewt wrote:
I wasn't able to find any scam sites in my cursory examination.

that widgetbucks site they link to looks like a waste of space on the internet, but I didn't see any links to outright fraudulent like phishing, malware, money mule, fake drugs, etc.

Overall, it looks like a site I would avoid, but possibly benign.

Did you find anything I missed?

Do not find any specific malware. Lots of links going to questionable scam sites of the take your money for nothing type, but no malware.

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Sat Apr 26, 2008 4:36 pm    Post subject:
Reply with quote

chrisretusn wrote:
Lots of links going to questionable scam sites of the take your money for nothing type
such as?

Back to top
View users profile Send private message
chrisretusn

Private
Private
Premium Member

Joined: Sep 08, 2004
Posts: 41
Location: Philippines
Premium

PostPosted: Sun Apr 27, 2008 6:25 am    Post subject:
Reply with quote

brewt wrote:
chrisretusn wrote:
Lots of links going to questionable scam sites of the take your money for nothing type
such as?


Well, maybe I made a some assumptions, but very few links have any thing to do with archiving or lead to real archive utility sites. All most all lead to everything under the sun, except archives sites. I A lot of sites ask for name and/or email for "free" whatever. I suppose most referred sites are relatively benign. I would think if I supplied my email address to any of these sites, that would pretty much mean spam would not be far away. I overreacted I suppose, my apologies.

Here are a few possibilities I found.
hxxp://www.the-entrepreneur-club.com/
hxxp://www.online-bingo.net/

Not sure about this one.
hxxp://www.baddebtsecuredloans.co.uk/

Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Sun Apr 27, 2008 7:03 am    Post subject:
Reply with quote

chrisretusn wrote:
I suppose most referred sites are relatively benign. I would think if I supplied my email address to any of these sites, that would pretty much mean spam would not be far away. I overreacted I suppose, my apologies.
No apologies are necessary.

My goal in asking the question was to seek clarity.

I think we can agree that most of the linked sites are worthless, questionable, and possibly fraudulent.

Thanks for bringing this up.
I'm sure you aren't the first to have these questions.

Back to top
View users profile Send private message
chrisretusn

Private
Private
Premium Member

Joined: Sep 08, 2004
Posts: 41
Location: Philippines
Premium

PostPosted: Sun Apr 27, 2008 1:45 pm    Post subject:
Reply with quote

Thanks. You have been very helpful. If I suspect a possible malicious site I will continue to post. Better to have someone who deals in this daily take a look. I also learned a lot just browsing that site and the follow on links. I just don't see how anyone can fall pray to this sort of think, sites like this really seem like a waist of space.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer