User Support & Resources Account Problems | Questions | Suggestions

clicksnetworks.net? blackhole toolkit on ls1tech?

Thread Tools
 
Search this Thread
 
Old Jan 16, 2012 | 09:07 AM
  #1  
DarkFox118's Avatar
Thread Starter
TECH Enthusiast
iTrader: (7)
 
Joined: Jan 2011
Posts: 590
Likes: 2
From: Longbeach, CA
Default clicksnetworks.net? blackhole toolkit on ls1tech?

Good morning guys,

I'm sitting here browsing the forums and my symantec keeps popping up every time I make a post or view a thread saying it's blocking traffic because of a "blackhole" exploit.

then I get a constant timeout of "clicksnetworks.net" and the forum page won't finish loading until I hit the X in the browser.

never had this issue before, seems to be just the site today.

even as I type this the browser is saying "connecting to clicksnetworks.net" in the bottom right (firefox.)

I did a google of this site and nothing came up.

ip address I have is 146.185.254.34 and this is the addy that endpoint is blocking.

I'm on here all the time, never had this issue before, and didn't turn up anything on the search.

Eventually the clicksnetwork request stops, be it that it responds or that it times out, I'm not sure.

Here's my logs:

[SID: 24215] Web Attack: Blackhole Toolkit Website 12 detected.
Traffic has been blocked from this application: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Traffic from IP address 146.185.254.34 is blocked from 1/16/2012 9:56:26 AM to 1/16/2012 10:06:26 AM.

False alarm I'm sure.. but why just now?

research on this toolkit thing doesn't sound very reassuring.

http://www.symantec.com/connect/blogs/blackhole-theory
Reply
Old Jan 16, 2012 | 09:33 AM
  #2  
DarkFox118's Avatar
Thread Starter
TECH Enthusiast
iTrader: (7)
 
Joined: Jan 2011
Posts: 590
Likes: 2
From: Longbeach, CA
Default

confirmed this is not just my computer here at the office. Tried from home, received same warning. This was not occuring last night.

home log:

[SID: 24215] Web Attack: Blackhole Toolkit Website 12 detected.
Traffic has been blocked from this application: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Traffic from IP address 146.185.254.34 is blocked from 11/27/2011 5:26:41 PM to 11/27/2011 5:36:41 PM.

Same parameters in both cases. clicksnetworks.net is the name resolution.

the thing that has me most concerned on symantec's site:

Originally Posted by symantec's site
3) passw.plug – It will hook the export table of a number of WININET.dll and USER32.dll functions and will log every username/password combination that is typed, as well as any URLs visited.
Man I hope I'm wrong about this. I'm not trying to create panic, just resolve this ASAP. Just tried a 3rd computer,fresh install plus AV, same warning, this time with IE9.

Last edited by DarkFox118; Jan 16, 2012 at 09:43 AM.
Reply
Old Jan 16, 2012 | 09:35 AM
  #3  
99FormulaM6's Avatar
TECH Junkie
20 Year Member
iTrader: (21)
 
Joined: Aug 2004
Posts: 3,161
Likes: 0
From: Virginia Beach, VA
Default Blackhole toolkit Website 12

Norton is blocking this every time I come to LS1tech. Address is: clicksnetworks.net

Any idea what it is? I googled it and someone on CF posted the same thing.. Kinda weird both sites are IB sites. I don't get the warning when I go to other websites either. I have only gotten it here and on CF, I haven't been on the PC enough this morning to go to a bunch of other sites though.


Here is the CF link:
http://forums.corvetteforum.com/c6-c...rus-alert.html
Reply
Old Jan 16, 2012 | 09:37 AM
  #4  
99FormulaM6's Avatar
TECH Junkie
20 Year Member
iTrader: (21)
 
Joined: Aug 2004
Posts: 3,161
Likes: 0
From: Virginia Beach, VA
Default

I just went to the list of IB sites:

http://www.internetbrands.com/our-brands/automotive/

and started clicking on random ones, and it is coming from alot of them, but not all. I wonder if IB was targeted or something...
Reply
Old Jan 16, 2012 | 09:39 AM
  #5  
MeentSS02's Avatar
Kleeborp the Moderator™
20 Year Member
iTrader: (11)
 
Joined: Mar 2004
Posts: 10,316
Likes: 6
From: Dayton, OH
Default

I'm getting the same thing.
Reply
Old Jan 16, 2012 | 09:41 AM
  #6  
99FormulaM6's Avatar
TECH Junkie
20 Year Member
iTrader: (21)
 
Joined: Aug 2004
Posts: 3,161
Likes: 0
From: Virginia Beach, VA
Default

Info about it:
http://www.symantec.com/security_res...jsp?asid=24215

A thread on Norton:

http://community.norton.com/t5/Norto...ck/td-p/461114

Hi mml_1980,



That information is helpful. A Web Attack indicates that you are encountering a driveby download attempt. Since you indicate that this is only happening when you access your homepage, then this is likely resulting from a compromised website or poisoned ads, as you say, rather than from malware on your system.



If you are getting this without going to the Yahoo! site, either manually or automatically, there may be an issue. If just getting online causes these alerts, then something may be connecting out.
Reply
Old Jan 16, 2012 | 09:45 AM
  #7  
MeentSS02's Avatar
Kleeborp the Moderator™
20 Year Member
iTrader: (11)
 
Joined: Mar 2004
Posts: 10,316
Likes: 6
From: Dayton, OH
Default

I notified someone at IB about this...hopefully they can resolve this before it causes someone a problem.
Reply
Old Jan 16, 2012 | 09:50 AM
  #8  
MeentSS02's Avatar
Kleeborp the Moderator™
20 Year Member
iTrader: (11)
 
Joined: Mar 2004
Posts: 10,316
Likes: 6
From: Dayton, OH
Default

I'm getting the same thing.
Reply
Old Jan 16, 2012 | 09:52 AM
  #9  
01BlackCamaroSS's Avatar
TECH Regular
iTrader: (1)
 
Joined: Jan 2006
Posts: 411
Likes: 0
From: Maryland
Default

Same here
Reply
Old Jan 16, 2012 | 10:35 AM
  #10  
1point3liter's Avatar
TECH Regular
 
Joined: May 2003
Posts: 404
Likes: 0
From: Jacksonville, FL
Default

i believe it just infected a friend of mine's machine.
Reply
Old Jan 16, 2012 | 10:36 AM
  #11  
1point3liter's Avatar
TECH Regular
 
Joined: May 2003
Posts: 404
Likes: 0
From: Jacksonville, FL
Default

Btw, i also saw a couple warnings from Symantec endpoint.
Reply
Old Jan 16, 2012 | 10:45 AM
  #12  
arock24's Avatar
Launching!
iTrader: (4)
 
Joined: Sep 2011
Posts: 251
Likes: 0
From: PHX
Default

me dos

Has this been addressed?
Reply
Old Jan 16, 2012 | 10:48 AM
  #13  
BIGDRAGON's Avatar
Launching!
iTrader: (9)
 
Joined: Aug 2011
Posts: 202
Likes: 1
From: Mansfield,Texas
Default

Me too.
Reply
Old Jan 16, 2012 | 10:48 AM
  #14  
DarkFox118's Avatar
Thread Starter
TECH Enthusiast
iTrader: (7)
 
Joined: Jan 2011
Posts: 590
Likes: 2
From: Longbeach, CA
Default

I reported my own post to admins, no contact from them yet.

I'm more worried about people who are unprotected that browse the site.

(you should ALWAYS use protection. )
Reply
Old Jan 16, 2012 | 11:00 AM
  #15  
J-Rod's Avatar
6600 rpm clutch dump of death Administrator
20 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Dec 2001
Posts: 4,983
Likes: 13
From: Texas
Default

I'm checking into it. My guess is someone bought a banner and is directing it to a "bad" site. That happens from time to time.
Reply
Old Jan 16, 2012 | 11:04 AM
  #16  
Hi-Po's Avatar
TECH Enthusiast
iTrader: (4)
 
Joined: Nov 2005
Posts: 712
Likes: 0
From: Florida
Default

hitnetsystem(dot)com is what Kaspersky is telling me.
Reply
Old Jan 16, 2012 | 11:09 AM
  #17  
DarkFox118's Avatar
Thread Starter
TECH Enthusiast
iTrader: (7)
 
Joined: Jan 2011
Posts: 590
Likes: 2
From: Longbeach, CA
Default

Originally Posted by J-Rod
I'm checking into it. My guess is someone bought a banner and is directing it to a "bad" site. That happens from time to time.

possible. This visit I didn't receive the error.

I have adblock on my browser (sorry!) so I'm not seeing most of the banners, but that doesn't mean the code isn't being loaded apparently. It was on every single page for a while tho.
Reply
Old Jan 16, 2012 | 11:25 AM
  #18  
J-Rod's Avatar
6600 rpm clutch dump of death Administrator
20 Year Member
Photogenic
Photoriffic
Shutterbug
 
Joined: Dec 2001
Posts: 4,983
Likes: 13
From: Texas
Default

I haven't gotten any warnings on my session, but as i said, I am looking into it. I have also let IB know so they can have their guys look into it as well. Posted in here if you see anything else.
Reply
Old Jan 16, 2012 | 11:27 AM
  #19  
speedtigger's Avatar
Old School Heavy
15 Year Member
Photogenic
Liked
Loved
iTrader: (16)
 
Joined: May 2010
Posts: 8,835
Likes: 84
From: Florida
Default

I had the same thing happen. I reported it.
Reply
Old Jan 16, 2012 | 11:32 AM
  #20  
DarkFox118's Avatar
Thread Starter
TECH Enthusiast
iTrader: (7)
 
Joined: Jan 2011
Posts: 590
Likes: 2
From: Longbeach, CA
Default

not seeing it anymore on my side.

Last event was logged here:

Traffic from IP address 146.185.254.34 is blocked from 1/16/2012 11:47:21 AM to 1/16/2012 11:57:21 AM.

current time is 12:30PM, and I've been on here tooling around with PMs and following up threads (slow work day..) for the last few minutes, so whatever it is, I think ya musta got it. Now the fun part is of course finding out what it was to begin with, and how it got here.

I don't run an operation anywhere near as sophisticated as this site, but I do work in IT, so I know how troublesome this kinda thing can be, especially if users data is compromised. I'm STILL chasing demons from a user who fell for a phishing scam 2 months ago.
Reply



All times are GMT -5. The time now is 05:17 PM.