clicksnetworks.net? blackhole toolkit on ls1tech?
I'm sitting here browsing the forums and my symantec keeps popping up every time I make a post or view a thread saying it's blocking traffic because of a "blackhole" exploit.
then I get a constant timeout of "clicksnetworks.net" and the forum page won't finish loading until I hit the X in the browser.
never had this issue before, seems to be just the site today.
even as I type this the browser is saying "connecting to clicksnetworks.net" in the bottom right (firefox.)
I did a google of this site and nothing came up.
ip address I have is 146.185.254.34 and this is the addy that endpoint is blocking.
I'm on here all the time, never had this issue before, and didn't turn up anything on the search.
Eventually the clicksnetwork request stops, be it that it responds or that it times out, I'm not sure.
Here's my logs:
[SID: 24215] Web Attack: Blackhole Toolkit Website 12 detected.
Traffic has been blocked from this application: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Traffic from IP address 146.185.254.34 is blocked from 1/16/2012 9:56:26 AM to 1/16/2012 10:06:26 AM.
False alarm I'm sure.. but why just now?
research on this toolkit thing doesn't sound very reassuring.
http://www.symantec.com/connect/blogs/blackhole-theory
home log:
[SID: 24215] Web Attack: Blackhole Toolkit Website 12 detected.
Traffic has been blocked from this application: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Traffic from IP address 146.185.254.34 is blocked from 11/27/2011 5:26:41 PM to 11/27/2011 5:36:41 PM.
Same parameters in both cases. clicksnetworks.net is the name resolution.
the thing that has me most concerned on symantec's site:
Last edited by DarkFox118; Jan 16, 2012 at 09:43 AM.
Any idea what it is? I googled it and someone on CF posted the same thing.. Kinda weird both sites are IB sites. I don't get the warning when I go to other websites either. I have only gotten it here and on CF, I haven't been on the PC enough this morning to go to a bunch of other sites though.
Here is the CF link:
http://forums.corvetteforum.com/c6-c...rus-alert.html
http://www.internetbrands.com/our-brands/automotive/
and started clicking on random ones, and it is coming from alot of them, but not all. I wonder if IB was targeted or something...
http://www.symantec.com/security_res...jsp?asid=24215
A thread on Norton:
http://community.norton.com/t5/Norto...ck/td-p/461114
That information is helpful. A Web Attack indicates that you are encountering a driveby download attempt. Since you indicate that this is only happening when you access your homepage, then this is likely resulting from a compromised website or poisoned ads, as you say, rather than from malware on your system.
If you are getting this without going to the Yahoo! site, either manually or automatically, there may be an issue. If just getting online causes these alerts, then something may be connecting out.
Trending Topics
The Best V8 Stories One Small Block at Time
I'm more worried about people who are unprotected that browse the site.
(you should ALWAYS use protection.
possible. This visit I didn't receive the error.
I have adblock on my browser (sorry!) so I'm not seeing most of the banners, but that doesn't mean the code isn't being loaded apparently. It was on every single page for a while tho.
Last event was logged here:
Traffic from IP address 146.185.254.34 is blocked from 1/16/2012 11:47:21 AM to 1/16/2012 11:57:21 AM.
current time is 12:30PM, and I've been on here tooling around with PMs and following up threads (slow work day..) for the last few minutes, so whatever it is, I think ya musta got it. Now the fun part is of course finding out what it was to begin with, and how it got here.
I don't run an operation anywhere near as sophisticated as this site, but I do work in IT, so I know how troublesome this kinda thing can be, especially if users data is compromised. I'm STILL chasing demons from a user who fell for a phishing scam 2 months ago.








