Blog for hpHosts, and whatever else I feel like writing about ....

Thursday, 14 October 2010

SurfTown: Yet more compromised sites

A friend alerted me, after reading my blog, to a plethora of other sites on SurfTown IP space he'd found, that were also carrying malicious code.

SurfTown did get back to me after my last blog, telling me it had been cleaned up but alas - it hadn't. A quick check showed the infection was very much still there, and indeed, a quick check a second ago, shows it's still there as of 15-10-2010 03:03 (GMT London).

It would seem, just like HostingDiscounter (a Netherlands based IP that had a plethora of sites compromised recently), SurfTown is having major problems with compromised sites on their network. Until this is resolved, I'd strongly advise caution if going to ANY site on their network.

Some of the sites I've checked this morning do indeed appear to have been cleaned up, but alot haven't.

The redirects have been seen going through the following on port 11066;

IPPTRASNCountry
112.200.146.142112.200.146.142.pldt.net.9299PH
112.202.3.206112.202.3.206.pldt.net.9299PH
115.117.114.59-10199IN
115.118.212.164115.118.212.164.static-delhi.vsnl.net.in.10199IN
115.118.212.164115.118.212.164.static-delhi.vsnl.net.in.10199IN
115.43.120.37host-37.120-43-115.dynamic.totalbb.net.tw.9416TW
115.43.120.37host-37.120-43-115.dynamic.totalbb.net.tw.9416TW
117.195.5.121-9829IN
117.195.5.121-9829IN
120.138.120.8585-120-138-120.mysipl.com.45194IN
120.138.120.8585-120-138-120.mysipl.com.45194IN
123.203.153.82123203153082.ctinets.com.9269HK
123.203.153.82123203153082.ctinets.com.9269HK
123.203.153.82123203153082.ctinets.com.9269HK
123.237.110.13-17803IN
123.237.110.13-17803IN
123.237.110.13-17803IN
173.25.85.232173-25-85-232.client.mchsi.com.6478US
173.25.85.232173-25-85-232.client.mchsi.com.6478US
173.29.92.16173-29-92-16.client.mchsi.com.6478US
183.82.166.185-55577IN
188.112.198.85-49291RU
188.112.198.85-49291RU
189.121.14.247bd790ef7.virtua.com.br.28573BR
200.93.51.185200.93.51-185.dyn.dsl.cantv.net.8048VE
201.80.111.147c9506f93.virtua.com.br.28573BR
201.87.47.240-19182BR
207.161.169.211wnpgmb01dc6-169-211.dynamic.mts.net.15290CA
212.220.95.180-6828RU
24.140.170.239cable-170-239.sssnet.com.12097US
24.181.122.5624-181-122-56.dhcp.leds.al.charter.com.20115US
24.181.122.5624-181-122-56.dhcp.leds.al.charter.com.20115US
24.191.39.250ool-18bf27fa.dyn.optonline.net.6128US
58.9.136.89ppp-58-9-136-89.revip2.asianet.co.th.17552TH
58.9.136.89ppp-58-9-136-89.revip2.asianet.co.th.17552TH
59.166.91.16259-166-91-162.rev.home.ne.jp.9824JP
64.56.253.253dsl-64-56-253-253.tor.primus.ca.6407CA
64.56.253.253dsl-64-56-253-253.tor.primus.ca.6407CA
65.188.144.128cpe-065-188-144-128.triad.res.rr.com.11426US
66.177.151.191c-66-177-151-191.hsd1.fl.comcast.net.33489US
66.177.153.116c-66-177-153-116.hsd1.fl.comcast.net.33489US
66.177.153.116c-66-177-153-116.hsd1.fl.comcast.net.33489US
66.177.153.116c-66-177-153-116.hsd1.fl.comcast.net.33489US
66.25.108.7cs6625108-7.bham.res.rr.com.10994US
67.248.48.45cpe-67-248-48-45.nycap.res.rr.com.11351US
67.248.48.45cpe-67-248-48-45.nycap.res.rr.com.11351US
67.81.138.31ool-43518a1f.dyn.optonline.net.6128US
70.75.77.178S0106000c7686e0b4.cg.shawcable.net.6327CA
71.229.172.69c-71-229-172-69.hsd1.co.comcast.net.33652US
75.158.23.218d75-158-23-218.abhsia.telus.net.852CA
75.87.91.99cpe-75-87-91-99.kc.res.rr.com.11955US
76.189.93.227cpe-76-189-93-227.neo.res.rr.com.10796US
76.26.94.109c-76-26-94-109.hsd1.wv.comcast.net.7016US
78.15.169.96dynamic-adsl-78-15-169-96.clienti.tiscali.it.8612IT
78.43.245.52HSI-KBW-078-043-245-052.hsi4.kabel-badenwuerttemberg.de.29562DE
78.88.158.228078088158228.tczew.vectranet.pl.29314PL
81.198.148.252-12578LV
82.230.217.23-12322FR
82.232.214.156mrc45-1-82-232-214-156.fbx.proxad.net.12322FR
83.254.68.200c83-254-68-200.bredband.comhem.se.39651SE
83.82.88.173535258AD.cm-6-3b.dynamic.ziggo.nl.9143NL
83.82.88.173535258AD.cm-6-3b.dynamic.ziggo.nl.9143NL
84.90.101.23co1-84-90-101-23.netvisao.pt.13156PT
85.225.222.170c-aadee155.360-1-64736c11.cust.bredbandsbolaget.se.2119SE
86.0.138.150cpc1-pete8-0-0-cust661.4-4.cable.virginmedia.com.5089GB
87.12.200.171host171-200-static.12-87-b.business.telecomitalia.it.3269IT
87.251.137.82-39792RU
88.147.9.228-29096BE
88.147.9.228-29096BE
88.23.87.165165.Red-88-23-87.staticIP.rima-tde.net.3352ES
88.23.87.165165.Red-88-23-87.staticIP.rima-tde.net.3352ES
89.132.11.7adsl-89-132-11-7.monradsl.monornet.hu.6830HU
89.132.11.7adsl-89-132-11-7.monradsl.monornet.hu.6830HU
89.176.43.147ip-89-176-43-147.net.upcbroadband.cz.6830CZ
89.228.25.34host-89-228-25-34.zamosc.mm.pl.21021PL
89.29.223.1389.29.223.13.elda.cableworld.es.3339ES
89.29.223.1389.29.223.13.elda.cableworld.es.3339ES
89.29.223.1389.29.223.13.elda.cableworld.es.3339ES
89.29.223.1389.29.223.13.elda.cableworld.es.3339ES
90.34.46.213AAmiens-156-1-71-213.w90-34.abo.wanadoo.fr.3215FR
90.34.46.213AAmiens-156-1-71-213.w90-34.abo.wanadoo.fr.3215FR
91.117.111.107107.111.117.91.dynamic.mundo-r.com.12334ES
91.139.232.11-28898BG
92.126.35.159-41440RU
93.115.252.101-34060RO
93.115.252.101-34060RO
94.181.61.160net61.181.94-160.chel.ertelecom.ru.41661RU
94.181.61.160net61.181.94-160.chel.ertelecom.ru.41661RU
94.181.61.160net61.181.94-160.chel.ertelecom.ru.41661RU
98.226.109.141c-98-226-109-141.hsd1.in.comcast.net.33491US
98.248.200.221c-98-248-200-221.hsd1.ca.comcast.net.33651US
98.250.233.52c-98-250-233-52.hsd1.mi.comcast.net.33668US

No comments: