History - A warning from Google!

David Brooks <[email protected]> Thu, 2 Nov 2023 14:29:36 +0000
Newsgroups alt.computer.security,alt.computer.workshop
Organization blocknews - www.blocknews.net
Message-ID <[email protected]>
On 15/05/2009 18:07, BoaterDave wrote:

> Hi :)
> 
> I went to this URL
> http://www.linkedin.com/ppl/webprofile?action=vmi&id=1317524&pvs=pp&authToken=jNAa&authType=name&trk=ppro_viewmore&lnk=vw_pprofile
> where there is the LinkedIn profile for Gregory Gooden.  (The owner of
> Annex.com)
> 
> Under 'Websites' I selected 'My Blog' and went to this URL
> http://www.luftmensch.com/    I then clicked on RanZ(Blog) ..........
> 
> And received this:-    "Warning: Visiting this site may harm your
> computer"  (White font on a bright red banner). That was followed
> by .........
> 
> "The website you are visiting appears to contain malware. Malware is
> malicious software that may harm your computer or otherwise operate
> without your consent. Your computer can be infected just by browsing
> to a site with malware, without any further action on your part.
> 
> For detailed information about problems found on this site, visit
> Google Safe Browsing diagnostic page for 74.222.134.170"
> 
> The IP number was a link which, when followed, provided this
> information:-
> 
> "What is the current listing status for 74.222.134.0?
> This site is not currently listed as suspicious.
> 
> Part of this site was listed for suspicious activity 1 time(s) over
> the past 90 days.
> 
> What happened when Google visited this site?
> Of the 13 pages we tested on the site over the past 90 days, 0 page(s)
> resulted in malicious software being downloaded and installed without
> user consent. The last time Google visited this site was on
> 2009-05-14, and the last time suspicious content was found on this
> site was on 2009-05-14.
> Malicious software includes 8 trojan(s), 6 scripting exploit(s), 4
> exploit(s).
> 
> This site was hosted on 1 network(s) including AS35908 (VPLSNET).
> 
> Has this site acted as an intermediary resulting in further
> distribution of malware?
> Over the past 90 days, 74.222.134.0 did not appear to function as an
> intermediary for the infection of any sites.
> 
> Has this site hosted malware?
> Yes, this site has hosted malicious software over the past 90 days. It
> infected 6 domain(s), including blonging.com/, myinvestorblog.com/,
> dollarandsense.net/.
> 
> Next steps:
> Return to the previous page.
> If you are the owner of this web site, you can request a review of
> your site using Google Webmaster Tools. More information about the
> review process is available in Google's Webmaster Help Center.
> 
> **************************
> 
> There was a "Go Back" and an "Ignore  warning" button. Selecting the
> latter, I ended up here  http://www.luftmensch.com/wordpress/
> 
> It seems a great site to own - you might even notice that there is a
> comment which I left there last July with regard to "A day at the
> zoo"!
> 
> *** Googling 74.222.134.170 gives some interesting results! ***
> 
>  From what I can gather with my limited knowledge, 74.222.134.170 is
> located in California (http://www.geoiptool.com/en/?IP=74.222.134.170)
> 
> I'm left wondering who might have wished to infect Mr Gooden's Blog
> pages ...... and if the same folk may have 'got at' the Annexcafe
> newsgroups too!
> 
> --
> Dave