Help and Support
Ask a question, report a problem, request a feature...
<<  Back To Forum

Heads up: Site known for malware linked to torrent tracker site

by Guest on 2016/02/28 07:05:38 PM    
Something new for me.
Over the last few days Norton's AV has been blocking a steady stream of connection attempts from a server in Portugal, reportedly related to some sort of cryptolocker ransomware scheme.

See screenshot here:  http://i.imgur.com/LcMi1vi.png

The 'attacks' are coming from a convoluted URL: sso.anbtr.com/domain/www.alterati.net - notice the double domain names.

sso.anbtr.com and anbtr.com resolve to:
195.22.28.222 - server hosted in Portugal, blacklisted by malwaredomains.com as of 1 Feb 2016

As to the anbtr.com server, many security services have recently added it to their blacklists.
For examples see: http://tinyurl.com/zpb57qp

The same reporting site gives alterati.net a clean bill of health.

www.alterati.net and alterati.net resolve to:
195.22.26.248 - iow, same B class subnet as anbtr.com

Alterati.net seems to provide tracker and RSS services related to torrents. Since I added its IP to my block list, over 100 tracker and RSS connection attempts to Tixati.exe have been intercepted and blocked. I am assuming normal traffic. But could I be wrong?

Recall the block report by Norton's indicated the 'attacks' were targeting my torrent client, Tixati.exe

Since whoever is behind this knows they are dealing with torrent clients, do they know of some potentially exploitable weaknesses in any particular client?

Has someone at or using anbtr.com compromised servers at alterati.net? Are they somehow learning torrent tracker user's IPs then hitting them from anbtr.com with port probes or other connection attempts?

Or could alterati.net be in cohoots in some nefarious cryptolocker ransomware scheme?

All I have is questions at this point, but given the serious nature of cryptoLocker ransomware attacks, I am concerned.
by ZarkBit on 2016/02/29 02:10:32 PM    
huh, FYI sso.anbtr.com is a browser hijacker, not a cryptolocker, might wanna do some scans on your pc to make sure youre clean.
by Bugmagnet on 2016/04/01 03:41:37 PM    
It maybe a browser hijacker but it is also implicated in planting a trojan related to some cryptolocker attack.  See the first link I posted for the screenshot which clearly shows this..

    i.imgur.com/LcMi1vi.png
by ZarkBit on 2016/04/01 04:24:42 PM    
Many virus are mislabeled, until a deep analyses is made, only then the correct name is given, so as far as I know that is a browser hijacker.




This web site is powered by Super Simple Server