Malicious Toolkit Website

The #1 community for Gun Owners in Indiana

Member Benefits:

  • Fewer Ads!
  • Discuss all aspects of firearm ownership
  • Discuss anti-gun legislation
  • Buy, sell, and trade in the classified section
  • Chat with Local gun shops, ranges, trainers & other businesses
  • Discover free outdoor shooting areas
  • View up to date on firearm-related events
  • Share photos & video with other members
  • ...and so much more!
  • indymike

    Marksman
    Rating - 100%
    32   0   0
    Jun 29, 2009
    211
    18
    Just a heads up that one of the ads on this site is repeatedly attempting a java exploit. My Symantec Endpoint Ent has blocked and logged this each time I've visited over the last 3 days. Here's some info, hope it helps.

    [SID: 24609] Web Attack: Malicious Toolkit Website 12 attack blocked.
    Remote Host: TCP 72.51.47.66 80
    Malicious Toolkit URL: 72.51.47.66/adsolution70x12/metrics.php?t=98&dr=(string-removed)
     

    AnthonyG

    Gentard
    Rating - 100%
    2   0   0
    Jan 21, 2010
    242
    18
    Ann Arbor
    I had removed the ads once, but Fen wanted them back, the advertiser has been notified on the issue & reports that their ad customers verified that their sites are verified as malware free, unfortunately their is nothing i can do, it can also be a false positive on your malware program because the string looks like another known malware string...
     

    IndyDave1776

    Grandmaster
    Emeritus
    Rating - 100%
    12   0   0
    Jan 12, 2012
    27,286
    113
    Malicious Toolkit Website? I am disappointed. I was expecting to be directed to an internet vendor of specialized tools for the deletion of miscreants, not malware.
     

    william

    Sharpshooter
    Rating - 100%
    7   0   0
    Jan 3, 2011
    636
    18
    Fishers
    Getting the same thing over and over...Malicious tool kit, and some Trojan warning. Happens every time I open INGO. My Norton goes nuts
     

    Jimbovia

    Marksman
    Rating - 100%
    4   0   0
    May 1, 2010
    166
    18
    Plainfield
    Same thing

    Here you go.

    attachment.php
     

    AnthonyG

    Gentard
    Rating - 100%
    2   0   0
    Jan 21, 2010
    242
    18
    Ann Arbor
    Read post #2....

    I've tried to remove the footer ads, did it once, but was told to put them back up.

    If you can post up a screen shot of what ads are on the page in the footer when you get it, post it.

    @Jimbovia, my Norton does NOT trigger an alert, no idea why yours is.
     

    Jimbovia

    Marksman
    Rating - 100%
    4   0   0
    May 1, 2010
    166
    18
    Plainfield
    @AnthonyG: No worries. I was only trying to help with the issue identified by multiple users.

    I've blocked the IP from loading, so I'm fine.

    Fix it, don't fix it, whatever loads your cartridge. :dunno:

    Regards,
    Jim


    Read post #2....

    I've tried to remove the footer ads, did it once, but was told to put them back up.

    If you can post up a screen shot of what ads are on the page in the footer when you get it, post it.

    @Jimbovia, my Norton does NOT trigger an alert, no idea why yours is.
     

    Cameramonkey

    www.thechosen.tv
    Staff member
    Moderator
    Site Supporter
    Rating - 100%
    35   0   0
    May 12, 2013
    32,163
    77
    Camby area
    Read post #2....


    @Jimbovia, my Norton does NOT trigger an alert, no idea why yours is.

    Its probably because that server hasnt fed you the "right" ad yet. AKA just because you didnt get sick from eating at a chinese buffet doesnt mean the 5 other people with you didnt. LOL
     

    AnthonyG

    Gentard
    Rating - 100%
    2   0   0
    Jan 21, 2010
    242
    18
    Ann Arbor
    Its probably because that server hasnt fed you the "right" ad yet. AKA just because you didnt get sick from eating at a chinese buffet doesnt mean the 5 other people with you didnt. LOL

    Ive never received the attack alert from Norton since this has started 2 months ago, so yes, i would have seen all the ads served.
     

    Cameramonkey

    www.thechosen.tv
    Staff member
    Moderator
    Site Supporter
    Rating - 100%
    35   0   0
    May 12, 2013
    32,163
    77
    Camby area
    A false positive isn't likely, but somewhat feasible. If your av software is still throwing alerts make sure the definitions are current.

    If they are current and you still think the ads are malicious, look into an ad blocker. I doubt the site will miss the clicks of two or three users.

    Oh, and depending on what cookies are on various users' PCs could also affect who gets/doesnt get the alert. it could be somewhat targeted ads and those with Norton that DONT get the alerts visit sites that are of a different nature than those that do, causing some to see it and others not to.
     
    Last edited:

    moosebag

    Sharpshooter
    Rating - 0%
    0   0   0
    Jan 3, 2012
    420
    18
    Indiana
    It appears that the problem has been cleaned up as the ad at the bottom (footer) of the pages was null for a few hours. Now I am not receiving the virus notices any longer. Whatever was causing it appears to have subsided and it looks like the footer ad is now new. :yesway:
     

    william

    Sharpshooter
    Rating - 100%
    7   0   0
    Jan 3, 2011
    636
    18
    Fishers
    Read post #2 moosebag.

    Post #2 was two weeks ago...Obviously it didn't fix it. Just happened to me again, and it seems it's happening to others too. Maybe it's time to talk to Fenway again. I understand it's not your fault, but you're the one posting here so I'm complaining to you.
     

    Cameramonkey

    www.thechosen.tv
    Staff member
    Moderator
    Site Supporter
    Rating - 100%
    35   0   0
    May 12, 2013
    32,163
    77
    Camby area
    Maybe its time for Fenway to look at a different ad source? if you regularly get food poisoning when you eat out, you'd switch restaurants, right?

    To all those that are getting the hits: Try clearing your cookies, web cache, etc. See if that helps, at least for now. If the hostile ads are in fact somewhat targeted, it may get better as you may have cookies from certain sites/categories of sites that the malicious ads are targeting. Also, try a different browser or upgrading your browser if possible. Same with Java. Ditch java 6 entirely, uninstall it, and install the latest versions of Java 7, flash, shockwave, etc. It could be targeting certain vulnerabilities in specific versions of software on your system. (at this point I'm grasping at straws)

    Also if you dont mind a tiny bit of big brother, you can switch your DNS provider to Opendns.com. They do SOME vetting of sites and help prevent certain attacks, but collect anonymous usage data. As long as you arent prone to searching for pressure cookers and/or kiddie porn, I wouldnt be too worried about what they collect. :lmfao:

    I personally havent seen any attacks since the server move, but I did see them personally on a frequent basis up until the switch, so you arent going insane.
     

    AnthonyG

    Gentard
    Rating - 100%
    2   0   0
    Jan 21, 2010
    242
    18
    Ann Arbor
    Post #2 was two weeks ago...Obviously it didn't fix it. Just happened to me again, and it seems it's happening to others too. Maybe it's time to talk to Fenway again. I understand it's not your fault, but you're the one posting here so I'm complaining to you.


    #2 doesnt say it was fixed.
     

    chezuki

    Human
    Rating - 100%
    48   0   0
    Mar 18, 2009
    34,160
    113
    Behind Bars
    Post #2 was two weeks ago...Obviously it didn't fix it. Just happened to me again, and it seems it's happening to others too. Maybe it's time to talk to Fenway again. I understand it's not your fault, but you're the one posting here so I'm complaining to you.
    I believe post #2 is politely stating that AG removed the offending ad, but the boss said no so it was put back.

    Bugatti payments gotta be made and even the INGO jet is affected by current fuel prices.
     
    Top Bottom