Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Another data sources #6

Open
kowith337 opened this issue Feb 26, 2019 · 31 comments
Open

Another data sources #6

kowith337 opened this issue Feb 26, 2019 · 31 comments

Comments

@kowith337
Copy link
Owner

kowith337 commented Feb 26, 2019

This should be large company data sources that expose E-Mail address and sites, divided in each category.
https://googlegroups.com/group/itsenator/attach/e5bf4f790aa48e15/Prospect%20Audiences.xls?part=4+
from: https://groups.google.com/forum/#!forum/itsenator

kowith337 added a commit that referenced this issue Feb 26, 2019
@kowith337 kowith337 changed the title Another large data sources Another data sources Mar 28, 2019
@kowith337

This comment has been minimized.

kowith337 added a commit that referenced this issue Mar 28, 2019
How many lots of fake sites to inject ads out there!? most of them created by Russian peoples and hosts them with random Poland domains?
- Also include something from #6 (comment)
@kowith337

This comment has been minimized.

kowith337 added a commit that referenced this issue Apr 7, 2019
Add M3Tech and related sites, plus update with related search from #6 (comment)
@kowith337

This comment has been minimized.

@kowith337

This comment has been minimized.

kowith337 added a commit that referenced this issue May 1, 2019
@kowith337
Copy link
Owner Author

kowith337 commented May 1, 2019

Note that TrueHits was already blocked because of this domain was flagged as Tracking, so I use the Google cache instead.

  • http://webcache.googleusercontent.com/search?hl=en&q=cache%3Ahttp%3A%2F%2Ftruehits.net%2Fmodule%2Fstato.php%3FG_CODET%3Dp0026927%26t%3D2%26y%3D2016%26m%3D05%26Web%3Dwww.n-content.com%26cate%3D%26v%3D1%26dir%3Ddirectory%26order%3D444%26g%3D
  • http://webcache.googleusercontent.com/search?q=cache:QJQpxE3vUzkJ:truehits.net/module/stato.php%3FG_CODET%3Dp0026927%26t%3D2%26y%3D2015%26m%3D12%26Web%3Dwww.n-content.com%26cate%3D%26v%3D1%26dir%3Ddirectory%26order%3D358%26g%3D+&cd=5&hl=en&ct=clnk&gl=th

kowith337 added a commit that referenced this issue May 1, 2019
Note that I'm also deep searching with the previous tools (NirSoft's DomainHostingView) with some existing domains below...
- GetCools
- SolutionOne Holding (Headquarter of N-Content and NMPCenter)
kowith337 added a commit that referenced this issue May 2, 2019
@kowith337
Copy link
Owner Author

kowith337 commented May 5, 2019

Need to lookup this report from Comodo

  • https://www.comodo.com/ctrlquarterlyreport/Comodo-20Sept-2017-special-report-konica-copier-attack.pdf
  • https://www.comodo.com/ctrlquarterlyreport/Comodo_IKARUSdilapidated_Special_Report_Part_II.pdf

@kowith337
Copy link
Owner Author

https://truehits.net/script/201812/rank_10.php

@kowith337
Copy link
Owner Author

This repo below contains some ThinkSmart domains
https://github.com/Tksm-Attaphon/dtacplay-github

kowith337 added a commit that referenced this issue May 5, 2019
Subdomains checked via NirSoft's DomainHostingView
- enjoy108
- mono2u

Include from comments
- #6 (comment)
- #6 (comment)

Miscellaneous
- Block even more Russian baits (Use CF TLD)
- Include more ThinkSmart subdomains from CertDB
- Found related domains that use same IP address of ThinkSmart, e.g.
  - fabruary30
  - thaisync
@kowith337
Copy link
Owner Author

kowith337 commented May 26, 2019

Incomplete lists related to Shinee (aka. AD Venture)
  • https://www.google.co.th/search?num=100&no_sw_cr=1&pws=0&safe=off&hl=th&lr=lang_th&q=%22Girl+Clip%22+SMS+-site%3Afacebook.com+-site%3Apantip.com+-site%3Acommunity.*
  • https://www.google.co.th/search?num=100&no_sw_cr=1&pws=0&safe=off&hl=th&lr=lang_th&q=022076805+OR+02-2076805+OR+02-207-6805+-site%3Afacebook.com+-site%3Apantip.com+-site%3Acommunity.*

kowith337 added a commit that referenced this issue May 26, 2019
…4579

#6 (comment)
- They are related to Shinee (aka. AD Venture)
- Not finished yet, because I'm commit from mobile device, need to head onto my notebook for recheck and rearrange...
@kowith337
Copy link
Owner Author

kowith337 commented May 27, 2019

Conference data, I don't know...

http://mobile.shinee.com/01/rqf_v1.0/reqform/ReqForm_list.asp

Note: Username parameter are needed to view conference properly...
  • http://mobile.shinee.com/01/rqf_v1.0/reqform/reqform_list.asp?usert=all&user=nadtinee
  • http://mobile.shinee.com/01/rqf_v1.0/reqform/reqform_list.asp?usert=co&user=nadtinee
  • http://mobile.shinee.com/01/rqf_v1.0/reqform/reqform_list.asp?usert=sp&user=nadtinee
  • http://mobile.shinee.com/01/rqf_v1.0/reqform/reqform_list.asp?usert=rm&user=nithi

Edited note:
They're many types of user teams and also give different topics, only matched username and group team can browse those conversations.

kowith337 added a commit that referenced this issue May 27, 2019
- Found one IP address connect to OpenX to retrieve ads
- Continue from #6 (comment) that I'm re-search again and found one domain just indexed and appeared
@kowith337
Copy link
Owner Author

kowith337 commented May 28, 2019

TrueHits Cache

http://webcache.googleusercontent.com/search?hl=en&q=cache%3Ahttps%3A%2F%2Ftruehits.net%2F2018%2Findex.php%3Fcateid%3D10

@kowith337

This comment has been minimized.

@kowith337
Copy link
Owner Author

kowith337 commented Jun 14, 2019

ThinkSmart use ZeroPark to show ads and redirect traffics and/or web page to directly subscribe their services without any user-side confirmations!

https://www.bangkokbiznews.com/pr/detail/48072

image

With the picture above, expected that ThinkSmart use ZeroPark to serve ads, then redirect to the web page that hosted on CTrackz for performing quick subscribe!

@kowith337
Copy link
Owner Author

kowith337 commented Jun 20, 2019

...

https://olimob.com/inc/ajax/offers_pubstat.php

A tool to generate full-width text to prevent URL clicking

https://lingojam.com/VaporwaveTextGenerator

kowith337 added a commit that referenced this issue Jun 20, 2019
Phone Number: 020839290
- Determined these sites below are the part of ThaiZa
  - oho-mobile.com
  - spak.me

Previously blocked and related to...
- funster.mobi
  - gamiebox.com
  - redclub.mobi

Other update included
- Block more MobIdea subdomains
- Block ThaiZa NS subdomains
- Block ahyoyo.com
@kowith337
Copy link
Owner Author

@kowith337
Copy link
Owner Author

kowith337 commented Jul 24, 2019

Update from #6 (comment)

...

http://mobile.shinee.com/01/rqf_v1.0/reqform/ReqForm_Detail.asp?user=nadtinee&usert=all&rq_id=5391&brqno=01201907220001

TMC = TeleInfo Media Co.,Ltd. (Thailand Yellow Pages)

@kowith337
Copy link
Owner Author

From https://pantip.com/topic/39093998

SumOne (aka. RakContent)
  • https://www.google.co.th/search?num=100&no_sw_cr=1&pws=0&safe=off&hl=th&lr=lang_th&q=025592997+OR+02-5592997+OR+02-559-2997+OR+0-2559-2997+-site%3Afacebook.com+-site%3Apantip.com+-site%3Acommunity.*
  • https://www.google.co.th/search?num=100&no_sw_cr=1&pws=0&safe=off&hl=th&lr=lang_th&q=025592913+OR+02-5592913+OR+02-559-2913+OR+0-2559-2913+-site%3Afacebook.com+-site%3Apantip.com+-site%3Acommunity.*
Spreadsheet Exposed, gotta find something more in there!

http://103.80.100.92/%E0%B8%82%E0%B9%89%E0%B8%AD%E0%B8%A1%E0%B8%B9%E0%B8%A5%20Business%20Guide%20All/BusinessAll.xls

@kowith337
Copy link
Owner Author

kowith337 commented Aug 7, 2019

Relationship of company: HexCube

  • 020179600
    • They use this number for automation calling to lure peoples who receive the call make subscribe their services.
    • After unintentionally subscribe their service, they will start sending SMS and show other service numbers.
    • See twitter report

  • 026190882
    • Manager Online have a news article said about subscribing SMS news service to keep support specific political TV channel.

  • 026199814
    • Many results also show this call center number related to GameLoft (Region)

kowith337 added a commit that referenced this issue Aug 7, 2019
@kowith337
Copy link
Owner Author

More interesting information

@kowith337
Copy link
Owner Author

@kowith337
Copy link
Owner Author

kowith337 commented Aug 29, 2019

Todo: b8a735f

  • view-source:https://gamehack.bid/v2/th/game/com.supercell.clashofclans-hack?referer=my.dek-d.com
  • List all subdomains of bemobtrk.com as much as possible.

kowith337 added a commit that referenced this issue Aug 29, 2019
@NotRealPaz
Copy link

NotRealPaz commented Oct 5, 2019

I think *****.bemobtrk.com is just a ad-tracker according to this website bemob.com

@kowith337
Copy link
Owner Author

kowith337 commented Oct 6, 2019

Yes, it's deserve to blocked due to it's possible to redirecting to AOC supscription page, but they may have lots of random subdomains, however.

@NotRealPaz
Copy link

Then the file it's gonna be very large due to host file doesn't support wildcards. around 60 million lines of host file.

@kowith337
Copy link
Owner Author

kowith337 commented Oct 7, 2019

Hmm, I don't think it's site will use 11111, aaaaa till zzzzz.

If they really do, their site and/or server might be large enough like a server farm, or have lots of virtual servers/containers?

@NotRealPaz
Copy link

They just point to same server. You can try to ping them. I think they are around 2-10 servers.

@kowith337
Copy link
Owner Author

kowith337 commented Oct 13, 2019

That might still be return to a same point by adding randomized sub hosts, since this is a hosts file, not wildcard, direct DNS name block or top-level blocking or something.

Unless it have some possible ways, e.g.

  • Add bemobtrk.com to your additional hosts list in pDNSF to ensure that everything from that domain will be blocked, regardless of any other subs.
  • uBO (or Nano) and uMatrix are also block subdomains of them since the main of it's domain are listed and blocked already.

However, not everyone use any good tools, and any browsers than Chrome, either.

Because Chrome itself are able to bypass blocking and use their own built-in DNS, unless you've turn off this flag!

@kowith337

This comment has been minimized.

@kowith337

This comment has been minimized.

kowith337 added a commit that referenced this issue Dec 29, 2019
Search with SMS sender numbers and found `aplaymusic.com` that appear in E-Mail address.
It's related to `APlayDigital`, however, I didn't include that in the past, so I just update this.

#6 (comment)
kowith337 referenced this issue Dec 29, 2019
Those are related to (shady) services with two topics
- Football
- Movies download
 * Both are seems to be illegal, they also make use (and abuse) of operator content charging API for member subscriptions.
kowith337 added a commit that referenced this issue Apr 8, 2020
kowith337 added a commit that referenced this issue Nov 28, 2020
I've randomly found from self-promo banner that suggest to subscribe for premiere league clips highlight and use the call number 02-766-9038, clicking its banner are lead me to BigFunSpace and seems like its use same UI of Truemove-H WAP subscriptions, so it's good to block it!
Note that related to call center number above, if change the call number to 02-766-9000, it's reference to `AddTech Hub` under the `Mitsui ICT Ltd.`

More informations will be commented into issue #6
@kowith337
Copy link
Owner Author

kowith337 commented Nov 28, 2020

About recent commit: 5df5b18 + https://pantip.com/topic/40352230
ba047b70-308d-11eb-8299-03e28962d52d_original

Found from TrueID news articles that have its promo banner, all links below are converted to Outline.

So, it's clear that Truemove create subscription services by their own!

@kowith337
Copy link
Owner Author

New affiliate lists to check along with OilMob

https://leads.mengine.me/live-offers/index/per-page/100/page/7/order/ID/dir/desc

Trend Micro report of malware that written with Kotlin

https://www.trendmicro.com/en_us/research/18/a/first-kotlin-developed-malicious-app-signs-users-premium-sms-services.html
In images and extracted URL are pointed to GMPMobi

kowith337 added a commit that referenced this issue May 6, 2021
…33518924

- Blocking another layer of `Truemove-H` AOC landing and confirmation domains
- Update probably `GMPMobi` IP address (TrendMicro Report)
- Added `AppFlood` from Trend Micro report
- Added gambling site that give fake call centre numbers that not related to them
kowith337 added a commit that referenced this issue Sep 13, 2021
#6 (comment)
- Search with any preview images of Thai campaign that left the phone numbers, newer entries are mostly related to eTracker/MacroKiosk
- As well as IP blocklists

https://pantip.com/topic/40975506
- Added scam site that disguise as clothing brand
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants