Author Topic: clk.apx tracking blacklist  (Read 2572 times)

0 Members and 1 Guest are viewing this topic.

Offline Mustapha15

  • Newbie
  • *
  • Posts: 4
clk.apx tracking blacklist
« on: May 13, 2020, 09:19:37 AM »
Why do I keep getting this warning and how can I stop it

Thank you


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: clk.apx tracking blacklist
« Reply #1 on: May 13, 2020, 09:41:40 AM »
This is because of Avazu Private Exchange (APX).
A leading self-served ad exchange for publishers to convert global traffic into revenue.
Advertisers use APX as a platform for unified distribution channels,
while publishers manage their global inventories with APX.

Most adblockers etc. block this adware driven -clk.apxadtracking dot net
See: https://webiplookup.com/clk.apxadtracking.net/
for instance here: https://webiplookup.com/npy21.com/domain.htm

You do not want to be taken to an adware infested sub-domain by miscreants, do you?
See: https://exploits.shodan.io/?q=apx  (command injection and buffer overflow exploits).
So often adware goes hand in hand with cybercrime and infections of some sort.
To alert you against that is the mission of any av-solution.
That is why you got alerted by avast's.

Have a peaceful day,

polonus (volunteer 3rd party cold recon website security-analyst and website error-hunter)
« Last Edit: May 13, 2020, 09:51:56 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: clk.apx tracking blacklist
« Reply #2 on: May 13, 2020, 11:45:24 AM »
Avast blocks this as an unsafe website: -http://gulfstarsauto.com/banner/apx/shp/index/xb/

Backtracking such sites search for *apx with urlscan.io,
like with a search request like: https://urlscan.io/search/#apx%2Fshp%2Findex
and one could detect examples like this one (malicious):
https://urlscan.io/result/165c588d-a922-4739-8982-034838ae3d72/
resulting in a 100% PHISHING Score.
See the vulnerabilities that could have been exploited here:
https://www.shodan.io/host/192.210.199.68
Colo Crossing abuse on IP: https://www.virustotal.com/gui/ip-address/192.210.199.68/relations
7 engines detect this domain (burncalis dot gq), see: https://www.virustotal.com/gui/url/3a0e73b105e62407b8c14ad177862eb52bb482df1ff5205e34059859c450c668/detection

And an example where this PHISHING has been cleansed apparently (since December last):
https://urlscan.io/result/8c23cf21-d206-4095-88d6-2edeac0fadfa

polonus
« Last Edit: May 13, 2020, 06:39:59 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: clk.apx tracking blacklist
« Reply #3 on: May 13, 2020, 07:08:52 PM »
Similar PHISHing schema found 7 months ago: -http://cardanalysis.tk-
-> https://urlscan.io/result/99869c57-38f1-4270-a165-8b6b956e8acb/
Not taken down apparently: https://aw-snap.info/file-viewer/?protocol=not-secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=Xnx9I3xufGx5c1tzLnRr~enc
VT results, 4 engines to flag: https://www.virustotal.com/gui/url/9eead6bf47d748a3dd5a41bc99e46cf2f1986c93c571fd577548e1fe2f9ccdd5/detection
At present only three to flag: https://www.virustotal.com/gui/url/9eead6bf47d748a3dd5a41bc99e46cf2f1986c93c571fd577548e1fe2f9ccdd5/detection

Status now "connection reset by peer https://httpstatuses.com/429
for Google's UA"- Re:  https://sitecheck.sucuri.net/results/cardanalysis.tk

Verotel International BV - IP abuse -
PORT   STATE SERVICE VERSION
80/tcp open  http    nginx
|_http-title: 429 Too Many Requests  Not Found Anymore

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Mustapha15

  • Newbie
  • *
  • Posts: 4
Re: clk.apx tracking blacklist
« Reply #4 on: May 14, 2020, 09:31:57 AM »
Thanks for replying but I have no idea what you're on about as I am not a computer expert in any shape or form, just imagine you're talking to a cat

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: clk.apx tracking blacklist
« Reply #5 on: May 14, 2020, 12:43:53 PM »
Hi Mustapha15,

Explanation in simple words. You watch something and it is a website that uses the  Avazu Private Exchange.
You see on the website the one thing, while the advertisement scheme takes you to ads from somewhere else.
The website owner gets revenue for taking you to ads the user did not ask for to visit and see.
If such a scheme is unfair or hidden and performed by seo-cybercriminals we say it is malicious adware.

Avast flags such behavior by websites - going from main domain to an advertisement sub-domain as unasked for.

You might as a user not want such schemes, it is not done in a fair way. We call that adware.

Of course there are some old grannies that are glad even to receive spam messages,
as ads and spam are the only communication they will ever get from their computers,
but normal users want to block that crap and stay free from it.
Install uBlock Original adblocker will certainly help.
A good adblocker may stop all such problems for you.

It makes your browser also faster if you need not be taken to unwanted advertisements via redirects in the first place.

pol
« Last Edit: May 14, 2020, 12:49:00 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: clk.apx tracking blacklist
« Reply #6 on: May 14, 2020, 01:46:30 PM »
Hi Mustapha15,

It could also be you have some crap on that computer that takes you to such clk.apx destination.
Could you present us with a screenshot of that particular avast message.

Maybe you need some help from a qualified remover to help you through the cleansing routine,
if need be.

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
« Last Edit: May 14, 2020, 01:49:47 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Mustapha15

  • Newbie
  • *
  • Posts: 4
Re: clk.apx tracking blacklist
« Reply #7 on: May 15, 2020, 10:43:15 AM »
How do you add an image, when I click on insert image it just brings up these brackets (IMG)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: clk.apx tracking blacklist
« Reply #8 on: May 15, 2020, 11:01:41 AM »
How do you add an image, when I click on insert image it just brings up these brackets (IMG)
See the screenshot from Magna86.

W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Mustapha15

  • Newbie
  • *
  • Posts: 4
Re: clk.apx tracking blacklist
« Reply #9 on: May 15, 2020, 12:48:35 PM »
No idea how i didn't see that

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: clk.apx tracking blacklist
« Reply #10 on: May 15, 2020, 04:11:09 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37531
  • Not a avast user
Re: clk.apx tracking blacklist
« Reply #11 on: May 15, 2020, 05:45:11 PM »
See process on your screenshot: it seems to be your VPN program (urbanVPN) that connect to that URL


« Last Edit: May 16, 2020, 10:38:25 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: clk.apx tracking blacklist
« Reply #12 on: May 16, 2020, 12:53:17 AM »
Hi Pondus,

But when that detection appears to be genuine, it can be no more than an adware PUP detection
(potentially unwanted programme).
That is probably also why it is not generally being flagged on VT.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!