Greens website taken over by spammers?

johnboy 2 July 2009 7

RiotACT’s all seeing eye has noticed a strange thing. It’s a link to an online payday lender on the ACT Greens’ website.

Now if you go to that website with a modern browser you won’t see it there. The all seeing eye doesn’t use sophisticated web rendering.

But if you take a look at the source code (and I’ve printed out a copy) you’ll find it’s definitely there.

Down at the very tail end of the code there are links to a staggering array of viagra products.

Perhaps time for a revamp?

What's Your Opinion?

Please login to post your comments, or connect with
7 Responses to Greens website taken over by spammers?
YapYapYap YapYapYap 11:10 pm 03 Jul 09

Oh, now I see.

YapYapYap YapYapYap 11:09 pm 03 Jul 09

Hell Skid, how did you do that – find out all that stuff?

Skidbladnir Skidbladnir 9:45 am 03 Jul 09

E: The viagra ads.

Wierd… are a Soros Group Foundation (as in George “Swimming Around In A Tower Full of Cash, 29th Richest Man On Earth” Soros)

Created On:19-May-1999 21:17:10 UTC
Last Updated On:05-Feb-2008 16:27:13 UTC
Expiration Date:19-May-2013 21:17:46 UTC
Sponsoring Registrar:Network Solutions LLC (R63-LROR)
Registrant ID:21838242-NSI
Registrant Name:Anthony Galietti
Registrant Organization:Open Society Institute – Soros Foundations
Registrant Street1:400 West 59th Street
Registrant Street2:4th Floor
Registrant Street3:
Registrant City:New York
Registrant State/Province:NY
Registrant Postal Code:10019
Registrant Country:US
Registrant Phone:+1.212548069
Registrant Email:agalietti@SOROSNY.ORG
Admin ID:21838242-NSI
Admin Name:Anthony Galietti

The source code of any of the documents in the directories of all point to an italian website called which is full of both viagra referrers and porn referrers.
So very many porn referrers.
Although at first appearances an Italian website, it is hosted in the Ukraine, with Domain registered to:
LV Inc LTD Li.
James Mosersbrown (
5841 S. Maryland Avenue

(Which according to Google Maps is the University of Chicago hospital)

Good luck chasing phantoms, its probably just easier to go back to scratch and find a better host.

farq farq 10:11 pm 02 Jul 09

bound to be some pun in this.

farq farq 10:07 pm 02 Jul 09

channelvision eh?

another great service from transact.

firestorm22 firestorm22 9:48 pm 02 Jul 09

Looks like I lied…finally found the log & it appears to be the channelvision site that has a virus…

Threat Name: VirTool:JS/Obfuscator.D
Detection Date and Time: 2/07/2009 9:10 PM
File Name: C:\Users\Tim\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YGKI8V0D\channelvision_com_au[1].htm
Threat Severity: Severe
Threat Category: Tool
Contained Object: (SCRIPT0000)
Virus and spyware monitoring found potentially unwanted software: (ANTIVIRUS_ONACCESS)
Threat Status: Removed

firestorm22 firestorm22 9:25 pm 02 Jul 09

Hmmm the code is still there. Definitely looks like something nasty sitting on their hosting.

OH WAIT I just had a Trojan warning triggered off by my antivirus (obfuscator Trojan) – only had and the greens site open…I’m now guessing a Trojan is hanging out on the greens site waiting to infect people behind on Windows Updates, antivirus or using an old browser/OS.

Looking for the log in my antivirus (windows onecare) to see wher eit came from…

CBR Tweets

Sign up to our newsletter

Region Group Pty Ltd

Search across the site