Sunday, January 4, 2015

Adware pop ups in my iphone, ipad and other mobile devices - SOLVED

I have this problem in my Iphone 6's Safari. Evey time when I visited my regular news portal e.g.

  1. http://www.themalaysianinsider.com/
  2. http://www.thestar.com.my/
I would get annoying pop ups in my IOS safari. It was to the extend that it would redirect you to download stuffs and apps below:

  1. www.adcash.com
  2. down.mobimobcell.com
  3. cldlr.com
  4. 93902.api-05.com
  5. LookerPlusMat.apk
All non HTTPS website are affected


Yes, it adware is on my iphone, One if the safest device in the world with ad ware.

What i have suspected:
  1. I first thought themalaysian insider was spreading some malware. I even reported it to their adminstrator. 
  2. I then notice it only happen to my wifi, home network time fiber. I have no problem with my Maxis LTE. I tried my wife's iPhone 5s, same problem with wifi - same problem. Now, it gotta be the ISP. Called but the said not their problem.
  3. I kept trying until I found the moon:
What is The Moon malware?

The Moon malware
bypasses authentication on the router by logging in without actually knowing the admin credentials.  Once infected, the router starts flooding the network with ports 80 and 8080 outbound traffic, resulting in heavy data activity.  This can be manifested as having unusually slow Internet connectivity on all devices.
I followed what was suggested in the KB: link but the issue persist. I notice it only happen to non HTTPS websites. It only affect HTTP and on my IOS devices. My desktop IE and Firefox was alright.

To cut the story short: The culprit:
I know it was my router (Linksys E1200 V2) with latest firmware 2.0.06. Until I found check on the suspicious static DNS in my router:



A quick google on 104.131.237.53 and I found this link. Finally, I have nailed the culprit. I do not know how but the some websites has remotely updated the static DNS in my router without me knowing. I have them changed to Google public DNS: 8.8.8.8 and 8.8.4.4 and my problem is solved!

I hope this post would help others with similar issue.


1 comment:

  1. Are you trying to earn money from your websites by using popup ads?
    In case you do, did you try using EroAdvertising?

    ReplyDelete