Our Community Forums will be closing on June 27, 2024. Please visit att.com/support for all your support needs.
Need help with your equipment?
caramelsun's profile

New Member

 • 

6 Messages

Friday, February 17th, 2023 4:37 PM

Prreqcroab.icu continues to pop up as blocked from different devices on our network

Hi,

I looked this site up and it shows as a high risk/scam/low trust level site but no one is consciously going ther. Is there some hacking attempt going on?

AT&T Smart Manager blocks the outbound attempts thankfully but how can I ban this entirely? Or find out what’s causing this?

I noticed it in real time when I clicked a YouTube ad then shortly after taken to the site which appeared legitimate it … the Smart Manager popped up notifying protection. But I looked in the history of blocks and noticed the same site from various devices on our network.

Any help will be greatly appreciated.

Accepted Solution

Official Solution

Employee

 • 

420 Messages

1 year ago

Hello Community and @caramelsun,

Thank you for your patience and feedback on this topic.  I was able to speak with our Smart Home Manager team, and they provided the details below.

Firstly, you are able to disable the pop up messages if you'd like.  You can go into the SHM settings/app preferences and turn off ActiveArmor Alerts. The security product will still block the spam ware, but the pop up alerts will stop.  In addition, the messages will still show in the message center if you want to look at it later.  Keep in mind if you do this, you won't see the messages for any pop ups until you re-enable this.

 

Second, let me explain why you're getting this message, and what it means.  An example to help illustrate what happens would be when you click on one of those articles on Facebook like "20 funniest sport moments", or "50 dumbest statements from celebrities".  When the page loads, you will likely see a few of the messages shown above come up. However, you'll notice the article on the page still loads.  If you look at the page closely though, you will notice several places where there was an ad that is blank now. What happens is when you go to the page, it spawns a bunch of spam/adware applets attached to the page. This is why you think you never went to that site ActiveArmor says is blocked, because it's the applet that it's blocking, not the main page.  You didn't want the ad when you went to the original URL, but the page you went to tried to go to that site without your knowledge.

Long story short, the security software sees all these secondary spam URLs and blocks those while leaving the main page source alone.  That’s why some areas on the page may be blank. Think of it like an ad blocker, and the page should load faster without all these other spawned pages.

Lastly, the ad/spam folks are smart, and these sites get wise to the fact that security software is blocking them.  So, they change their URL from time to time to try and out smart the software until they are caught again. Like cat and mouse.

I apologize for the lengthy response, but wanted to make sure to fully explain what is happening, how to fix it, and what to be on the look out going forward.

Thanks

Tim, AT&T Community Specialist

New Member

 • 

1 Message

1 year ago

I started getting this message involving the same url. No idea what is triggering this but it has been happening for a few days now.
No one is accessing this site. The message names one of my wireless routers, so I'm not sure if this is some sort of firmware bug or something.
The brand is Deco if you happen to have the same brand router.

New Member

 • 

6 Messages

1 year ago

I have an AT&T router, so not sure if that will help determine if it's firmware, but I do hope someone from AT&T can let us know if it's a device, a potential security breach/bug, malware viruses/links, or what other issue could be causing this. It seems to be something other people are experiencing, too, as the searches online regarding this site are demonstrating.

I'm unsure what this means, and certainly not a tech, but I noticed it a while ago when some of the college kids were doing homework and would have to go to a site-directed by the course/instructor. Some of these sites are NOT checked, yet the students still have to research or use them.

But it really clicked/I noticed it again when I hit an ad link on Youtube, and the Smart Manager message popped up. Perhaps it's already in the network trying to reach back to its source, I don't know, but something isn't right. So I'm thinking, OK, perhaps ad links could be unsafe/faulty .... it's possible, right?

I mean, malware is alive and well out here on the internet. I know I didn't deliberately click that site link. But then, I started searching online and noticed others were reporting the same thing. Coincidence? Probably not. Something is going on.

I want to know what is "IS" and how to "PREVENT" damage or initiate more protection if necessary. Searching on the net brings up many warnings about this site on scam site checkers/detectors. Thankfully, it appears that Site Manager is blocking the site from outbound access, so to me (in my mind), it could possibly mean it may be in the network/on devices or something. Or not. 

I'd sure like to know for sure.

New Member

 • 

4 Messages

1 year ago

Anxious to hear as well. 

I have the same website popping up as blocked over and over. In fact, it pops up in the middle of the night when there are no devices active. What my search has revealed to this point is it it does seem to coincide with Google Calendar activity. I just entered something in my calendar and that website got blocked or a website reminder went off at 2:00am and that website got blocked. Only anecdotal evidence thus far, and that this is not enough for me to unblock it until I hear from AT&T.

(edited)

New Member

 • 

5 Messages

1 year ago

This is the scary comment on Wikipedia:

the firm measures metrics such as audience age and gender makeup, areas of interest and type, length and frequency of their engagement with certain types of content. This private information is made publicly available to be used by marketers and publishers to accurately understand their audience in granular detail.

here’s the Whois record:

whois.nic.icu]
Domain Name: PRREQCROAB.ICU
Registry Domain ID: D325526776-CNIC
Registrar WHOIS Server: whois.markmonitor.com
Registrar URL:
Updated Date: 2022-11-08T12:00:59.0Z
Creation Date: 2022-09-30T20:36:52.0Z
Registry Expiry Date: 2023-09-30T23:59:59.0Z
Registrar: MarkMonitor, Inc (TLDs)
Registrar IANA ID: 292
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Registrant Organization: Quantcast
Registrant State/Province: CA
Registrant Country: US
Registrant Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Admin Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Tech Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Name Server: NS-209.AWSDNS-26.COM
Name Server: NS-765.AWSDNS-31.NET
Name Server: NS-1766.AWSDNS-28.CO.UK
Name Server: NS-1347.AWSDNS-40.ORG
DNSSEC: unsigned
Billing Email: Please query the RDDS service of the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Tech contact of the queried domain name.
Registrar Abuse Contact Email: [email scrubbed]
Registrar Abuse Contact Phone: +1.2083895740
URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of WHOIS database: 2023-02-19T01:03:00.0Z <<<

For more information on Whois status codes, please visit https://icann.org/epp

>>> IMPORTANT INFORMATION ABOUT THE DEPLOYMENT OF RDAP: please visit
https://www.centralnic.com/support/rdap <<<

The Whois and RDAP services are provided by CentralNic, and contain
information pertaining to Internet domain names registered by our
our customers. By using this service you are agreeing (1) not to use any
information presented here for any purpose other than determining
ownership of domain names, (2) not to store or reproduce this data in
any way, (3) not to use any high-volume, automated, electronic processes
to obtain data from this service. Abuse of this service is monitored and
actions in contravention of these terms will result in being permanently
blacklisted. All data is (c) CentralNic Ltd (https://www.centralnic.com)

Access to the Whois and RDAP services is rate limited. For more
information, visit https://registrar-console.centralnic.com/pub/whois_guidance.

(edited)

New Member

 • 

4 Messages

1 year ago

Any idea how they got out of my machine/our machines? What service is using them? AT&T, this is your form why is no one from AT&T answering?

New Member

 • 

6 Messages

1 year ago

wow 😯🫤 Yeah…I want to know how too ….not sure if AT&T will have an answer since it appears the Smart Manager is doing its job. I have a VPN…do my best to put privacy blockers in place but ….virus software……but tech is evolving. So I hope something is put  in place to counter these tactics.

New Member

 • 

5 Messages

1 year ago

This is not something we can control. Anytime we go to a website, if that website uses this analytical software, then you'll have a call from that browser connection being made back to the mother ship (quantcast). So it happens as you're surfing the web; this does not originate from your machine, it's a call being made from your browser because of the website you're on. AT&T has no control over that; their tech. simply sees it happening and puts the kibosh on it, which is exactly what I want it to do.

New Member

 • 

5 Messages

1 year ago

The evildoer in this case is quantcast and their ability to bypass whatever privacy tools we may have installed as extensions in our browsers. They've figured out a way to track all our behavior without using cookies. I imagine all these calls to that weird web address have something to do with that.

New Member

 • 

4 Messages

1 year ago

Jrkoop, if it is a response to going to a website, why does it happen in the middle of the night.  I blame Chrome and google. The only other thing working in the wee hours is Code 42. 

Not finding what you're looking for?
New to AT&T Community?
New to the AT&T Community? Start by visiting the Community How-To.
New to the AT&T Community?
Visit the Community How-To.