Welcome to DU!
The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards.
Join the community:
Create a free account
Support DU (and get rid of ads!):
Become a Star Member
Latest Breaking News
Editorials & Other Articles
General Discussion
The DU Lounge
All Forums
Issue Forums
Culture Forums
Alliance Forums
Region Forums
Support Forums
Help & Search
DU Community Help
Related: About this forumWhois: eoperfops12.qcloudteo.com
Suspicious attempts at connection to, on multiple DU pages.Doesn't act like an advertiser. TIA
11 replies
= new reply since forum marked as read
Highlight:
NoneDon't highlight anything
5 newestHighlight 5 most recent replies
Whois: eoperfops12.qcloudteo.com (Original Post)
justaprogressive
Sunday
OP
surfered
(11,766 posts)1. Do you have any of their posts?
justaprogressive
(6,343 posts)2. Sorry these are not associated with a user
it's on the pages themselves.
A whois tells me VERY little about this ip address...
surfered
(11,766 posts)3. Send a screenshot if you see it again
justaprogressive
(6,343 posts)4. here ya go

To be clear this ONLY happens on DU PAGES.
sboatcar
(752 posts)6. Brave.exe belongs to the brave browser
I've also seen brave.exe spoofed as other things, but it looks like someone is trying to do some kind of an exploit from a brave browser coming from that IP address (I'll provide it if you'd like it, but I'd rather not post in here)
justaprogressive
(6,343 posts)8. No the pages are linking to that website!
I'm using Brave. The page is trying to direct the browser to connect to this suspect website.
sboatcar
(752 posts)9. Ahhh gotcha
Likely its one of the ads.
sboatcar
(752 posts)5. DNS lookup says its registered in china, names redacted
The IP address geolocates to Brazil. Odd.
justaprogressive
(6,343 posts)7. yeah like I said ODD!
Who do I contact in Admin to report this?
surfered
(11,766 posts)11. Send DU email to EarlG
surfered
(11,766 posts)10. Here's one theory
1. Perhaps it's an embedded gif from a non secure server...
Ie: http vs https at the beginning of the embedded image URL