Why so many outbound connections to 'ad4.liverail.com'?

Posting here is no longer possible, please use the forum of a filter list project, such as EasyList
Locked
greenbeans123
Posts: 3
Joined: Thu Jul 02, 2015 4:54 pm

Why so many outbound connections to 'ad4.liverail.com'?

Post by greenbeans123 »

I am a bit new to the security field, and in the midst of shoving a ton of information in to the brain. One thing I am trying to understand is why I am seeing some of the clients machines I support making several thousand connections to 'ad4.liverail.com' and several other ad websites? Our AV is not catching anything, but there is no way this is normal behavior.
User avatar
mapx
Posts: 21940
Joined: Thu Jan 06, 2011 2:01 pm

Re: Why so many outbound connections to 'ad4.liverail.com'?

Post by mapx »

it depends on the sites they are visiting, video streaming sites probably, examples ?
greenbeans123
Posts: 3
Joined: Thu Jul 02, 2015 4:54 pm

Re: Why so many outbound connections to 'ad4.liverail.com'?

Post by greenbeans123 »

one example would be:

http://t4.liverail.com/?metric=error&er ... &x=&y=&xy=

I'm just not sure if this is one of those hidden ad clicking programs or is legitimate traffic.
User avatar
mapx
Posts: 21940
Joined: Thu Jan 06, 2011 2:01 pm

Re: Why so many outbound connections to 'ad4.liverail.com'?

Post by mapx »

well, I asked for a site they are visiting

however, the link you provided seems to be tracking stuff
greenbeans123
Posts: 3
Joined: Thu Jul 02, 2015 4:54 pm

Re: Why so many outbound connections to 'ad4.liverail.com'?

Post by greenbeans123 »

Gotchya, thanks for the info. They way things are set up here right now, we don't have access to the full links from the logs. That will be changed soon. But what I have seen from the tools I am using will record 693 hits to t4.liverail.com or ad4.liverail.com in one instance, or other sites like ads.adaptv.advertising.com. The URL's they hit prior will be to these connections I still am unsure of.
Locked