Translate

3/30/2014

Malicious Blogspotvisitor snapchatpasswordgenerator.blogspot.com

(To this Blog, and probably to many others who
highlight the Snapchat Data-breach a while ago):

PHISHING FOR MOBILE PHONE NUMBERS
Pretending you will win some IPhone, or some other Malware Crap...




PHISHING BLOG: THE bit.ly LINK HAS BEEN FOUND ON THE FOLLOWING BLOGSPOT:
MALICIOUS COMMENT SPAMMER: (SPAMMED MY OWN BLOG)


COMMENT WAS GIVEN ON THIS POST:
stayaway2.blogspot.com/2014/01/hacked-skype-and-snapchat-compromised.html
http://snapchatpasswordgenerator.blogspot.com/
  • https://www.virustotal.com/de/url/d99d7a09c4fdd8b2bf19eae284261183d0884644de04b4e28dfc35a661cceca0/analysis/1396125921/

SUSPICIOUS ActiveX behaviour:
  • http://wepawet.iseclab.org/view.php?hash=a9a04c5facd1c77a6a57444abdb478d2&t=1396123149&type=js

THE OWNER OF THIS BLOG IS (should be) Saad Hashmi (SOUNDS LIKE HASH ME) AND HAS VIDs CALLED: How to Hack Twitter ETC. WHERE SEVERAL VIDs HAVE BEEN REMOVED OR NEVER EXISTED:
https://plus.google.com/101817228413013975367/posts
  • https://www.virustotal.com/de/url/1315983a69f47b3e7a91c6d4dc1148f7eb8ebd773ac7846caf907cd711affbed/analysis/1396127927/

PHISHING FOR MOBILE NUMBERS (SUPPOSING TO WIN SOMETHING) BEFORE DOWNLOADING (DOMAIN):
http://bit.ly/1h4aQgx
  • https://www.virustotal.com/de/url/775bedbd10540c804cd6045beaad4728754a8a35c3a673d9d4df0afaddfe1179/analysis/1396128854/

AT PHISH TANK:
  • http://sitecheck3.sucuri.net/results/bit.ly/1h4aqgx
  • http://www.phishtank.com/phish_detail.php?phish_id=2348877

REDIRECTS TO: --->
http://cleanfiles.net/?stj2nPC
  • https://www.virustotal.com/de/url/025997ab9b0805abdd4d83e9997a54085e2dfbc5ebc39893b1e5c76d27d87916/analysis/1396129645/
  • https://www.virustotal.com/de/file/ef8567646f6f7b246704a8550da770a2beb5f628b154bca2b89bc733a756c1a2/analysis/1396128932/

REDIRECTS TO: --->
http://jlyse.net/?stj2nPC
  • https://www.virustotal.com/de/url/a9e5e6fd72161667774a27f2ecaca3cd16d65a473ac4af8553ea41dea4dac749/analysis/1396129771/

---->
http://cleanfiles.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/4d26dd55eb21671c4b451ba271d1a4264d27c783e8bbda93608f8cdaf11c3a7c/analysis/1396129874/
FILE:
  • https://www.virustotal.com/de/file/bafc06f1e99e8ceb57dda20a1f97bc1ca1b347890d3ea8d057e6592306a896cb/analysis/1396130019/

----->
http://jlyse.net/includes/public/log_visitor.php
  • https://www.virustotal.com/de/url/18a2a109263c3ba20011e59974ef4bd5e49b44d7aeb0f4e7745dc7bb65106550/analysis/1396130315/

------>
http://jlyse.net/includes/offers/bootstrapWindow.php?file=143026
  • https://www.virustotal.com/de/url/38c9384d1eef60edb4173b22cd71a98361e104fa2ca2e71d2b942fc93506884c/analysis/1396130553/

------->
http://jlyse.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/e340b2c1a3e48ff193de46aaf0a5e60ebf3632fce7bd315f9b446d861c4429c0/analysis/1396130639/
  • https://www.virustotal.com/de/file/7cc16f897286710dfbb1e44ff8793113990ec3c9cac4df8aebefd95c7e11f35c/analysis/1394224032/

-------->
http://jlyse.net/bootstrap/assets/css/bootstrap.css
  • https://www.virustotal.com/de/url/6fd04f3ba5075a1dc73400b5f604307f4d3a613c76492870004ca216c64d6645/analysis/1396130730/
  • https://www.virustotal.com/de/file/03db46511bdaf1e131c2c9954c7b0cbd8f3c593aa4498b7f89ac3067511a5d60/analysis/1374039732/

--------->
http://cleanfiles.net/js/dwn8.js?v=17
  • https://www.virustotal.com/de/url/74ea97392f9c77ac88c303e9be63a528c9c36d26a3ba5baa7d3b5623c548b6f3/analysis/1396130811/
FILE:
  • https://www.virustotal.com/de/file/ff8b96ace5c518b297cb290bc797b9e26e794cd8d5cc2fdd05ed422eaa0e0a50/analysis/1396131053/

---------->
http://js-agent.newrelic.com/nr-361.min.js
  • https://www.virustotal.com/de/url/c593c58403de499701b64c2af0823e7f7d119ea39bb921ae6819c07057c52a88/analysis/1396131852/
  • https://www.virustotal.com/de/file/fce342d034fb770700ba7ac8421e05cd19d08bdc06ee0636f30fcdb3cd5db5fd/analysis/1396131856/

http://wepawet.iseclab.org/view.php?hash=d6973fc5d3786821ffb747ac7e431874&t=1396128982&type=js

Keine Kommentare:

Kommentar veröffentlichen