Translate

4/23/2014

MALICIOUS BLOGVISITOR FROM Hangzhou, CHINA
PHISHING:
billingcheckout.com (IP: 70.39.189.232) &
js.realypay.com (IP: 122.225.38.53)

DOMAIN 1:
China Telecomcenter
http://www.billingcheckout.com/
  • https://www.virustotal.com/de/url/d094721c14cdcebbee68aa9f08211ac1db05bee594e63e48667aaa6ba5c4ebcc/analysis/1398259763/ 
VISITING URL (on this BLOG)
http://www.billingcheckout.com/risk/index.js
  • https://www.virustotal.com/de/url/832c73b107ea273b0c1f89f78554f82c19824a74af820c6b71be41315ecaa39c/analysis/  
  • https://www.virustotal.com/de/file/dd6dc666f505f2f2d7664f13539a8dcb4537231c7350e0a468784da4035d7f64/analysis/1397057907/
IP:
China Telecomcenter
http://70.39.189.232/
  • https://www.virustotal.com/de/url/56f02705ec3f5dcf32c0f5b4d2f8371a514f2c2fb5c7f262b370c120e1171654/analysis/1398260122/ 
  • https://www.virustotal.com/de/ip-address/70.39.189.232/information/

REDIRECTS TO: --------------->  
(Reference See: http://wepawet.iseclab.org/view.php?hash=18cf2248ff8c66c0e25f36c34fc849d7&t=1392066256&type=js)

DOMAIN 2:
China Telecom Zhejiang
http://js.realypay.com/
  • https://www.virustotal.com/de/url/fe243629b072a3fbc0a2441bcbe6f47c5485ca2c5308e1d30e1623f2dc30bf82/analysis/1398261500/ 
REDIRECT LINK:
http://js.realypay.com/index2.js?ref=&url=http%3A%2F%2Fwww.billingcheckout.com%2Frisk%2Findex.js&w=1024&h=768&lx=IE7.0&auth=f2d9Pqacl20tqeAAq2ALsY7pxonRQq9w8T6J01rfr%2FNt98aDqte65aV%2FexcKt9mKFUYD3undAMCB   
  • https://www.virustotal.com/de/url/e717239f9c1ed65c250f8d024290d0f4605ba37a744495925135c67e970f5c7e/analysis/1398261822/
  • https://www.virustotal.com/de/file/0d23d902baf9638276780afdb9df44a26b748f775a350e1606b9472febee964f/analysis/1398261736/ 
IP:
China Telecom Zhejiang
http://122.225.38.53/
  • https://www.virustotal.com/de/url/5510f55d0eb200ce7673e5d94310cd473316d970a7d098c9c0df2541890b6fd6/analysis/1398262349/
  • https://www.virustotal.com/de/file/282c12070ea3254e26761b3dc58a7f342ac7e9f4c3b1f1630cf4d5c96bfce7de/analysis/1398262288/
  • https://www.virustotal.com/de/ip-address/122.225.38.53/information/

Keine Kommentare:

Kommentar veröffentlichen