Translate

Posts mit dem Label Category SUSPICIOUS DOMAIN werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Category SUSPICIOUS DOMAIN werden angezeigt. Alle Posts anzeigen

3/03/2014

POTENTIALLY MALICIOUS DOMAIN: danaearhartlitif.discovermangosteen.com & descubramangostan.com
Hex Obfuscation of document.write % Encoding

(UNITED STATES)


SUSPICIOUS/MALICIOUS DOMAIN: 
Obfuscation of document.write % Encoding

DOMAIN:
http://danaearhartlitif.discovermangosteen.com/
  • https://www.virustotal.com/de/url/8d60d054384c8961ee45cbb34bc5f3d41c16aaefec0af1223c9a3c7f1dc5b7ef/analysis/1393851554/
http://danaearhartlitif.discovermangosteen.com/goland3
  • https://www.virustotal.com/de/url/61d343cfbb29a32d27a54489b3d7f887164d7f2bda2d2c01bd0fc2c6ed80db07/analysis/1393844797/
  • https://urlquery.net/report.php?id=9750352
Obfuscation of document.write % Encoding 
(SEE: http://jsunpack.jeek.org/?report=655d39915efe7e0ad9d7598684efabb10ede91ff )
http://www.discovermangosteen.com/preenroll.php?uname=danaearhartlitif&nopop=&er=1&firstname=&lastname=&firstin=1&email=&phonenumber=&promocode=goland3
  • https://www.virustotal.com/de/url/2328a244e313f7d2586c5a74cabc5508ca1124ec5046917f8672e0665ef14ef0/analysis/1393846412/
  • https://urlquery.net/report.php?id=9750525
LISTED AT hpHosts:
  • http://hosts-file.net/?s=discovermangosteen.com
FULL REPORT:


Document hosting: UploadEdit.com


1/26/2014

www.onsitepctech.com.au
CVE-NO-MATCH Shellcode Engine Binary Threshold
(Potentially Malicious Domain from AUSTRALIA)






POTENTIALLY MALICIOUS DOMAIN:

www.onsitepctech.com.au
  • https://www.virustotal.com/de/url/0e29adcc5201def1c348c16d0be739c7b71392e612d9a9eb2f7055d5edadba5a/analysis/
suspicious: Warning detected /warning CVE-NO-MATCH Shellcode Engine Binary Threshold
suspicious: shellcode of length 4517/2725
suspicious: shellcode of length 388/227
suspicious: shellcode of length 140/102
suspicious: shellcode of length 2244/1348
suspicious: shellcode of length 138/100
suspicious: shellcode of length 363/287
suspicious: shellcode of length 2215/1319
suspicious: shellcode of length 73/45
suspicious: shellcode of length 167/129
suspicious: shellcode of length 1351/802
suspicious: shellcode of length 58/41
suspicious: shellcode of length 1352/803
suspicious: shellcode of length 2217/1321
suspicious: shellcode of length 526/412
suspicious: shellcode of length 2213/1317
suspicious: shellcode of length 856/509
suspicious: shellcode of length 844/502
suspicious: shellcode of length 6757/4069
suspicious: shellcode of length 75/54

  • http://jsunpack.jeek.org/?report=45d570fdee9ba93122369874ac25a35eccfa39a7

1/21/2014

www.scalesexpress.com (United Kingdom)
POTENTIALLY SUSPICIOUS DOMAIN
Microsoft Internet Explorer remote code execution via option element






POTENTIALLY SUSPICIOUS DOMAIN:

Microsoft Internet Explorer remote code execution via option element
www.scalesexpress.com
  • https://www.virustotal.com/de/url/48d23059451f6289a371b36f14ae5a7dd254d945ba32294d67ef8f2dd8ab44ac/analysis/1390310938/
  • https://urlquery.net/report.php?id=8877127
  • https://urlquery.net/report.php?id=7605847
  • https://urlquery.net/report.php?id=7870025
  • https://urlquery.net/report.php?id=8182437
---------------------------------------------------------------------------------------------------------------------------------------------

MORE ABOUT THIS SPECIFIC THREAT:
http://www.iss.net/security_center/reference/vuln/HTML_IE_Option_Uaf.htm 

1/14/2014

thecutekid.com
Potentially Suspicious Domain
(SPAM / SCAM)

Damaging Children

Potentially Suspious Domain
thecutekid.com
  • https://www.virustotal.com/de/url/6b1f6ada03f1f47740f47c4ea37ed35f3236d409323c4cac3d163ca10280678f/analysis/1389651026/
HTML (W32.HfsIframe.30a4 ?)
  • https://www.virustotal.com/de/file/82c0d8c44d0005315a8018e35cb8471ff8a530e4cfc3a1390c4fdc05f805818c/analysis/1389687845/
  • http://jsunpack.jeek.org/?report=75070cd01e0962fd47bf0e38d199e43e6acb2198
  • https://urlquery.net/report.php?id=8801837
LISTED AT hpHosts:
  • http://hosts-file.net/?s=thecutekid.com
  • https://www.mywot.com/en/scorecard/thecutekid.com
  • http://quttera.com/detailed_report/thecutekid.com
-------------------------------------------------
thecutekid.com/submit-a-photo1.php
  • https://www.virustotal.com/de/url/eba120adfb41c986d3733a97b61933417dc0aacc8ce773d1e983b5234bc83294/analysis/1389689158/
HTML (W32.HfsIframe.B090 ?)
  • https://www.virustotal.com/de/file/b4f47b55ea1c6cbaa65285d094be59210a8dd32fef657cd58a8d4a9276763b26/analysis/1389688921/
-------------------------------------------------
thecutekid.com/ckgallery/registration/upload/valentines-2014
  • https://www.virustotal.com/de/url/6cbdae817f595da871ff09ed54cd4e7caf1e0860ab50371181b4b6900b447613/analysis/1389689431/
HTML (W32.HfsIframe.95ab ?)
  • https://www.virustotal.com/de/file/d05503ceea41ba7dc954689e523afb932347611d1a8862c6b23faede9e0005c4/analysis/1389689350/
-------------------------------------------------
exclusives.thecutekid.com/submit-a-photo1.php
  • https://www.virustotal.com/de/url/1bf25802687d7f92e9d82d3e2c9d750f7f86804efc4dec6d8a5f38692359120a/analysis/1389689745/
HTML (W32.HfsIframe.B090 ?)
  • https://www.virustotal.com/de/file/b4f47b55ea1c6cbaa65285d094be59210a8dd32fef657cd58a8d4a9276763b26/analysis/1389688921/
-------------------------------------------------
HIDDEN IFRAME TO:
pixel.fetchback.com/serve/fb/pdj?cat=&name=landing&sid=4603
  • https://www.virustotal.com/de/url/c0299f678cfbe071efdce06de8716f9af719e4b9cc81cc6aa8beb1691ffb2d64/analysis/1389690132/
HTML (W32.HfsIframe.196a ?)
  • https://www.virustotal.com/de/file/f142e133db63f657e74e44fff8cf9636ad6a9c05312a76624ad60c66617b25d4/analysis/1389689927/
  • http://www.UnmaskParasites.com/security-report/?page=thecutekid.com
  • http://jsunpack.jeek.org/?report=44a2a6faf18a68ad446179943feaa3021c27a5fa