Translate

Posts mit dem Label SCAM Site werden angezeigt. Alle Posts anzeigen
Posts mit dem Label SCAM Site werden angezeigt. Alle Posts anzeigen

4/05/2014

pchelpsoft.com welcomes you with:
MALICIOUS DOWNLOADS (Win32/SpeedingUpMyPC) PLUS
HIDDEN IFRAMES
(IP: 107.6.189.44)
as well as a Bad Reputation
USA & FRANCE


FOR WEBMASTERS & BLOGGERS
If you own a Website or a Blog and are affiliated with Google AdSense, in order to your own Reputation, should block the Domain www.pchelpsoft.com in your AdSense Dashboard. The Site lets your Visitors download and install persistant ADWARE or other Malware like in this case a variant of Win32/SpeedingUpMyPC. See the following Report:


MALICIOUS ADvertiser & HIDDEN IFRAMES

Screenshot with only SOME of the detected Hidden IfRames

DOMAIN:
http://www.pchelpsoft.com/
  • https://www.virustotal.com/de/url/5c3edae4e373ca3e00b12d47e8cca063d95788ce51bf2231183583fb09c410fe/analysis/1396709017/
W32.HfsIframe
  • https://www.virustotal.com/de/file/5423ccf2d362c574dd92ee16048771654c0c147615e30969708287e823e86d14/analysis/
AD-LINK:
http://googleads.g.doubleclick.net/aclk?sa=l&ai=C_5YSLfY_U477Oaf97QbKlYCICo_WvewF95Pew5MBwI23ARABII7AlCNQ59rJ-fr_____AWC7A6AByYS85gPIAQGpArbIwK_Uja4-qAMByAPDBKoEhAFP0DaVh04U04otA5RC7LkKN6Bb_76Gi-a6KPMQvyX3m8F19ghuSsCTgBc7cUAPAstOz7czutL_m7MOzFOIkKzeFLZ3UN9ZUEOlz4xXwJPPBb5gK8G6YxHi-4h_mZg4uzJ7soJ9bRaeuP_OZ2MIq7zyOqfZY3eePfaxuKdr22MRIEQwDEuAB5_7wxk&num=1&sig=AOD64_3jGSApnWn_Emx9WI29PpLZtrEk6Q&client=ca-pub-5585202032329389&adurl=http://www.pchelpsoft.com/pc-cleaner/lp1-ms/%3Ftracking%3DPH_EN_PP_GO_CO_ROW_PCC%26keyword%3D%26campaignID%3DADWORDS&nm=39&mb=2&bg=!A0Q9TCHak0v0HwIAAABKUgAAADcqAOG1EZitqUzYO4cdHgIIvh0nlm7oDd0knPeZUrYknpQ3F5-tZmBmXeKSHkPmRrr_CHVhEUhzRoOlThSLBgrs5fJLBrB5bES3Cg3gSdBl8Q6gTAGIzXrrfFYMCH9BIYOWLOuS7dqRqWoHQHEer0wQaFUVg8VOCK9FOIlzVHnwhGYzDu54619Pr81rBHDv7mscitGvxqSMzZirAzqRJipFcOzj4t9u__q1EYkusciy23n30yN3jgPeP_Ps4igDQY2IWVDYlesicGJKIgCoclKMhqQuga9DgkcUZAewYWXsVZknShE

VT ANALYSIS:
  • https://www.virustotal.com/de/url/aaa0b4defa15863722a5a1f3a972cb1b5ae58782a51ee2ddf099479d13401a25/analysis/
W32.HfsIframe
  • https://www.virustotal.com/de/file/97297c8b5512bf9630a4785d5efc8b1fa8c0ed256a259f41f2e420dd7ab75f3f/analysis/
URL After Redirect:
http://www.pchelpsoft.com/pc-cleaner/lp1-ms/?tracking=PH_EN_PP_GO_CO_ROW_PCC&keyword=&campaignID=ADWORDS&gclid=COLyicasyb0CFcU-Mgod9WIAFg
  • https://www.virustotal.com/de/url/b812f343e219878f936a148c61d82ee7b868b62f126c33035034c30558cff252/analysis/
W32.HfsIframe
  • https://www.virustotal.com/de/file/33e518a1049cacd6ad92fcb4dc8cc4276a7def88a673ec8f8b6730169c874399/analysis/1396709347/
OTHER (MALICIOUS) LINK OF THIS DOMAIN:
http://webtools.pchelpsoft.com/download.cfm?tracking=PH_EN_PP_GO_CO_ROW_PCC&keyword=&campaignID=ADWORDS&gclid=CJi1oOCsyb0CFcx9OgodfGkAVg&go=http://cdn2.pchelpsoft.com/pch_downloads/pc-cleaner-3248.exe
  • https://www.virustotal.com/de/url/1ac047af6364f4d0b32c39cc39916c2f2c20126ac9084b34a8e37fc243575e3a/analysis/1396710143/
Win32/SpeedingUpMyPC
  • https://www.virustotal.com/de/file/61825b61802647f122a2faf60ed2b06d4d139939c2305f421557ba7aadeaca8d/analysis/1396709870/
---> REDIRECTION TO: (7 AV-FLAGS)
http://cdn2.pchelpsoft.com/pch_downloads/pc-cleaner-3248.exe
  • https://www.virustotal.com/de/url/695aac7dd7c803f95c1ff3fb22114a8c07710377c1f761360b4919703dde422d/analysis/
Win32/SpeedingUpMyPC
  • https://www.virustotal.com/de/file/61825b61802647f122a2faf60ed2b06d4d139939c2305f421557ba7aadeaca8d/analysis/1396709870/

SEE AS WELL:
Scam
Misleading claims or unethical
Poor customer experience

  • https://www.mywot.com/en/scorecard/pchelpsoft.com
LISTED AT HpHosts:
  • http://hosts-file.net/?s=pchelpsoft.com
IPs:
http://107.6.189.44/  (Chicago, U.S.A.)
  • https://www.virustotal.com/de/url/500ee0900e907eb3ec6ddfa941715422ba0d629117bd78a11abfc425e792f55a/analysis/1396710479/
  • https://www.virustotal.com/de/ip-address/107.6.189.44/information/

http://217.195.25.241/  (Le Pecq, FRANCE)
  • https://www.virustotal.com/de/url/2fcdb898c3033fa329006d6ad7a857426898b76c36d4031015e80c74b1bcdc0e/analysis/1396710659/
  • https://www.virustotal.com/de/ip-address/217.195.25.241/information/

http://205.251.253.160/  (Seattle, U.S.A.)
  • https://www.virustotal.com/de/url/69651f27754573792bde992f0a5bdbb08107d6477da0e85a9f383504ced67cad/analysis/1396710819/
  • https://www.virustotal.com/de/ip-address/205.251.253.160/information/
BHA: 3
  • https://www.projecthoneypot.org/ip_205.251.253.160

3/29/2014

Just another Spam, from...
www.ratgeberplatz.com:
„Ihre Bewerbung. Ihr Gehalt: bis zu 300 Euro täglich!
(Da müsste ich doch längst Millionär sein bei all diesen Bewerbungen...)“
(„Your application for employment“)

from Australia & Germany (IP: 14.2.24.1)

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM-Screenshot from....ratgeberplatz.com

Guten Tag,
Sie wurden ausgewählt! Wir stellen Ihnen jetzt exklusiv Wissen zur Verfügung für Ihren neuen Nebenjob. Ihr Gehalt: bis zu 300 Euro täglich!

Nach Ihrer kostenlosen Anmeldung erhalten Sie sofort gratis Wissen und können starten.

Hier klicken:
http://mailings.ratgeberplatz.com/tracker.php

Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.


IN THIS CASE THE ORIGINATING IP ADRESS IS:
14.2.24.1   (Australia)
  • https://www.virustotal.com/de/url/6671096f3f434b58d889520e044498210faf3944dae80d8a5a084fd47ee0e3a6/analysis/1396003406/
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=14.02.24.01
Second IP:
83.136.83.241   (Germany)
  • https://www.virustotal.com/de/url/248549c14fcab8bb31ebba0e20bc506f52d4070c0eb6fe42fbb7a48ab258dca9/analysis/1396118848/
THAT IS ALSO THE REASON WHY THIS POST (DOMAIN www.ereatvipgame.la) IS CONNECTED TO ratgeberplatz.com, as they use the same SPAM Server:

http://stayaway2.blogspot.com/2014/03/phishing-spam-from-wwwereatvipgamela-in.html

DIES IST DER GRUND WIESO ratgeberplatz.com mit involviert ist im folgenden POST (Casino-Phishing www.ereatvipgame.la) da sie beide die gleiche SPAMSERVER-IP-Adresse nutzen:

http://stayaway2.blogspot.com/2014/03/phishing-spam-from-wwwereatvipgamela-in.html

3/18/2014

Just another Spam, from...
www.ratgeberplatz.com:
„2014 Träume erreichen - Eine schuldenfreie Zukunft“
(„Make your Dreams come true in 2014 - Your Future out of dept“)

from Australia & Germany

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

  


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel:

IN THIS CASE THE ORIGINATING IP ADRESS IS:
14.02.15.21 (AUSTRALIA)
AS4739 Internode Pty Ltd

  • https://www.virustotal.com/de/url/a60f76f2fa705159fd37cafe947fa4e01681ae42ecc3b80554695bcc238a8fd9/analysis/1395151319/

3/14/2014

Just another Spam, from...
www.ratgeberplatz.com:
„15 Euro Gutschein bei BAUR sichern“
(„Get your 15 Euro Voucher from BAUR, Just like that!“)

from Germany

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:



Just another SPAM SCREENSHOT from ratgeberplatz.com...


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel:

Interessenten können auch diesen Artikel lesen:
http://www.it-recht-kanzlei.de/abmahnung-unverlangt-zugesandter-email-newsletter.html 

3/07/2014

Link of the Moment (Best of the Web since 2008 - ratgeberplatz (SPAM/SCAM/PHISH)



Link of the Moment can be found here:
http://stayaway2.blogspot.com/2014/01/just-another-spam-from.html

MALICIOUS Visitor to THIS Blog:
www.helptool.co.uk (IP: 74.119.233.25)
SCAM/SPAM/PHISHING
Microsoft Internet Explorer remote code execution via option element
UNITED STATES


POTENTIALLY MALICIOUS 
(SPAM/SCAM/PHISH) DOMAIN:
Microsoft Internet Explorer remote code execution via option element


VISITING DOMAIN:
http://www.helptool.co.uk/
https://www.virustotal.com/de/url/ac74ead641b92d866114b1be1f06dd82013e72a80560ecd1f2357b65b2f072e3/analysis/1394194891/

Microsoft Internet Explorer remote code execution via option element
  • https://urlquery.net/report.php?id=9809294
  • https://urlquery.net/report.php?id=9809290
  • https://urlquery.net/report.php?id=9809296
  • https://urlquery.net/report.php?id=9809291

SPECIFIC VISITING LINK:
http://www.helptool.co.uk/monogram-empreinte-wallets.html
  • https://www.virustotal.com/de/url/e0b9d0118bf9302ea8cc2757944df40f923aa75700f0dd6ce12fdc36eece362b/analysis/1394194885/
Microsoft Internet Explorer remote code execution via option element
  • https://urlquery.net/report.php?id=9809297
  • https://urlquery.net/report.php?id=9809298
--->
http://www.realypay-checkout.com/risk/index.js
  • https://www.virustotal.com/de/url/918164e05db230153e1e0d41bbcf1a4d41a569ff91ca63883bb8e24fd7067484/analysis/
  • https://www.virustotal.com/de/file/dcd00dcc6e406be2b2b271abbbf16a59d7efb76a1942e74b2cad5d2e9f8f5938/analysis/1393880237/
  • http://threatlog.com/search/realypay-checkout.com/domain/
  • https://www.mywot.com/en/scorecard/realypay-checkout.com
--->
http://www.mallpayment.com/risk/index.js
  • https://www.virustotal.com/de/url/e1a3b4508777564232d8ef062eb682a3e236bc997af4338a20cd8d46f423e346/analysis/1394196268/
  • https://www.virustotal.com/de/file/91ef2b7aa8e485fe44e489e0ae574d00552af458200ec03e0373863f5f060a40/analysis/1394196273/
--->
http://pcookie.cnzz.com/app.gif?&cna=SqigC3Hpk2oCAYBvMAyTGMVT
  • https://www.virustotal.com/de/url/b56a92a571d24fb7480aed4f263678c886a3f3f6981a4f5809a0d2daedf7d7f3/analysis/1394196462/
  • https://www.virustotal.com/de/file/cf4724b2f736ed1a0ae6bc28f1ead963d9cd2c1fd87b6ef32e7799fc1c5c8bda/analysis/1393805553/

1/26/2014

MALICIOUS SITE: rukiyehayran.com
(PHISHING, MALWARE, SCAM, SEO SPAM)
TURKEY (Rogue Medications - Zymbiotix)


MALICIOUS SITE: PHISHING, MALWARE, SCAM, SEO SPAM (Zymbiotix Cleanse)

"Are you sure you don\'t want to take advantage of the Garcinia Cambogia offer?\n\nDon\'t forget - it will only be available for a LIMITED TIME.

Since this offer is so cheap, there is no risk to you. You can also give them away if you\'d like. Or give it a shot, and get Garcinia Cambogia.\n\nIf you are wondering why this offer is so cheap, the simple answer is because the manufacturer is confident that their products will help you, and that you will continue to use their products, and refer friends and family.

Celebrities like Kim Kardashian and Britney Spears have lost a
signifcant amount of body fat with just these 2 diet cleanses. The duo
cleanse is clinically proven to flush out all the junk in your body and
melt away body fat without harming your immune system. Keep reading and
you'll find out why we created this report."

DOMAIN:
rukiyehayran.com
  • https://www.virustotal.com/de/url/2f6ab6c39c5b436e410ec66f2f62be5d8f1156c38b48b63c8d5062128605e9f2/analysis/1390758337/

HTML
  • https://www.virustotal.com/de/file/1f1218e4661f525ee1fcd70a043b7c0a3709ab33b39af313ffec819f59e24ffa/analysis/1390751239/


LINK 2
rukiyehayran.com/likeit.php
  • https://www.virustotal.com/de/url/6ebf42c21c420e1b2d377bbd335ed3b3317373a895c8e29566deb40650e4bfe3/analysis/

HTML
  • https://www.virustotal.com/de/file/70c6546a370ccedbdbf101bfd0124adc537fc4cccb7c022a0300071c3f09afcd/analysis/
  • http://jsunpack.jeek.org/dec/getfile?hash=3585/7a7fe26eb28c4a47ccd31474b3944cefef41
  

LINK 3 (SPECIFIC)
rukiyehayran.com/likeit.php?nwqmqztem1151qapb
  • https://www.virustotal.com/de/url/9f589ceabb55b17f43769500f860b201ff60715e36bff0cc6422728b93b92232/analysis/1390758346/

HTML
  • https://www.virustotal.com/de/file/70c6546a370ccedbdbf101bfd0124adc537fc4cccb7c022a0300071c3f09afcd/analysis/

POSSIBLE ORIGINATING IP ADRESS: 108.166.43.117

Screenshot of E-Mail Scam from rukiyehayran.com