Translate

Posts mit dem Label Blackhat SEO werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Blackhat SEO werden angezeigt. Alle Posts anzeigen

12/29/2013

www.unverschmiert-bs.ch - SPAM SEO (VIAGRA, CIALIS & Co.) -
Malicious Domain

MALICIOUS DOMAIN (2nd TIME): TDS URL pattern & More (SEO SPAM (BLACKHAT))

Swiss Employees, unknown that their (GOOD) (WEB-)Site has been compromised

www.unverschmiert-bs.ch
  • https://www.virustotal.com/de/url/6cba18350b1119bd06ead9d1d67d4486c450507bc39a9213ad627364b633746e/analysis/
www.unverschmiert-bs.ch/internetapotheke-cialis.html
  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/
TDS URL pattern & More
  • https://urlquery.net/report.php?id=8611512
--->
keycollector.pw
  • https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1388348713/
keycollector.pw/go.php?sid=1
  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1388348762/
--->
edapotek.eu
  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1388348958/
edapotek.eu/order-cialis-online-en.html
  • https://www.virustotal.com/de/url/92f52a030e39a0a2ea0c2835e38fe61ea4ec1a561e4338be10629f8a458962af/analysis/1388348926/
  • https://www.google.com/search?client=opera&q="viagra"+site%3Awww.unverschmiert-bs.ch&sourceid=opera&ie=UTF-8&oe=UTF-8

12/28/2013

Malicious Site: romhc.org.uk - Blackhat SEO Spam - Rogue Applications etc. SCAM, PHISHING

BLACKHAT SEO SPAM - TDS URL pattern - RBN 434
https://www.google.com/search?q=%22Cheap%20Vista%20for%20Students%22%20site%3Aromhc.org.uk#q=%22Adobe%22+site%3Aromhc.org.uk


DOMAIN:
romhc.org.uk
  • https://www.virustotal.com/de/url/fdf4cf336eedca039caf6ff3fed712e937f006b214e15ea7b69152e1e0c3315a/analysis/1388235750/
  • https://urlquery.net/report.php?id=8582533
romhc.org.uk/index.php?q=adobe-web-premium-student-discount
  • https://www.virustotal.com/de/url/929018858465569e78df15ed77e8ce8ef42f487a76e99e7f3ac43d79db3a3573/analysis/1388222771/
  • https://urlquery.net/report.php?id=8582530
--->
keycollector.pw
  • https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1388235992/
keycollector.pw/go.php?sid=1
  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1388236011/

--->
qualisoft.biz
  • https://www.virustotal.com/de/url/27091106895406579538ebe33e76cccf4bd476210f3229c77669af925b050388/analysis/1388236240/
--->
euxzqvcxgbirbtra.qualisoft.biz
  • https://www.virustotal.com/de/url/a7d545757276ed198bb6efc694ff44c82105b43c8a5581190ee2cb582ecafcf1/analysis/1388236376/
---------------------

IP romhc.org.uk: 74.220.207.77
  • https://www.virustotal.com/de/url/acc2a6be4299a171f54c7de4da8ff07c1836e88f52a6166bc3401dcdeed70327/analysis/1388236607/
  • https://www.virustotal.com/de/ip-address/74.220.207.77/information/

12/25/2013

Malicious Site: www.itv-h.nl - Blackhat SEO Rogue Medications SCAM, SPAM, PHISHING

BLACKHAT SEO SPAM (Viagra, Cialis & co.) (TDS URL PATTERN)
https://www.google.com/search?q=%22Cheap%20Vista%20for%20Students%22%20site%3Awww.itv-h.nl#q=%22Viagra%22+site%3Awww.itv-h.nl



DOMAIN

www.itv-h.nl
https://www.virustotal.com/de/url/db0b7cacafa60e9af86d59ffd9cb50607746297dc4a696b44f90ebcd22166709/analysis/1387967753/

SPECIFIC URL:
www.itv-h.nl/viagra-kob.html
https://www.virustotal.com/de/url/dd8f10f702e672d1ec9dff469c0db539494b6dc782d80ec296d07f83782c4ee7/analysis/1387967607/

TDS URL PATTERN
https://urlquery.net/report.php?id=8541346

---> REMOTE DOMAIN
keycollector.pw
https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1386973287/

SPECIFIC URL:
keycollector.pw/go.php?sid=1
https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387967941/

TDS URL PATTERN
https://urlquery.net/report.php?id=8541376

--->
edapotek.eu
https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387967991/

12/16/2013

Deutsche Kentucky Fried Chicken Website (HESSEN) infiziert mit Blackhat SEO SPAM (PHISHING inklusive)

KOMPROMITTIERTE URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL PFAD - PHISHING


KFC Logo
URL:


www.kfc-hessen.de/viagra-fur-die-frau-online-kaufen

  • https://www.virustotal.com/de/url/fa0ce0aed0980ed05dc97032971980f4536b6c04fd66227e46b0b7605f962906/analysis/1387219444/



TDS URL PFAD
INDICATOR-COMPROMISE Suspicious .pw dns query



  • https://urlquery.net/report.php?id=8404039


---> TDS PFAD

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387220505/
  • https://urlquery.net/report.php?id=8404170

---> LEITET WEITER AN PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387220706/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.61.42.211

  • https://www.virustotal.com/de/url/14c84d8d823c8a2dd31c0dad9aaecd39a5bc6b183093196acf12ea1f2fb0c7c3/analysis/1387223113/
ENGLISH POST:

German Kentucky Fried Chicken Website Infected with Blackhat SEO SPAM (Phishing included)

MALICIOUS URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL pattern - PHISHING


KFC Logo
URL:


www.kfc-hessen.de/viagra-fur-die-frau-online-kaufen

  • https://www.virustotal.com/de/url/fa0ce0aed0980ed05dc97032971980f4536b6c04fd66227e46b0b7605f962906/analysis/1387219444/


TDS URL pattern
INDICATOR-COMPROMISE Suspicious .pw dns query



  • https://urlquery.net/report.php?id=8404039

---> TDS PATH

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387220505/
  • https://urlquery.net/report.php?id=8404170

---> TO PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387220706/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.61.42.211

  • https://www.virustotal.com/de/url/14c84d8d823c8a2dd31c0dad9aaecd39a5bc6b183093196acf12ea1f2fb0c7c3/analysis/1387223113/

Deutsches POSTING:
http://stayaway2.blogspot.com/2013/12/deutsche-kentucky-fried-chicken-website.html

12/15/2013

Malicious URL: www.ramada-friedrichroda.de - Rogue Medications
SCAM, SPAM, PHISHING

MALICIOUS URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL pattern - PHISHING



URL:

www.ramada-friedrichroda.de/apotheke-niederlande-cialis

  • https://www.virustotal.com/de/url/440d20e3414b328c712cd2b8f239eedcd4384017bb38147ca9892f6d456ce261/analysis/1387125985/

TDS URL pattern
INDICATOR-COMPROMISE Suspicious .pw dns query

  • https://urlquery.net/report.php?id=8396692

---> TDS PATH

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/b0059244125b4a42d4ed3fee193cf1c19300c7a4499f5cfe6e1d8b51c833796a/analysis/1387126405/
  • https://urlquery.net/report.php?id=8396782

---> TO PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387126466/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.152.215.126

  • https://www.virustotal.com/de/url/09f69d67216a170c75e9e24f1ce49a682e2af481d34c54948168b78daf829c85/analysis/1387127170/
  • https://www.virustotal.com/de/ip-address/5.152.215.126/information/

12/02/2013

United Kingdom: Governmental Website with Malicious Hidden Blackhat SEO SPAM revealed - www.kidwelly.gov.uk

Blackhat SEO SPAM (also defined as Spamdexing. Rogue Medications like Viagra, Cialis etc.) have been placed on a U.K. (.gov)-Domain has been identified, Phishing Risk included.

From Kidwelly Town Council to Ordering Viagra...
Analysis:

DOMAIN: www.kidwelly.gov.uk

https://www.virustotal.com/de/url/260c4e69c8b67d926d2dd35855943e73fc4686018563119216333e30f86fa065/analysis/1386001577/
Detection of a TDS URL pattern
www.kidwelly.gov.uk @ Urlquery 1
www.kidwelly.gov.uk @ Urlquery 2
---> Pattern 1
https://www.virustotal.com/de/url/108ea225a2cbc221f9a087fbcc49495921fa191d9fb0358385673df27b0a805d/analysis/1386002253/
https://www.virustotal.com/de/url/e66426cf99e99ffef07c60a6733e9bd3e28ea9531e0a8888651ed0a0ab6368a0/analysis/1386002281/
Detection of a TDS URL pattern
Reference 1
---> Pattern 2
https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1386002386/

Check This Link, there are several Links to find at Google (for now at least):

https://www.google.com/search?q=%22Viagra%22+site%3Awww.kidwelly.gov.uk&cad=h