Translate

Posts mit dem Label Blogger werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Blogger werden angezeigt. Alle Posts anzeigen

4/12/2014

Let US Welcome:
lunpandubishengfa.zhuolingxiu.com as a MALICIOUS VISITOR
(to this Blogspot)
FROM Beijing, CHINA & Walnut, UNITED STATES
IP: 110.173.196.1



MALICIOUS BLOGVISITOR FROM Beijing, CHINA
& Walnut, UNITED STATES

DOMAIN:
http://zhuolingxiu.com/
  • https://www.virustotal.com/de/url/b7d7f19c52b69e6721a7b9073741e7c6dc01f7bd4f3e04d9a95e150abb4ecb29/analysis/1397322523/
HTML:
  • https://www.virustotal.com/de/file/70624e295994c8b58995ea206a9d203bb56fad709b05ac972f053307a3399911/analysis/1397322837/
  • http://sitecheck2.sucuri.net/results/zhuolingxiu.com
IP:
http://110.173.196.1/
  • https://www.virustotal.com/de/url/ab6314d04650288df2d4054571208375f4606cdf8b09266e3427a91d2a6f8e62/analysis/1397323537/
  • https://www.virustotal.com/de/ip-address/110.173.196.1/information/
BHA: 3
  • https://www.projecthoneypot.org/ip_110.173.196.1
Fwd/Rev DNS Match: NO
  • http://www.senderbase.org/lookup/?search_string=110.173.196.1
MALICIOUS SUBDOMAIN:
http://lunpandubishengfa.zhuolingxiu.com/
  • https://www.virustotal.com/de/url/7481662efef095e53073ccc590585966f6b5c3f3c21d2364dc550ee577836b1f/analysis/
  • http://sitecheck2.sucuri.net/results/lunpandubishengfa.zhuolingxiu.com
  • http://www.urlvoid.com/scan/lunpandubishengfa.zhuolingxiu.com/
VISITING LINK:
http://lunpandubishengfa.zhuolingxiu.com/16024/
  • https://www.virustotal.com/de/url/df9f8d71cd3e8c7a80affdc3a9addb0964b0cae6355eddfabc316dbb74ef5e85/analysis/1397321793/
IP:
http://107.160.11.209/
  • https://www.virustotal.com/de/url/ab6314d04650288df2d4054571208375f4606cdf8b09266e3427a91d2a6f8e62/analysis/1397323537/
Network Owner: Psychz Networks
http://www.psychz.net/
  • https://www.virustotal.com/de/url/d1aaf5879110e18c64671ba2386ec1e8cb1e8c9144adb6dc9e1003003f67e814/analysis/1397325169/

COMMENT SPAMMER FROM BLOGGER TO BLOGGER:
Mr. Ams Patil Subject: AMS India from Bangalore
"I would like to recommend your article .. you can also refer PLC Repairs"
OR
"You for me and i for you..."




POTENTIALLY SUSPICIOUS/(MALICIOUS ?)
COMMENT SPAMMER TO THIS BLOG: 
Ams Patil - AMS India - Bangalore
COMMENT: I would like to recommend your article .. you can also refer PLC Repairs

SCREENSHOT COMMENT

 

The Related Post where the Comment has been made, can be found here:

PROFILE LINK:
  • http://www.blogger.com/profile/09937088204105970127
  • https://www.virustotal.com/de/url/4f98b161a5a79f4148538919dcdbc87664d9041df3094edc5d81b3ab1612d648/analysis/1397236254/


HTML
  • https://www.virustotal.com/de/file/f62eff5f017a92631ff39e8100874d1689b185fd096c5669427d46624968b1de/analysis/1397236179/
REDIRECTS TO:
  • https://plus.google.com/110974622069636956786
  • https://www.virustotal.com/de/url/8531cbb1b6af2c6970bd60b52f6743675ebad460b5e273a5d7c53a6cdfad1140/analysis/


HTML
  • https://www.virustotal.com/de/file/d4fc3dd86dfcbc77b810d9d3a4a38e220614f2da7ca2ff0dc8f805c12c9e1923/analysis/1397234501/
about:blank

----> THEN
  • http://plus.google.com/_/scs/apps-static/_/js/k%3Doz.home.en_US.QOoKRaOs7Pc.O/m%3Db%2Cprc/am%3DAMAwAAAMhEEAAAAKFICQAFITAwAACg/rt%3Dj/d%3D1/z%3Dzcms/rs%3DAItRSTPetjrOyteDRh4NktQaFVRe9zAjug
  • https://www.virustotal.com/de/url/bfd1e5160e4365a55b606d76d7a4a33de780bf93219d77014ca1684e9183283e/analysis/1397236576/
SEE AS WELL:
  • http://wepawet.iseclab.org/view.php?hash=fb5bb51b955f9532e7935ffe16a76969&t=1397234005&type=js

OTHER MALICIOUS CONNECTIONS (LINKS) FOUND:

1.0
http://jntukukatpally.blogspot.in/
  • https://www.virustotal.com/de/url/9349507e2076ab173d1ee3edbd50ec32d042f3373b6960bf3481a9d8de742b35/analysis/
http://jntukukatpally.blogspot.com/
  • https://www.virustotal.com/de/url/4c8dbd6ec2caf73b58643c14e2f5cbcc9673613d9293edcd99388332950b8b30/analysis/1397238392/
jntukukatpally links (directly OR indirectly) to:

1.1
http://resources.infolinks.com/js/infolinks_main.js
  • https://www.virustotal.com/de/url/30af8cab0ff04044433949f965963f0d0773bedb554811a276512b174ef219cd/analysis/
  • https://www.virustotal.com/de/file/58b308392779bb9868090be24ba4c3e6880efcdc7df43d2e90547ce0b9e9b957/analysis/1397238583/

2.0
http://driver-lap.blogspot.com/
  • https://www.virustotal.com/de/url/8b47e821ad5a463f2bcfa83228b7df55b0d2e7b860923bddc7158f7b30c4cf3a/analysis/1397238344/
driver-lap links (directly OR indirectly) to:

2.1
http://resources.infolinks.com/js/infolinks_main.js
  • https://www.virustotal.com/de/url/30af8cab0ff04044433949f965963f0d0773bedb554811a276512b174ef219cd/analysis/
  • https://www.virustotal.com/de/file/58b308392779bb9868090be24ba4c3e6880efcdc7df43d2e90547ce0b9e9b957/analysis/1397238583/
UPDATE 3/05/2014:

Ams Patil Made the same Comment on: Comment Spammer From BLOGGER TO BLOGGER:
RRRRRROOOOOOOOOFFFFFFLLLLLLL:

SEE SCREENSHOT: LLLLLLLLLLLLOOOOOOOOOOLLLLLLLL


2/20/2014

Rogue Software:
learntricksandtips.blogspot.com
(AV-SOFTWARE (ESET, DrWeb) + HIDDEN LINKS)
Suspicious-WI


Tipps & Rogue Tricks

POTENTIALLY MALICIOUS SITE: ROGUE SOFTWARE AV-SOFTWARE (ESET, DrWeb) (RBN 368) + HIDDEN LINKS
http://learntricksandtips.blogspot.com/
  • https://www.virustotal.com/de/url/d9ab0529b0d7f68df53f94932e3c82d329f31c3345441654a517a5e3253f9acb/analysis/
HTML
  • https://www.virustotal.com/de/file/9ee22b95344eb0eafbd33ae3e3e427c41d1ec79a1de2598832bb4c979503d905/analysis/1392918780/
Suspicious-WI
  • http://app.webinspector.com/public/reports/20206793

SEE ALSO:
  • https://urlquery.net/report.php?id=9552731
  • http://quttera.com/detailed_report/learntricksandtips.blogspot.com
  • http://sitecheck.sucuri.net/results/learntricksandtips.blogspot.com
  • http://www.UnmaskParasites.com/security-report/?page=learntricksandtips.blogspot.com