Translate

Posts mit dem Label Category SEO Spam werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Category SEO Spam werden angezeigt. Alle Posts anzeigen

4/15/2014

www.ensemble-berlin.de
infected with SEO SPAM (Viagra & Co.)
ROGUE MEDICATIONS PHISHING
IP: 80.67.31.164 & 5.61.42.211
GERMANY



MALICIOUS RUSSIAN PILLS PHISHING URL:
TDS URL pattern
http://www.ensemble-berlin.de/
  • https://www.virustotal.com/de/url/fa621d60d52c535f849c29fe9327a46e2248dedcc24fbe3ccf58388cad5c5c85/analysis/1397567841/
http://www.ensemble-berlin.de/viagra-rezeptfrei-lander.html
  • https://www.virustotal.com/de/url/c516b883ef52e0fef2b2884bcad2b97ecb7db4c9cd1037a847e1d082523cc5a7/analysis/1397566470/
TDS URL pattern
  • https://urlquery.net/report.php?id=1397566888166

  • https://urlquery.net/report.php?id=1397566887262

  • https://urlquery.net/report.php?id=1397566892018
---->
http://tds.cigarettescheap.net/
  • https://www.virustotal.com/de/url/108ea225a2cbc221f9a087fbcc49495921fa191d9fb0358385673df27b0a805d/analysis/1397567431/
TDS URL pattern
  • https://urlquery.net/report.php?id=1397567579389
----->
http://apharmshop.com/
  • https://www.virustotal.com/de/url/a0cf825561616bba65374be8a7b676cbfeb2964a47b08a7a566c186b4d511158/analysis/1397567650/
------>
http://edapotek.eu/
  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1397567302/

3/30/2014

Real Comment Number 1 on COMMENT SPAM !
Michael Burning: "My homepage :: Mike Burns......
KEY COMMENT: "is a enormous source of facts"

This Post is (and will be & stay) to demonstrate what SPAM IN BLOGS (Comment SPAM) IS about and how you should difference it ! From this part it is surveilled, and followed. IP-Data and Domains who are involved are being recorded, to monitor the frequency and analyzing the connections given to it. In case suspicious Connections (related to Phishing, Spambots (what they already are), and other fraudulent activities and/or behaviour) will (not only) be recorded and transfered to the appropriate agencies (i.e. IC3) what however is done anyway. Special observations from outside can be adressed to me through IC3. 

Reminder: However, every SPAM-Post is delivered to the appropriate Adress. Keep following.
-------------------------------------------------------------------------------------------------------------------------------------------

STARTER IS (Number One):

Hi there, its pleasant article concerning media print, we all be familiar with media is a enormous source of facts.

My homepage :: Mike Burns
SPAM COMMENT MADE ON FOLLOWING POST:

http://stayaway2.blogspot.com/2013/12/malicious-site-romhcorguk-blackhat-seo.html

Screenshot Michael Burning

PERSONAL OPINION BEHALF MYSIDE:
Is Michael Burning with Cola ? Or with a Cool Aid ?


3/06/2014

Category MALICIOUS IP: 72.8.190.39 (ezuvekury.tk)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES) HTML:RedirME-inf [Trj]

The IP address 72.8.190.39 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "ezuvekury.tk", and this link is an example of the redirect: "http://ezuvekury.tk?q". In other words the website "ezuvekury.tk" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.


In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "ezuvekury.tk" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly ezuvekury.tk itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.


REFERENCES:
72.8.190.39
  • https://www.virustotal.com/de/url/d402ba3e37849bfcab82b8de74d860729defcf62cbe3244ed2aa7e62d6fc1fbd/analysis/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=72.8.190.39
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=72.8.190.39
--------------------------------------------------------
 
MALICIOUS SITE & IP: SPAMBOT PHISHING (VIAGRA & CO.)
 

http://ezuvekury.tk/
https://www.virustotal.com/de/url/c1fbcded30036142e1f72bb0c2e51b02f82143cfe1a203d8a0c696cf0c569259/analysis/1394109439/
HTML
https://www.virustotal.com/de/file/b4bc40d341c4ba868d0b4c350c16e45255a3ef0228f5559a7083fb903717ee5f/analysis/1394110104/


http://ezuvekury.tk/?q
https://www.virustotal.com/de/url/2c7095e8f7ce859b887a11de197516a0967f6e82c43a263f356c7609590bb499/analysis/1394109442/
 

HTML
https://www.virustotal.com/de/file/0191d7cb7b3f637aa74fceb86c5c6575b2b08e0765ca2da8635b1c7ea9538a28/analysis/1394110251/
 

--->

http://csbakhita.com/unsurpassable.html
https://www.virustotal.com/de/url/ea34f52e3fd906449af0c3be62218acd913bafb820752a841887a83baa97a854/analysis/1394110601/


HTML:RedirME-inf [Trj]
https://www.virustotal.com/de/file/983395c456d29de19308294e8a2e9de64ca643fa93d1005114d1fece45c7d1bd/analysis/1394110385/
 

---->

http://rx69.ru/
https://www.virustotal.com/de/url/afcb00221df516d2d5a6f95163ab18e3cdc7984103981f9aa20f9ca0995a2e96/analysis/1394111089/
 

HTMLs
https://www.virustotal.com/de/file/e579b048df4b4306705de79a4ff523b0c84f31e723449609c62026bb86020726/analysis/1394110754/
https://www.virustotal.com/de/file/5515e3e32b05d79f21752af75eca9eaa8150097d5280a08b2f017bcafd6fb94e/analysis/1394110741/
 

---->

http://www.doctortern.ru/
https://www.virustotal.com/de/url/d2ebc69875257b228bc3f76ebe89afd30249e66674f63bac247f90d6546bc842/analysis/1394111231/

 

 

3/04/2014

MALWARE-SPAM from Levitra (PHISHING):
variographics.de - keydiscover.pw - edapotek.eu
(GERMANY) (Rogue Medications) KAUFEN, KAUFEN, KAUFEN




MALWARE-SPAM: TDS PATTERN (sid) SEO SPAM

COMPROISED DOMAIN:
http://www.variographics.de/
  • https://www.virustotal.com/de/url/826914f71c772081a4006a4b8d4a0052e94516f5fd367fa9e2664a6f43ab1d61/analysis/1393897768/
MALICIOUS URL:
http://www.variographics.de/levitra-generika-europa-kaufen
  • https://www.virustotal.com/de/url/4fdef3349ed2cc0f01d33729e0a98343d598ec47357eb19349b80c4753566085/analysis/1393896321/
SimpleTDS (go.php)
  • https://urlquery.net/report.php?id=9761299
--->
http://keydiscover.pw/
  • https://www.virustotal.com/de/url/79c16dc3063a395db04e63cc452803dc5dd7f20272f919868c31c31f462c301c/analysis/1393898631/
---->
http://edapotek.eu/
  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1393898671/


2/28/2014

Category MALICIOUS IP: 68.178.254.121 (www.bonsaihacker.com)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES)

The IP address 68.178.254.121 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "www.bonsaihacker.com", and this link is an example of the redirect: "http://www.bonsaihacker.com/infantile.htm?vixe". In other words the website "www.bonsaihacker.com" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.


In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "www.bonsaihacker.com" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly www.bonsaihacker.com itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.

REFERENCES:
68.178.254.121
  • https://www.virustotal.com/de/url/66dfd5856d9fd790189a5f8242c3eb4828b0e02c4e5a3932610e225e9d30e2be/analysis/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=68.178.254.121
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=68.178.254.121

FULL REPORT:


Document hosting: UploadEdit.com

Category MALICIOUS IP: 67.225.146.147 (wpnoupfront.authenticbd.com)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES & RUSSIAN FEDERATION)

The IP address 67.225.146.147 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "wpnoupfront.authenticbd.com", and this link is an example of the redirect: "http://wpnoupfront.authenticbd.com/invigorating.htm". In other words the website "wpnoupfront.authenticbd.com" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.

No Time to lay back...
In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "wpnoupfront.authenticbd.com" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly http://wpnoupfront.authenticbd.com itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.

Related Post: http://stayaway2.blogspot.com/2014/02/us-phishing-visitor-to-this-blog.html

REFERENCES:
67.225.146.147
  • https://www.virustotal.com/de/url/30de5a071652e44f8f6003ab0c22553e72808bfec8aa5982ae23fb7badde4857/analysis/1393510660/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=67.225.146.147
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=67.225.146.147
----------------------------------------------------------

http://wpnoupfront.authenticbd.com/
  • https://www.virustotal.com/de/url/1fb32860105dea70846f611020d9ba6c2a4557c5337ded5e1dcbe83b51b9641d/analysis/1393517602/
  • http://urlquery.net/report.php?id=9691230
http://wpnoupfront.authenticbd.com/invigorating.htm
  • https://www.virustotal.com/de/url/071ca9f4199a95b2d2824d0207e8c6287c20458ad1f87b80ac37a9a36ec2de9b/analysis/1393517601/
HTML:RedirME-inf [Trj]
  • https://www.virustotal.com/de/file/5f0925c559ea8e1285877f550f361a92770d54528f8800ab181bdc1a0c039427/analysis/1393520355/
  • (GETFILE: http://jsunpack.jeek.org/dec/getfile?hash=8ff9/ed8ea2a207c8f4ae5c70dac68556d6ff425a)
---> REDIRECTS TO
http://doctorxonft.ru/
  • https://www.virustotal.com/de/url/0512b24fcc96129c9951e4f5103bfed2312c9fe359403ed3a6ec36e6ced2e962/analysis/
HTML (PUA.JS.Obfus-7)
  • https://www.virustotal.com/de/file/8aad19003d4937d93cf60ff7f8457c231e4b72110d380a4c6a2e133b1e169fae/analysis/1393521420/
  • http://virusscan.jotti.org/de/scanresult/baf1b8fc0d963713dd61f1f9549226321e068189

FULL REPORT:
Document hosting: UploadEdit.com

2/22/2014

Compromised Website:
fresh-vital-drink.de
(SEO SPAM, VIAGRA & CO., ROGUE MEDS)
GERMANY SimpleTDS





Compromised Website: SimpleTDS go.php (sid)
http://www.fresh-vital-drink.de/
  • https://www.virustotal.com/de/url/bc0e1cc2bd28f61cde38cdada7a67d0d6a73daaf46b605eb3a7fe9ff0a93edc1/analysis/1393083183/
http://www.fresh-vital-drink.de/levitra-grossen.html
  • https://www.virustotal.com/de/url/16ab17043771a2dd113ade0718e5f41cef0e99b6ce0a64f055304e690b443dcd/analysis/1393083158/
  • https://urlquery.net/report.php?id=9584003
  • https://urlquery.net/report.php?id=9584007
  • https://urlquery.net/report.php?id=9584005

2/19/2014

kidron.oh.us.mennonite.net
SEO SPAM (Cigarettes)
Simple TDS URL Pattern (Germany & Goshen, Indiana, U.S.A.)
IP: 198.51.243.90



MALICIOUS: PHISHING URL
(Germany & Goshen, Indiana, U.S.A.)


TDS URL pattern

DOMAIN:

http://kidron.oh.us.mennonite.net/
  • https://www.virustotal.com/de/url/53747d933ebf776f1245f20e825c9e4417df556835c2dc75d4f9272cd893a307/analysis/1392820035/

MALICIOUS URL:

http://kidron.oh.us.mennonite.net/buy-cigarettes-license
  • https://www.virustotal.com/de/url/0e57417d97e949ee814a6a75b7e6e8d0b8b32bd8740b6355ad71cd935740c537/analysis/1392819470/
W32.HfsIframe.448b
  • https://www.virustotal.com/de/file/f05a3ff1fabe7871c9e5bbc54b491243d3bafc95dcb189bf6b5fe8e576e5987f/analysis/1392820241/
TDS URL pattern
  • https://urlquery.net/report.php?id=9530534
FULL REPORT:
Document hosting: UploadEdit.com



2/01/2014

www.visonic.com & www.visonictech.com &
www.dhtml-menu-builder.com & elpas.com

MALICIOUS DOMAINS INFECTED (Directly or Indirectly)
BV:StartPage-FY [Trojan]

visionic.com

MALICIOUS DOMAIN: HIDDEN LINK & BV:StartPage-FY [Trojan]
www.visonic.com
  • https://www.virustotal.com/de/url/f78e05cce3d42b2e2af2d9b77e333ddf02f255b3bcdf3633a2b4301fe7cfaf73/analysis/1391264633/
HTML
  • https://www.virustotal.com/de/file/e351123b15e39ce42e458fe0ce173a3dae67e6d2e332583eee0b4542a8a0ebc4/analysis/1391264778/
  • http://www.UnmaskParasites.com/security-report/?page=www.visonic.com
www.visonictech.com ---> redirects to elpas.com


HIDDEN LINK TO:
www.visonictech.com
  • https://www.virustotal.com/de/url/bb123e45066579186a9eee70d00a7314d58bb6dd707e8a810b26c94676152ae4/analysis/1391265169/
SPAM LINK (VIAGRA):
  • http://www.UnmaskParasites.com/security-report/?page=www.visonictech.com
dhtml-menu-builder.com

TO:
www.dhtml-menu-builder.com
  • https://www.virustotal.com/de/url/8067736540845fba3def863c89bc850f5ffb0a9d718793973034a7d79021121e/analysis/1391265583/
SPECIFIC MALICIOUS LINK:
www.dhtml-menu-builder.com/include/js/ie6-png.js
  • https://www.virustotal.com/de/url/8e1fbb8ba1b128744dbb94db5a9494af8e357ef88b047044cb261bae892d4128/analysis/1391266171/
INFECTED WITH: BV:StartPage-FY [Trj]
  • https://www.virustotal.com/de/file/66da12165f89ac7a2a330ed8d75288f3c3aeb98b3ce019c890ee1b06a3a48c6f/analysis/1391265996/
  • https://www.virustotal.com/de/file/c3504e6c4b8bf4c1f8bbb265bbdba23270ce5a593f124e38fe65214e4a4b88e2/analysis/1391266028/
REFERENCE & FILE(s):

  • http://jsunpack.jeek.org/?report=eb47e3a23a0f713fe37fb08bdc85ba42651ff26c
buysoftviagra.com

VIAGRA LINK:
buysoftviagra.com
  • https://www.virustotal.com/de/url/a71b8be18ba11c82b6dc425316a7b2c5d2e8766d2c198db755be4494e18d934d/analysis/1391265844/

AS WELL INVOLVED:
elpas.com
  • https://www.virustotal.com/de/url/eef5935a084f5ae84fa9ed3cc936df3531d37802cdef07a8fdc5b7f55e9d0dc4/analysis/1391266776/
  • SEE: http://jsunpack.jeek.org/?report=a8c2e01dc1da2d7ecd26be013ef04799379b3970
SEE ALSO:
  • http://sitecheck.sucuri.net/results/www.dhtml-menu-builder.com
  • http://sitecheck.sucuri.net/results/buysoftviagra.com
  • http://quttera.com/detailed_report/www.visonictech.com


1/26/2014

MALICIOUS SITE: rukiyehayran.com
(PHISHING, MALWARE, SCAM, SEO SPAM)
TURKEY (Rogue Medications - Zymbiotix)


MALICIOUS SITE: PHISHING, MALWARE, SCAM, SEO SPAM (Zymbiotix Cleanse)

"Are you sure you don\'t want to take advantage of the Garcinia Cambogia offer?\n\nDon\'t forget - it will only be available for a LIMITED TIME.

Since this offer is so cheap, there is no risk to you. You can also give them away if you\'d like. Or give it a shot, and get Garcinia Cambogia.\n\nIf you are wondering why this offer is so cheap, the simple answer is because the manufacturer is confident that their products will help you, and that you will continue to use their products, and refer friends and family.

Celebrities like Kim Kardashian and Britney Spears have lost a
signifcant amount of body fat with just these 2 diet cleanses. The duo
cleanse is clinically proven to flush out all the junk in your body and
melt away body fat without harming your immune system. Keep reading and
you'll find out why we created this report."

DOMAIN:
rukiyehayran.com
  • https://www.virustotal.com/de/url/2f6ab6c39c5b436e410ec66f2f62be5d8f1156c38b48b63c8d5062128605e9f2/analysis/1390758337/

HTML
  • https://www.virustotal.com/de/file/1f1218e4661f525ee1fcd70a043b7c0a3709ab33b39af313ffec819f59e24ffa/analysis/1390751239/


LINK 2
rukiyehayran.com/likeit.php
  • https://www.virustotal.com/de/url/6ebf42c21c420e1b2d377bbd335ed3b3317373a895c8e29566deb40650e4bfe3/analysis/

HTML
  • https://www.virustotal.com/de/file/70c6546a370ccedbdbf101bfd0124adc537fc4cccb7c022a0300071c3f09afcd/analysis/
  • http://jsunpack.jeek.org/dec/getfile?hash=3585/7a7fe26eb28c4a47ccd31474b3944cefef41
  

LINK 3 (SPECIFIC)
rukiyehayran.com/likeit.php?nwqmqztem1151qapb
  • https://www.virustotal.com/de/url/9f589ceabb55b17f43769500f860b201ff60715e36bff0cc6422728b93b92232/analysis/1390758346/

HTML
  • https://www.virustotal.com/de/file/70c6546a370ccedbdbf101bfd0124adc537fc4cccb7c022a0300071c3f09afcd/analysis/

POSSIBLE ORIGINATING IP ADRESS: 108.166.43.117

Screenshot of E-Mail Scam from rukiyehayran.com

 

1/15/2014

Category MALICIOUS DOMAIN: rheumatoidarthritisgout49419.soup.io
Rogue Medications & Phishing Risk (AUSTRIA)
(GOOGLE PHISHING)

Potentially Malicious Site: Drugs & Medications (PHISHING RISK)








DOMAIN:
rheumatoidarthritisgout49419.soup.io
  • https://www.virustotal.com/de/url/52b67f6d4e0d46e81f5e560297c575c638a9ba33b43e1229718fc6929a9a1c91/analysis/
MALICIOUS LINK FOUND TO: (DOMAIN)
is.gd (U.K.)
  • https://www.virustotal.com/de/url/47a68b786b0e7abcc8263d257b7fe90a26be583647d9371b38ceb24c09332a3b/analysis/1389627324/
SPECIFIC LINK:
is.gd/fpnxbB
  • https://www.virustotal.com/de/url/61b5b6b25706c0ab0bde93ea941fbea8d7334f699957f88072ea49eb2a19e8e1/analysis/1389804055/



ADDITIONAL MALICIOUS LINK FOUND TO: (DOMAIN)
stomsk.ru (Lithuania)
  • https://www.virustotal.com/de/url/c2cb23d08ab0e0430674bda1ede032890408106f0c480b81423f85a38ba09716/analysis/1389626637/
SPECIFIC LINK:
stomsk.ru/pics/doc.jpg
  • https://www.virustotal.com/de/url/7dd47a1cf793aa3da415720b51e6d6452bfad57f42bc9c494322ea79a4363601/analysis/1389626639/



Category MALICIOUS DOMAIN: bleacherreport.com
Phishing Risk
(GOOGLE PHISHING, ROGUE MEDICATIONS)





MALWARE SITE: (PHISHING, SCAM, SPAM, FRAUD)


DOMAIN:


bleacherreport.com
  • https://www.virustotal.com/de/url/73e7cf76bf1c58ce62ab54cf4a28f320766b249d72cf66c7d210f87a1b7544b2/analysis/

IP bleacherreport.com: 54.225.139.135
  • https://www.virustotal.com/de/url/14f09c097abffce28cca7fd184550619551ff1f8d6b6451d417986f53e69e57b/analysis/1389788841/

POTENTIALLY SUSPICIOUS FILES: 24
  • http://quttera.com/detailed_report/54.225.139.135

SPECIFIC LINK:
bleacherreport.com/users/3821374-suhagra-100-reviews-alprostadil-injection
  • https://www.virustotal.com/de/url/55c49329a6f064acbf9464d02d2e796ebf9a7f6556299ec7d20145eb50168c8f/analysis/1389788405/

SPECIFIC LINK HAS A DIFFERENT IP: 23.23.134.171
  • https://www.virustotal.com/de/url/cf6b75943c44872f1e6da28708b1d7f3fcf39a05efdfc11eab3012c5f3e81815/analysis/1389788766/

POTENTIALLY SUSPICIOUS FILES: 40
  • http://quttera.com/detailed_report/23.23.134.171

http_inspect: UNKNOWN METHOD
  • https://urlquery.net/report.php?id=8823259 

DESTINATION IP: 195.159.219.10 (NORWAY, MALICIOUS)
  • https://www.virustotal.com/de/url/2124f63fafe3b2ad6f32d647633508a27ad79a2aee4cbc424baec79be1c3b327/analysis/1389789045/

Web Reputation: POOR
  • http://www.senderbase.org/lookup/?search_string=195.159.219.10

LISTED AT hPHosts:
  • http://hosts-file.net/?s=bleacherreport.com

LISTED AT TreatLog: Spam/Scam/Fraud
  • http://threatlog.com/search/bleacherreport.com/domain/
  • http://www.urlvoid.com/scan/bleacherreport.com/

POTENTIALLY SUSPICIOUS FILES: 139
  • http://quttera.com/detailed_report/bleacherreport.com

CLICKING GOES TO: (RBN 398)
is.gd/YixLnc
  • https://www.virustotal.com/de/url/686b3e88a398c31a7ffbaaafc874064f92e51133dc3f257b3dcf49a1183cf28c/analysis/1389794625/
----> URL after Redirection: GOOGLE.COM (PHISHING)

  •  https://urlquery.net/report.php?id=8824810

1/13/2014

Category MALICIOUS DOMAIN: goutytophisurgery88758.soup.io
Rogue Medication Phishing Risk (AUSTRIA)
(GOOGLE PHISHING)

Potentially Malicious Site: Drugs & Medications (PHISHING RISK)


DOMAIN:
goutytophisurgery88758.soup.io
  • https://www.virustotal.com/de/url/9c76a54622c7037c90bffa40f734845fb4a36bdbe3c3807845151e7bc3ccb7bd/analysis/1389627071/
MALICIOUS LINK FOUND TO: (DOMAIN)
is.gd (U.K.)
  • https://www.virustotal.com/de/url/d92eb9fedadf8ef87d077931d558dbb058bc35f38251ddefc6cc4addba929439/analysis/1389804529/
SPECIFIC LINK:
is.gd/OFliej
  • https://www.virustotal.com/de/url/47a68b786b0e7abcc8263d257b7fe90a26be583647d9371b38ceb24c09332a3b/analysis/
ADDITIONAL MALICIOUS LINK FOUND TO: (DOMAIN)
stomsk.ru (Lithuania)
  • https://www.virustotal.com/de/url/c2cb23d08ab0e0430674bda1ede032890408106f0c480b81423f85a38ba09716/analysis/1389626637/
SPECIFIC LINK:
stomsk.ru/pics/doc.jpg
  • https://www.virustotal.com/de/url/7dd47a1cf793aa3da415720b51e6d6452bfad57f42bc9c494322ea79a4363601/analysis/1389626639/

Category MALICIOUS DOMAIN: potenzmittelcialis26471.soup.io
Cialis Phishing Risk (AUSTRIA)
(GOOGLE PHISHING)

Potentially Malicious Site: Drugs & Medications (PHISHING RISK)


DOMAIN:
potenzmittelcialis26471.soup.io
  • https://www.virustotal.com/de/url/235b3ff9bc5531c30a46d21413ab2967d150ccf26828070641ebbd39951673c9/analysis/1389564598/
MALICIOUS LINK FOUND TO: (DOMAIN)
is.gd (U.K.)
  • https://www.virustotal.com/de/url/d92eb9fedadf8ef87d077931d558dbb058bc35f38251ddefc6cc4addba929439/analysis/1389626217/
SPECIFIC LINK:
is.gd/yGa80d
  • https://www.virustotal.com/de/url/d7d0fbfe93759463be0317981370e4186c5814168847ea1a49d1ea606aed2f7b/analysis/1389626417/
ADDITIONAL MALICIOUS LINK FOUND TO: (DOMAIN)
stomsk.ru (Lithuania)
  • https://www.virustotal.com/de/url/c2cb23d08ab0e0430674bda1ede032890408106f0c480b81423f85a38ba09716/analysis/1389626637/
SPECIFIC LINK:
stomsk.ru/pics/doc.jpg
  • https://www.virustotal.com/de/url/7dd47a1cf793aa3da415720b51e6d6452bfad57f42bc9c494322ea79a4363601/analysis/1389626639/

12/29/2013

www.unverschmiert-bs.ch - SPAM SEO (VIAGRA, CIALIS & Co.) -
Malicious Domain

MALICIOUS DOMAIN (2nd TIME): TDS URL pattern & More (SEO SPAM (BLACKHAT))

Swiss Employees, unknown that their (GOOD) (WEB-)Site has been compromised

www.unverschmiert-bs.ch
  • https://www.virustotal.com/de/url/6cba18350b1119bd06ead9d1d67d4486c450507bc39a9213ad627364b633746e/analysis/
www.unverschmiert-bs.ch/internetapotheke-cialis.html
  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/
TDS URL pattern & More
  • https://urlquery.net/report.php?id=8611512
--->
keycollector.pw
  • https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1388348713/
keycollector.pw/go.php?sid=1
  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1388348762/
--->
edapotek.eu
  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1388348958/
edapotek.eu/order-cialis-online-en.html
  • https://www.virustotal.com/de/url/92f52a030e39a0a2ea0c2835e38fe61ea4ec1a561e4338be10629f8a458962af/analysis/1388348926/
  • https://www.google.com/search?client=opera&q="viagra"+site%3Awww.unverschmiert-bs.ch&sourceid=opera&ie=UTF-8&oe=UTF-8

12/28/2013

Malicious Site: romhc.org.uk - Blackhat SEO Spam - Rogue Applications etc. SCAM, PHISHING

BLACKHAT SEO SPAM - TDS URL pattern - RBN 434
https://www.google.com/search?q=%22Cheap%20Vista%20for%20Students%22%20site%3Aromhc.org.uk#q=%22Adobe%22+site%3Aromhc.org.uk


DOMAIN:
romhc.org.uk
  • https://www.virustotal.com/de/url/fdf4cf336eedca039caf6ff3fed712e937f006b214e15ea7b69152e1e0c3315a/analysis/1388235750/
  • https://urlquery.net/report.php?id=8582533
romhc.org.uk/index.php?q=adobe-web-premium-student-discount
  • https://www.virustotal.com/de/url/929018858465569e78df15ed77e8ce8ef42f487a76e99e7f3ac43d79db3a3573/analysis/1388222771/
  • https://urlquery.net/report.php?id=8582530
--->
keycollector.pw
  • https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1388235992/
keycollector.pw/go.php?sid=1
  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1388236011/

--->
qualisoft.biz
  • https://www.virustotal.com/de/url/27091106895406579538ebe33e76cccf4bd476210f3229c77669af925b050388/analysis/1388236240/
--->
euxzqvcxgbirbtra.qualisoft.biz
  • https://www.virustotal.com/de/url/a7d545757276ed198bb6efc694ff44c82105b43c8a5581190ee2cb582ecafcf1/analysis/1388236376/
---------------------

IP romhc.org.uk: 74.220.207.77
  • https://www.virustotal.com/de/url/acc2a6be4299a171f54c7de4da8ff07c1836e88f52a6166bc3401dcdeed70327/analysis/1388236607/
  • https://www.virustotal.com/de/ip-address/74.220.207.77/information/