Translate

Posts mit dem Label Compromised Website werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Compromised Website werden angezeigt. Alle Posts anzeigen

12/16/2013

Deutsche Kentucky Fried Chicken Website (HESSEN) infiziert mit Blackhat SEO SPAM (PHISHING inklusive)

KOMPROMITTIERTE URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL PFAD - PHISHING


KFC Logo
URL:


www.kfc-hessen.de/viagra-fur-die-frau-online-kaufen

  • https://www.virustotal.com/de/url/fa0ce0aed0980ed05dc97032971980f4536b6c04fd66227e46b0b7605f962906/analysis/1387219444/



TDS URL PFAD
INDICATOR-COMPROMISE Suspicious .pw dns query



  • https://urlquery.net/report.php?id=8404039


---> TDS PFAD

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387220505/
  • https://urlquery.net/report.php?id=8404170

---> LEITET WEITER AN PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387220706/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.61.42.211

  • https://www.virustotal.com/de/url/14c84d8d823c8a2dd31c0dad9aaecd39a5bc6b183093196acf12ea1f2fb0c7c3/analysis/1387223113/
ENGLISH POST:

German Kentucky Fried Chicken Website Infected with Blackhat SEO SPAM (Phishing included)

MALICIOUS URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL pattern - PHISHING


KFC Logo
URL:


www.kfc-hessen.de/viagra-fur-die-frau-online-kaufen

  • https://www.virustotal.com/de/url/fa0ce0aed0980ed05dc97032971980f4536b6c04fd66227e46b0b7605f962906/analysis/1387219444/


TDS URL pattern
INDICATOR-COMPROMISE Suspicious .pw dns query



  • https://urlquery.net/report.php?id=8404039

---> TDS PATH

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387220505/
  • https://urlquery.net/report.php?id=8404170

---> TO PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387220706/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.61.42.211

  • https://www.virustotal.com/de/url/14c84d8d823c8a2dd31c0dad9aaecd39a5bc6b183093196acf12ea1f2fb0c7c3/analysis/1387223113/

Deutsches POSTING:
http://stayaway2.blogspot.com/2013/12/deutsche-kentucky-fried-chicken-website.html

12/15/2013

Malicious URL: www.ramada-friedrichroda.de - Rogue Medications
SCAM, SPAM, PHISHING

MALICIOUS URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL pattern - PHISHING



URL:

www.ramada-friedrichroda.de/apotheke-niederlande-cialis

  • https://www.virustotal.com/de/url/440d20e3414b328c712cd2b8f239eedcd4384017bb38147ca9892f6d456ce261/analysis/1387125985/

TDS URL pattern
INDICATOR-COMPROMISE Suspicious .pw dns query

  • https://urlquery.net/report.php?id=8396692

---> TDS PATH

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/b0059244125b4a42d4ed3fee193cf1c19300c7a4499f5cfe6e1d8b51c833796a/analysis/1387126405/
  • https://urlquery.net/report.php?id=8396782

---> TO PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387126466/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.152.215.126

  • https://www.virustotal.com/de/url/09f69d67216a170c75e9e24f1ce49a682e2af481d34c54948168b78daf829c85/analysis/1387127170/
  • https://www.virustotal.com/de/ip-address/5.152.215.126/information/