Translate

Posts mit dem Label Dictionary Attacker werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Dictionary Attacker werden angezeigt. Alle Posts anzeigen

6/01/2014

Category MALICIOUS IP: 217.106.230.143
Infected with CONFICKER Botnet & Dictionary Attacker
CBL Listed (Russian Federation)


The IP Address 217.106.230.143 is listed in the CBL. It appears to be infected with a spam sending trojan, proxy or some other form of botnet.


It was last detected at 2014-06-01 09:00 GMT (+/- 30 minutes), approximately 3 hours ago.

This IP is infected (or NATting for a computer that is infected) with the Conficker botnet.

---------------------------------------------------------------------------------------------------------------------------------------------

IP:
http://217.106.230.143/
  • https://www.virustotal.com/de/url/2eec4640667c218ae8a6a9da97422083720b4477387dfcc59e569bd0d014d424/analysis/1401473689/
  • https://www.virustotal.com/de/ip-address/217.106.230.143/information/
Listed at SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=217.106.230.143
Listed at CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=217.106.230.143
Listed at Weighted Private Block List:
  • http://www.wpbl.info/cgi-bin/detail.cgi?ip=217.106.230.143
Listed NiX-Spam
  • http://www.dnsbl.manitu.net/?language=en
Dictionary Attacker & SPAM Sender:
SPAM MAILS SENT FROM THIS IP: 3.233
  • https://www.projecthoneypot.org/ip_217.106.230.143 
SEE ALSO:
  • http://zulu.zscaler.com/submission/show/dddc53f4ec74d5076fc8be59977acc69
  • http://www.senderbase.org/lookup/?search_string=217.106.230.143
  • http://net.cs.uni-bonn.de/wg/cs/applications/containing-conficker/

4/13/2014

Category MALICIOUS IP: Cutwail Spambot on IP 213.144.13.74 (Karlsruhe, GERMANY)
Pushdo Malware and Zeus Botnet - Dictionary Attacker


The IP Address 213.144.13.74 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-04-10 13:00 GMT (+/- 30 minutes), approximately 2 days, 23 hours, 29 minutes ago.

This IP is infected (or NATting for a computer that is infected) with the Cutwail Spambot. In other words, it's participating in a botnet.


Cutwail is a complex infection and requires a number of steps to ensure that it's eradicated.

First, Cutwail spams out very high volumes, and is one of the the largest vectors of malware on the Internet, and almost every cutwail infection also has a copy of the Pushdo (DDOS by web transaction) malware and/or the Zeus botnet. The Zeus botnet controls the Cutwail/Pushdo pair as well as does information stealing/keyboard logging. Hence, this is a very severe threat - not just to the owner of the infected computer, the other members of your internal network (if you have one) but the rest of the Internet too.

Second, there are two methods for detecting cutwail. One of the methods is by detecting the spams that cutwail sends. The other method does not work that way. This means that even if you block outbound port 25 from non-mail-servers on your local network, you can still detect a cutwail infection on your local network. This means that if you implement port 25 restrictions, you should implement logging so that you can detect what internal machines are being blocked by it and are thereby probably cutwail infections.

TO READ THE REST OF THIS ARTICLE, go to:

http://cbl.abuseat.org/lookup.cgi?ip=213.144.13.74

As well Listed at SORBS:
  • http://www.au.sorbs.net/lookup.shtml

Listed at SPAMRATS:
  • http://www.spamrats.com/lookup.php?ip=213.144.13.74

A small report on this IP can be seen by clicking the .txt. Icon:

Document hosting: UploadEdit.com

4/11/2014

PHISHING MAIL FROM:
safeukemailer.com & planosdesaudeagora.com

IP: 174.140.167.243 - DICTIONARY ATTACKER & SPAMSERVER
Heuristic.BehavesLike.JS.BufferOverflow.J


PHISHING MAIL FROM:
http://safeukemailer.com/
  • https://www.virustotal.com/de/url/7e6568720e2f0e44bfcb9d974823fc0d6bed744157a9e9b655c4f0ac5be96841/analysis/1397215692/
  • http://wepawet.iseclab.org/view.php?hash=99533e29222be52ac0aecd2104ced6ec&t=1397215185&type=js
REDIRECTS TO:
http://planosdesaudeagora.com/admin/index.php
  • https://www.virustotal.com/de/url/85b7433bf813cd4884a22a8f5f66a8481935be109e6e12066fad3f3ade37fe2f/analysis/1397215746/
HTML
  • https://www.virustotal.com/de/file/6ea7c43f2a8f0bc4b6d11931e3eaeb5fe8f085a5db9accf605424390a9e00e21/analysis/1394810790/
ALSO
http://planosdesaudeagora.com/admin/includes/js/javascript.js
  • https://www.virustotal.com/de/url/f8369cd305da7c812550ca69ecf82f857f4a2506bbd119b5217c57699ce19eac/analysis/1397216635/
Heuristic.BehavesLike.JS.BufferOverflow.J
  • https://www.virustotal.com/de/file/d8c5447067ec6b33acaa3701a50d1d75b985d4e933490b0d0ef81bfd4c7c606d/analysis/1378020397/




DOMAIN LISTED AT SURBL & JOEWEIN
  • http://www.urlvoid.com/scan/planosdesaudeagora.com/
  • https://www.mywot.com/en/scorecard/planosdesaudeagora.com

IP:
http://174.140.167.243/
  • https://www.virustotal.com/de/url/206033db51f7886c907adb9afc607982fbfab8d362ea78ec6e323a5d45cf167d/analysis/1397215940/
  • https://www.virustotal.com/de/ip-address/174.140.167.243/information/
DICTIONARY ATTACKER & SPAMSERVER:
  • https://www.projecthoneypot.org/ip_174.140.167.243
  • http://www.senderbase.org/lookup/?search_string=174.140.167.243

4/05/2014

ZDF ++EILT++ACHTUNG++SCHOCKIERENDE MELDUNG++:
German PHISHING MAIL from:
www.redcappi.com
arbeit-von-zuhause-aus.com
goo.gl/p3rL07

(United States)

++EILT++ACHTUNG++SCHOCKIERENDE MELDUNG++

ZDF berichtete HEUTE im Fernsehen!: Deutschland ist schockiert über diese Geldmaschine!
Vergessen Sie alles, aber wirklich ALLES was Sie bisher in Ihrem Leben gesehen haben!
So etwas haben Sie noch NIE gesehen! 100% GARANTIERT

Das wird sicher Ihr Leben komplett ändern!

Nur noch 429 Mal verfügbar!

Schauen Sie sich das Video an!

Hier klicken: >»ZUM VIDEO«<

Screenshot Mail
SPAM - SCAM - PHISHING MAIL:
http://arbeit-von-zuhause-aus.com/
  • https://www.virustotal.com/de/url/e7a5745161f044e06b3f75c5ec2b10cd724b9214dfd0d2b714ea9dee2eaf9d61/analysis/1396714323/
  • https://www.virustotal.com/de/file/06e076babd1bc5d7cd32d34f28fa54c4bdd37db5b50eb8328e0469ab29659bf3/analysis/1396714606/
OTHER LINK FOUND IN HTMLSRC:
http://www.mega-ways.com/index.php?d=forum&s=24
  • https://www.virustotal.com/de/url/e33e88bc05bacb38a97d9c73f111a852651edb02f5fcc9c5e99c1f10fc566ecd/analysis/1396718339/
TO MENTION HERE IS:
http://www.mega-ways.com/javascript/alphanumeric.js
  • https://www.virustotal.com/de/url/50d7f3901c7599a6af623faf05cf912b2e8ab05b4566ccd8ed69b6719c7308d0/analysis/1396716791/
Virus.exp.js.1
  • https://www.virustotal.com/de/file/bae1f370c9a4ae19a9bd6d68d98629c115f1f764a844691bfd406211ca321575/analysis/
Ihr Einkommen wird EXPLODIEREN - LOOOL

THROUGH:
http://www.redcappi.com/
  • https://www.virustotal.com/de/url/67dc853cd6c065dae93edf295021f261c0c3a2b181cdd28f6780119554a3cfca/analysis/
  • https://www.virustotal.com/de/file/c2bcdd9e4362bcb2341d8c18525b49f23bf5b5fc530ef43b4f13846bdb94a875/analysis/1396717343/
SPECIFIC MALICIOUS URL IN PHISH-MAIL:
http://www.redcappi.com/newsletter/clickrate/create/35671/MzY3NjczNjItZ2FyeWR1bnNtb3JlQGdtYWlsLmNvbQ/1
  • https://www.virustotal.com/de/url/39917f03a8488217564a62a540548c328a95b6aff48249951027f2b50aafd9d9/analysis/
---> REDIRECTS TO: (PHISHING INTENDED)
http://goo.gl/p3rL07
  • https://www.virustotal.com/de/url/5cab9105b00691593c6decf0b4702ba2798cbcfcd46331bed86f089e5913f759/analysis/
http://goo.gl/p3rL07 – this URL has been disabled. Note that goo.gl short URLs may be disabled for spam, security or legal reasons.


FULL REPORT:


Document hosting: UploadEdit.com

4/01/2014

Introducing COMMENT SPAMMERS (so the NET will not FORGET)
Helping those sorrow ones out in Publicity,
otherwise no one would notice them....


www.home-staging-montreal.com
IP: 66.43.56.89
(Montréal)


Anonymous wrote on February 8th, 2014:

Pretty great post. I just stumbled upon your blog and wished to mention that I have truly loved surfing around your weblog posts. After all I will be subscribing in your feed and I am hoping you write once more very soon! 
My weblog: www.home-staging-montreal.com...



COMMENT SCREENSHOT



On this Post:



Screenshot of the Webpage:

One important Question remains: Would you buy something at a place where the Spammer is trying to Advertise through an Article thats subject to Cild Predators & Pedophiles harming Children ??? I BET NOT !!!
----------------------------------------------------------------------------------------------------------------------------------------------

3/15/2014

Category MALICIOUS IP: Cutwail Spambot on IP 194.176.111.154 (Kyrgyzstan)
Pushdo Malware and Zeus Botnet - Dictionary Attacker


The IP Address 194.176.111.154 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-03-15 04:00 GMT (+/- 30 minutes), approximately 5 hours ago.

This IP is infected (or NATting for a computer that is infected) with the Cutwail Spambot. In other words, it's participating in a botnet.


Cutwail is a complex infection and requires a number of steps to ensure that it's eradicated.

First, Cutwail spams out very high volumes, and is one of the the largest vectors of malware on the Internet, and almost every cutwail infection also has a copy of the Pushdo (DDOS by web transaction) malware and/or the Zeus botnet. The Zeus botnet controls the Cutwail/Pushdo pair as well as does information stealing/keyboard logging. Hence, this is a very severe threat - not just to the owner of the infected computer, the other members of your internal network (if you have one) but the rest of the Internet too.

Second, there are two methods for detecting cutwail. One of the methods is by detecting the spams that cutwail sends. The other method does not work that way. This means that even if you block outbound port 25 from non-mail-servers on your local network, you can still detect a cutwail infection on your local network. This means that if you implement port 25 restrictions, you should implement logging so that you can detect what internal machines are being blocked by it and are thereby probably cutwail infections.

TO READ THE REST OF THIS ARTICLE, go to:

http://cbl.abuseat.org/lookup.cgi?ip=194.176.111.154

A small report on this IP can be seen by clicking the .txt. Icon:

Document hosting: UploadEdit.com

2/15/2014

HEUR:Trojan.Script.Generic ---> artofzengraphics.com
IP 216.177.139.128

(Laguna Niguel, California, United States)




MALICIOUS SITE & IP: HEUR:Trojan.Script.Generic
http://artofzengraphics.com/
  • https://www.virustotal.com/de/url/81193b530827110d85212ac17af2962377242f30ea759b2b673ecb33a91bc00c/analysis/

INFECTION:
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/28c5a744588396a98aefcd426d21687d6523192503858b9d56bcfa90699938ee/analysis/1392491478/
  • http://wepawet.iseclab.org/view.php?hash=bc670ebbbcb5ac14506a784751b405fa&t=1392491777&type=js
FULL REPORT:
Document hosting: UploadEdit.com

12/29/2013

Category MALICIOUS IP: 62.115.225.218 - Kelihos Spambot - Dictionary Attacker

The IP Address 62.115.225.218 (IP LOCATION: EUROPE) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. This IP is infected (or NATting for a computer that is infected) with the Kelihos Spambot. In other words, it's participating in a botnet.



REFERENCES:
  • https://www.virustotal.com/de/url/13a295f252a2ac99b668a8963044444342b5212e4f3d295df9739bc0f2355408/analysis/1388304961/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=62.115.225.218
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=62.115.225.218
LISTED AT SPAMCOP:
  • http://www.spamcop.net/w3m?action=checkblock&ip=62.115.225.218
Email Reputation: Poor
Spam Level: Critical & Very High

  • http://www.senderbase.org/lookup/?search_string=62.115.225.218
  • https://www.projecthoneypot.org/ip_62.115.225.218
HOSTNAME: 62-115-225-218.customer.teliacarrier.com
  • https://www.virustotal.com/de/url/8320762182ff099fdd8ae2e71a6e3894abbb9a5eafc6995f1f3a649ca1e0c1b2/analysis/1388306396/
DOMAIN:  teliacarrier.com
  • https://www.virustotal.com/de/url/c9cead4a3b71f7edecc088130f27c39b62f38557625c72a02626e798d2a27599/analysis/1388306612/