Translate

Posts mit dem Label Malicious IPs werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Malicious IPs werden angezeigt. Alle Posts anzeigen

12/28/2013

Category MALICIOUS IP: 177.97.145.173 - Kelihos Spambot - Brazil

The IP Address 177.97.145.173 (IP LOCATION: Brazil) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. This IP is infected (or NATting for a computer that is infected) with the Kelihos Spambot. In other words, it's participating in a botnet.



REFERENCES:
  • https://www.virustotal.com/de/url/e6fa619af189caf9a9822a91b5b969916a773e727bf608b8d7dd2e6b2484ad68/analysis/1388217360/
LISTED @ SPAMHAUS (POLICY BLOCK LIST):
LISTED @ CBLABUSEAT:
Fwd/Rev DNS Match: No
Email Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=177.97.145.173

12/11/2013

YOU CAN CALL ME AL - Newly Detected Malicious Site: www.cpubs.co.uk
Trojan-Downloader.JS.Iframe.as (Video Included)

THIS DOMAIN HAS BEEN RECENTLY DETECTED WITH MALWARE:


MALWARE: (Malicious iFrame)
Trojan-Downloader.JS.Iframe.as


DOMAIN: www.cpubs.co.uk
https://www.virustotal.com/de/url/e984b05cce3eae0369654e049e2ce54f954038cce0a29cb14b13953199d56224/analysis/1386789211/
Trojan-Downloader.JS.Iframe.as
https://www.virustotal.com/de/file/b8eedbce9f5ff054917c3e4b31424c2337bd64fea13a4a59e6190e8cfa57f5ea/analysis/1386789611/
Trojan.IframeRef
https://www.virustotal.com/de/file/fd4f1ba055e271eea9a901b744662b1d37e29ee08fe8aeb5f9ae82ee1b4606dd/analysis/1386789593/

IP: 83.223.104.120
https://www.virustotal.com/de/url/fcdc7c6193227ec7074f8e0b443a2ba1645b2bd40ea9902a6ec771f3a36f4610/analysis/1386706066/
https://www.virustotal.com/de/ip-address/83.223.104.120/information/

Pattern --->
http://124.217.249.45/   (mAL(ware)asia) https://www.virustotal.com/de/url/05df9f4655601684423f632c420bf3bea37c5b9101b0253c2a40b8869f41443e/analysis/1386705829/




Web Reputation: POOR
http://www.senderbase.org/lookup/?search_string=124.217.249.45
https://www.virustotal.com/de/ip-address/124.217.249.45/information/

URLs and sub domains distributing the malware or acting as a redirector:
http://labs.sucuri.net/?details=124.217.249.45
http://124.217.249.45/~user/html/TDS/go.php?sid=1
https://urlquery.net/report.php?id=8310905
https://www.virustotal.com/de/url/594724cae8d42909d3a3aaec05f53212d8aa6bba79a7de205b1bd3b00795e108/analysis/1386705825/

Newly Detected Malicious Site: www.alpha-accounting.co.uk - Trojan-Clicker.HTML.IFrame.gt

THIS DOMAIN HAS BEEN RECENTLY DETECTED WITH MALWARE:
Trojan Clicker

DOMAIN: www.alpha-accounting.co.uk
https://www.virustotal.com/de/url/5b7b21c0bb80afba00e2f3a1c58f6a60653046acab467cbce0b90f2a7a4652d0/analysis/1386702079/
Trojan-Clicker.HTML.IFrame.gt
https://www.virustotal.com/de/file/a3ff6a187831652dafaa7ac0767f8c2e4ba07278e58b1dd9ef5551b5e943336b/analysis/1386702405/
Heuristic.LooksLike.HTML.Infected.B
https://www.virustotal.com/de/file/7646a8ffcc874d6f569cdec21589355c2a828352856d84b9aad629868db62f87/analysis/1386702428/
https://urlquery.net/report.php?id=8310048

IP: 83.223.104.120
https://www.virustotal.com/de/url/fcdc7c6193227ec7074f8e0b443a2ba1645b2bd40ea9902a6ec771f3a36f4610/analysis/1386706066/
https://www.virustotal.com/de/ip-address/83.223.104.120/information/

Pattern --->
http://124.217.249.45/   (MALAySIA)
https://www.virustotal.com/de/url/05df9f4655601684423f632c420bf3bea37c5b9101b0253c2a40b8869f41443e/analysis/1386705829/

Web Reputation: POOR
http://www.senderbase.org/lookup/?search_string=124.217.249.45
https://www.virustotal.com/de/ip-address/124.217.249.45/information/

URLs and sub domains distributing the malware or acting as a redirector:
http://labs.sucuri.net/?details=124.217.249.45
http://124.217.249.45/~user/html/TDS/go.php?sid=1
https://urlquery.net/report.php?id=8310905
https://www.virustotal.com/de/url/594724cae8d42909d3a3aaec05f53212d8aa6bba79a7de205b1bd3b00795e108/analysis/1386705825/

New Malware: escrituras.com - Trojan-Spy.HTML.Fraud.iz

NEW MALWARE:

Trojan-Spy.HTML.Fraud.iz

DOMAIN: escrituras.com

https://www.virustotal.com/de/url/023bdad1bf212b69fc38f942d94a10605e3586e9c13bae9fab12eef580d48f62/analysis/1386595660/

Trojan-Spy.HTML.Fraud.iz

https://www.virustotal.com/de/file/e5a2cf61957340d4e0f991a6df9819636110d687856eae56c54d88ec6b21b86d/analysis/


IP: 200.98.247.12

https://www.virustotal.com/de/url/08f6a35041572c517d0f37b678212f07fd393105cb12a6cb0193b7897e23b2cb/analysis/1386596265/
https://www.virustotal.com/de/ip-address/200.98.247.12/information/
--->
mensagens.host.uol.com.br
https://www.virustotal.com/de/url/023f4a8bdd186e4454df21696a38c99557b7ea48c2f88af4cd87965a6723b1d1/analysis/1386596045/
mensagens.host.uol.com.br/aviso/aviso_compartilhado.html
https://www.virustotal.com/de/url/c2509e06f5edb12d74aa3f1f50eb0774fc2d113246a96e824eaf4d6e08e58cef/analysis/1386596036/
IP: 200.98.199.177:
https://www.virustotal.com/de/url/f5d0fadaea1a2477c78d88e32a3c47f3ee1088ad986960bbefd88f6af44336bc/analysis/1386596399/
https://www.virustotal.com/de/ip-address/200.98.199.177/information/

12/04/2013

Category MALICIOUS IP: 185.5.99.21 - Dictionaryattacker - Unknown0556 Spambot - Poland

The IP Address 185.5.99.21 (IP LOCATION: Poland) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. It was last detected on the 4th of November 2013. It has been relisted following a previous removal on 12th November. This IP is infected (or NATting for a computer that is infected) with a spambot that has not yet been identified. For the time being it is refered as the Unknown0556 Spambot.


IP 185.5.99.21 is participating in a botnet. CBL states: If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again.

Dictionary Attacks: 5.741 Emails sent from this IP.
Email Reputation: Poor
Spam Level: Very High

Reputation of IP 185.5.99.21 @:



OTHER INFORMATION:
AS198414
Biznes-Host.pl sp. z o.o.
Google Safebrowsing Report on ASN

New Additional Info on this IP

The latest CBL report states:

It was last detected at 2013-12-08 03:00 GMT (+/- 30 minutes), approximately 3 hours, 30 minutes ago. 
The listing of this IP is because it HELLOs as (IP) 17.158.8.111. Not only is this a violation of RFC2821/5321 section 4.1.1.1, it's even more frequently a sign of infection. (RFC 2821, section 4.1.1.1 Extended HELLO (EHLO) or HELLO (HELO)
These listings are often a sign of a compromised SSH account. If you are running a SSH service (especially on Linux), please check your ssh server logs (often /var/log/auth.log) for logins from this IP. If you find any, secure the associated account. This usually means changing the password or disabling the account. 
If it's a mail server, see naming problems for details on how to diagnose and fix the problem. 
If IP address 17.158.8.111 is or is NATing for a Symantec Protection Center instance, this appears to be a known issue. See this Knowlege Base item. We are attempting to work through this issue with them. Their KB item was updated October 18, 2010 to indicate that they now understand the issue. 
The KB item indicates that the problem will be resolved in a "future build", but no ETA is provided. If you have SPC's email notification feature turned on, we recommend turning it off before delisting your IP address as a temporary workaround. 
This IP is infected (or NATting for a computer that is infected) with a spam-sending infection. In other words, it's participating in a botnet. If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again.

11/25/2013

Spam Site(s) : www.irubyvivaclub.com & irubystarweb.com

Mit dem 200% Willkommensbonus von Ruby Palace müssen Sie nicht länger nur träumen.

Melden Sie sich heute noch an, um dieses einmalige Angebot zu nutzen und Ihr Guthaben wird im Handumdrehen dreimal so attraktiv sein - jede Menge Spielfreude ist garantiert.

Links go to VT Analysis
http://www.irubyvivaclub.com/ REDIRECTS TO:
http://www.irubycasinogame.com/



Es wird (ZUVIEL) oft gesagt, dass aller guten Dinge drei sind. Dies ist Ihre Chance, Ihrem Guthaben etwas Gutes zu tun.

Mit freundlichen Grüßen

Ruby Palace Support
----

Bitte klicken Sie hier, um unseren gesamten E-Mail-Service abzubestellen:
http://unsubscribe.irubystarweb.com/ 

PLUS Undemanded Download of Malware:
http://irubycasinogame.com/rubyPalace_setup_DE.exe


E-Mail Screenshot:

 

IP(s):
1) IP 178.175.99.240 is double listed at Spamhaus.org.
See: http://www.spamhaus.org/query/bl?ip=178.175.99.240


2) IP 188.65.211.137 (www.irubyvivaclub.com) is listed at Spamhaus.org.


3) IP 91.239.15.222 (www.irubycasinogame.com) is double listed at Spamhaus.org
"Dirty network: VympelStroy ltd."

4) IP 195.2.77.153 (unsubscribe.irubystarweb.com) connected to Spamhaus.org:
Header Analysis Quick Report
Originating IP: 178.175.99.240
Originating ISP: Ptk Ip/mpls Network
City: Gjakovë
Country of Origin: Serbia
* For a complete report on this email header goto ipTRACKERonline

Read also this article @ Krebs on Security: Stophaus vs. Spamhaus

11/21/2013

419 SCAM OF THE DAY: 41.138.97.161
(Mrs. Linda Adama from Burkina Faso)

Mrs. Linda Adama from Burkina Faso wrote:

"Dear Friend,
Greetings to you and your family; However, it's just my urgent need for foreign partner that made me to contact you for this transaction. I work in Bank of Africa foreign department. I want to place your name as the beneficiary to Ten Million Five Hundred Thousand United States Dollars (USD10.5M).
The said funds is right here in the bank, it's the balance deposited funds by one of our late customer from France Mr. Paul Louis Halley since then nobody has come up for the claim. Therefore, I solicit for your cooperation to collaboration with me to have this done; it will be transferred into an account you will provide any where of your choice.
If you are interested, please send me your full contact information as below and thereafter I will send to you text of application form to apply for the fund next of kin (Beneficiary). "
Expecting your urgent reply!
1. Full name:.........
2. Current Address:.........
3. Telephone N=B0:...........
4. Occupation:.............
5. Copy of your identity...
6. Age:............
7. Country:........
          Yours trulyMrs. 
          Linda Adama

Screenshots:




Malicious IP:      41.138.97.161

- Spamhaus.org
- Dictionary Attacker & More
- Reputationauthority.org
- LOOK UP


Header Analysis Quick Report
Originating IP: 41.138.97.161
Originating ISP: Onatel/fasonet's
City: n/a
Country of Origin: Burkina Faso
* For a complete report on this email header goto ipTRACKERonline

11/20/2013

Category MALICIOUS IP: 94.242.204.74
Worm:Win32/Boinberg (CnC Botnet)

The IP Address 94.242.204.74 (IP LOCATION: Luxemburg) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. It was last detected on 19th November 2013. It has been relisted following a previous removal on 12th November.

This IP address is infected with, and/or is NATting for a machine infected with the Worm.Boinberg. This Worm:Win32/Boinberg is part of the Malware-family of IRC-controlled worms that may be ordered to spread via Windows Live Messenger (ICQ, AOL Instant Messenger, Yahoo Pager, Skype, etc.) and/or USB drives. It may also spread through USB drives, RAR and ZIP files by adding a copy of itself into the target archive. Its first detection has been made in March 2011, and the threat level almost 4 years later is classified as severe. In order to spread, IM-Worms usually send a link (URL) to a list of message contacts. The link leads to a network resource where a file containing the body of the worm has been placed. This tactic is almost exactly the same as that used by Email-Worms.


This Worms Aliases by AVVendors:
  • Malware.Shadesrat (PCTools)
  • W32.Shadesrat (Symantec)
  • Backdoor.Win32.IRCBot.abgt (Kaspersky Lab)
  • W32/IRCbot.gen.a (McAfee)
  • Mal/VBCheMan-A (Sophos)
  • Worm:Win32/Boinberg (Microsoft)
  • Worm.Win32.Boinberg (Ikarus)
And not to forget that it is packed UPX (Ultimate Packer for eXecutables)
-----------------------------------------------------------------------------

It`s Installation:

When executed, Worm:Win32/Boinberg copies itself with a variable file name to the %APPDATA% directory, then executes this dropped copy.

The malware creates the following registry entries to ensure that its copy executes each Windows start:

In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Sets value: "<random string>"
With data: "%APPDATA%\<random file name>.exe"

In subkey: HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Sets value: "<random string>"
With data: "%APPDATA%\<random filename>.exe"

In the background, the worm injects itself into known Windows running processes, such as 'winlogon', 'svchost' and 'Explorer'.

The following mutex indicates the presence of the worm on the affected computer:

"__PDH_PLA_MUTEX__"
"<random string>"
"<empty / blank>"

Spreads via...

Instant messenger

The worm may send messages to the affected user's Windows Live Messenger contacts containing a URL pointing to the worm, or an attachment containing a copy of the worm.

Removable drives

Worm:Win32/Boinberg copies itself to the following locations on removable drives:

<targeted drive>:\<malware file>.exe
<targeted drive>:\autorun.ini - detected as Worm:Win32/Boinberg

It attempts to download an updated version from a remote server and spread this latest copy via removable drive.

It also places an autorun.inf file in the root directory of the targeted drive. Such autorun.inf files contain execution instructions for the operating system (OS), so that when the removable drive is accessed from another computer supporting the Autorun feature, the malware is launched automatically.

File infection 

It searches for RAR and ZIP files on the system and, if found, infects them by adding a copy of the worm into the target archive file. This may enable the worm to spread itself through file sharing or emailing.

IMPORTANT: PAYLOAD...

...allows backdoor access and control

Worm:Win32/Boinberg attempts to connect to an IRC server and join a channel to receive commands.

The following is a list of servers and TCP ports that Worm:Win32/Boinberg has been observed to use in this manner:



For more details on this Worm, visit Microsoft here.
-------------------------------------------------------------
The CBL detection is being made using sinkholing techniques.

To find an infected computer on a NATted network you will have to search through your firewall logs for connections to port 4042 TCP. In additional, evidence can be found in DNS logs by searching for the domain name "hi5fotos.info", for example:

cash.hi5fotos.info
xsi.hi5fotos.info
kkk.hi5fotos.info

This was detected by a TCP/IP connection from 94.242.204.74 on port 56501 going to IP address 87.255.51.229 (the sinkhole) on port 4042.

The botnet command and control domain for this connection was "hi5fotos.info".

Behind a NAT, you should be able to find the infected machine by looking for attempted connections to IP address 87.255.51.229 or host name hi5fotos.info on any port with a network sniffer such as Wireshark.

Equivalently, you can examine your DNS server or proxy server logs to references to 87.255.51.229 or hi5fotos.info. See Advanced Techniques for more detail on how to use Wireshark & ignore the references to port 25/SMTP traffic, the identifying activity is NOT on port 25.

This detection corresponds to a connection at 2013-11-19.

These infections are rated as a "severe threat" by Microsoft. It is a trojan downloader, and can download and execute ANY software on the infected computer, so better stay Awake. ;-)

RELATED POST: Symantec: Blackshades Remote Access Tool still being bargained