Translate

Posts mit dem Label Netherlands werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Netherlands werden angezeigt. Alle Posts anzeigen

4/01/2014

PHISHING from www.heavenjav.com (IP: 89.248.168.164)
Netherlands
PUA.Phishing.Bank


HeavenJAV Screenshot

Phishing SITE:
DOMAIN:
http://www.heavenjav.com/
  • https://www.virustotal.com/de/url/7ba4abf24940faa50c30bdea1e3788d98f79c5d38bbaf6a60934ec10951f8c02/analysis/1396342103/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/e0862f4de5204feea0c3d8e365db0082d9b66743873bd1622248b392dfdc63ef/analysis/1396342533/
  • http://virusscan.jotti.org/de/scanresult/0882e3fab80e1c4561884fb123e103298c89153a
http://www.heavenjav.com/2013/02/24/front-magazine-uk-no-178-2013/
  • https://www.virustotal.com/de/url/07f6c70e33553e5b4da02f94af3c4b3ecca2003cf1610505e437a106ae85cbf9/analysis/1396342096/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/90d8f789b5499a6d10b89b31cb75ed7474481e20996e125c676da78b8d599c9c/analysis/1396342153/
  • http://virusscan.jotti.org/de/scanresult/d8067f7e7a665777aeaeb064eb3fb32664db9e1a
http://89.248.168.164/
  • https://www.virustotal.com/de/url/3b8ce797c88762fece7858c4024261fb686117e4c6d68a9f0ef3d0f154a9ac71/analysis/1396350748/

3/30/2014

Real Comment Number 2 on COMMENT SPAM !

ANONYMOUS WROTE:
"It's really a great and useful piece of information."
KEY COMMENT: "Here is my blog post: pirater un compte Facebook"


My Site: www.facebook-recherche.com

This Post is (and will be & stay) to demonstrate what SPAM IN BLOGS (Comment SPAM) IS about and how you should difference it ! From this part it is surveilled, and followed. IP-Data and Domains who are involved are being recorded, to monitor the frequency and analyzing the connections given to it. In case suspicious Connections (related to Phishing, Spambots (what they already are), and other fraudulent activities and/or behaviour) will (not only) be recorded and transfered to the appropriate agencies (i.e. IC3) what however is done anyway. Special observations from outside can be adressed to me through IC3. 

Reminder: However, every SPAM-Post is delivered to the appropriate Adress. Keep following.
-------------------------------------------------------------------------------------------------------------------------------------------

NUMBER 2:
It's really a great and useful piece of information. I'm glad that you simply shared this helpful information with us. Please keep us up to date like this. Thank you for sharing. Here is my blog post pirater un compte Facebook www.facebook-recherche.com
SPAM COMMENT MADE ON FOLLOWING POST:

http://stayaway2.blogspot.com/2014/01/international-online-child-predators.html

SCREENSHOT OF ANONYMUS COMMENT SPAMMER




PHISHING & MALICIOUS DOMAIN: FACEBOOK ACCOUNT HIJACK (HACK) & PHISHING FOR FB CREDENTIALS AS WELL A BLOG COMMENT SPAMMER (LISTED AT SPAMHAUS)
http://www.facebook-recherche.com/
  • https://www.virustotal.com/de/url/86eba7512f57e84d6864a943230e74e9767a568755dd2240690ddba9572a1910/analysis/1396193684/
HTML
  • https://www.virustotal.com/de/file/4d92a05b9a4c097d28c09784947fd4af204e1238b13df695bc477f5f74666e67/analysis/
LISTED AT SPAMHAUS (DBL):
  • http://www.spamhaus.org/query/domain/facebook-recherche.com
-------------------------
IP: NETHERLANDS
http://37.46.125.166/
  • https://www.virustotal.com/de/url/a9a0fd6a7a201e4675d3179bd408efbf0f602f492c649f450d92fb56c1d140cf/analysis/1396195483/
  • https://www.virustotal.com/de/ip-address/37.46.125.166/information/

3/20/2014

SPYWARE DOMAIN: terra.mastertop100.net
TROJAN REDIRECTOR (Pagesinxt Malicious Redirect)

USA-RUSSIA-CANADA-Virgin-Islands
NORWAY-NETHERLANDS-FRANCE-ITALY


MALICIOUS DOMAIN:
SPYWARE - TROJAN REDIRECTOR 

USA-RUSSIA-CANADA-Virgin-Islands-NORWAY-NETHERLANDS-FRANCE-ITALY
http://terra.mastertop100.net/
  • https://www.virustotal.com/de/url/b99bc9716fa430c1e0417a758ddf03d3eaf1ca33f8619da37756c61e8469e559/analysis/1395328043/
Pagesinxt Malicious Redirect
  • https://urlquery.net/report.php?id=1395328112708
FOR FULL REPORT .txt ICON:

Document hosting: UploadEdit.com

2/24/2014

Category MALICIOUS DOMAIN & IP:
www.zbestclubreview2014.com (IP: 115.242.210.80)
Casino, Gambling
(PHISHING, SCAM, SPAM) (Ruby Palace, Mumbai, INDIA)


Auf unseren Webseiten finden Sie die besten Online Casinos mit exklusiven Angeboten, wenn Sie sich über unsere Webseiten registrieren.
Verschiedene Angebote wie Freispiele und Bonusse auf Einzahlungen erwarten Sie.

Besuchen Sie unsere Webseite, finden Sie Ihr neues Online Casino und profitieren Sie von einem exklusiven Angebot, das Ihnen am besten gefällt.

Klicken Sie hier, um unsere Webseite zu besuchen.
http://www.

zbestclubreview2014.com/
Mit freundlichen Grüßen

Bitte klicken Sie hier, wenn Sie von uns keine E-Mails mehr erhalten wollen:
http://unsubscribe.
zbestreview2014.com/


  • Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.
SPAM-Mail Screenshot
  • Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.

MALICIOUS DOMAIN(s): PHISHING, SCAM, SPAM

MAIL SENT THROUGH:
http://de-graaf.nl/
  • https://www.virustotal.com/de/url/9a2407169f616b2a2a036d1f5bdfdc1b586c3da935cbeb9586e394db4ebdb792/analysis/1393265245/
HTML (TITLE: test igr)
  • https://www.virustotal.com/de/file/897f06db515c21290c30c57dd1af5866fb260e19c213dd86af0c991bf5b2ab5f/analysis/1393265111/
IP:
http://109.109.120.43/
  • https://www.virustotal.com/de/url/3ea4a1d473e5c5d071795108a2ac018278483b00a9f78f903666ea1d8966dc72/analysis/1393265363/
  • https://www.virustotal.com/de/ip-address/109.109.120.43/information/
HOSTNAME:
http://pernis.cbizz.nl/
  • https://www.virustotal.com/de/url/1ffd59fd6c336547198255126d30d61be74c67d3ef51ad3dccac2037c71b43fa/analysis/1393265933/
HTML (PUA - LIKELY HOSTILE)
  • https://www.virustotal.com/de/file/b360defdc2da0baa651a970842c02965c9c7abf9aa64fc1313f4a4a1108faf3d/analysis/1393266111/
GETFILE: http://jsunpack.jeek.org/?report=516635988cbc568d4d2d43d0ad9c0e190325b4be
PUA.JS.Obfus-7
  • http://virusscan.jotti.org/de/scanresult/9bac55894b100053305d87eaf342fd1d7b967b33
  • http://www.UnmaskParasites.com/security-report/?page=pernis.cbizz.nl
DOMAIN:
http://cbizz.nl/
  • https://www.virustotal.com/de/url/1ef1ca00c396eeda1ca723d3780b7b912674431c8f5e5aff3d81e5c0b374a59b/analysis/1393266792/
----------------------

SPECIFIC "CASINO" (MALWARE) DOMAIN:
http://www.zbestclubreview2014.com/
  • https://www.virustotal.com/de/url/02ee438ea4071e0839c5b4f0839c174ff0413423e74f33227791241134dc444c/analysis/1393265668/
UNSUSCRIBE LINK:
http://unsubscribe.zbestreview2014.com/
  • https://www.virustotal.com/de/url/0e33f7e548f5d9685ac666974b4ded4025b0735f14b3e435b0c315555714a755/analysis/1393265770/
ORIGINATING IP ADDRESS:
http://115.242.210.80/
  • https://www.virustotal.com/de/url/98b43e7ad335c2310d1cb232e943d9bf9518613df8ba00d9f5dd41062a54e0c3/analysis/
LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/query/bl?ip=115.242.210.80
  • http://www.spamhaus.org/pbl/query/PBL386929
EMAIL REPUTATION: POOR
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=115.242.210.80




2/23/2014

Malicious Downloads of EXPRESS FILES:
Domain: pulidecor.com & go-for-files.com
Win32/ExpressFiles
(U.S.A., U.K., Ukraine, Russia, Netherlands)



ExpressFiles are  programs developed by Express Solutions. The most used version is 1.9.3, with over 98% of all installations currently using this version. Upon installation and setup, it defines an auto-start registry entry which makes this program run on each Windows boot for all user logins. A scheduled task is added to Windows Task Scheduler in order to launch the program at various scheduled times (the schedule varies depending on the version). 

The software is designed to connect to the Internet and adds a Windows Firewall exception in order to do so without being interfered with. The programs's main executable is ExpressFiles.exe and has been seen to consume an average CPU of less than one percent, and utilizes about 20.48 MB of memory. It also adds an icon to the Windows notifications area in order to provide access to the program. A vast majority of those who have this installed end up removing it just after a couple weeks. 

The software installer includes 10 files and is usually about 9.09 MB (9,531,113 bytes). EFUpdater.exe is the automatic update component of the software designed to download and apply new updates should new versions be released. In comparison to the total number of users, most PCs are running the OS Windows 7 (SP1) as well as Windows 8. While about 22% of users of ExpressFiles come from the United States, it is also popular in Italy and Germany.

For more on this Threat, see here

MALWARE SITE: EXPRESS FILES (RBN 434)

DOMAIN:

http://pulidecor.com/
  • https://www.virustotal.com/de/url/faf2ea9682c998e9a7d44c054d6f9483e682cd3cbe1bf8ecdbf0f0ad82587cbb/analysis/1393154354/


MALICIOUS LINK:

http://pulidecor.com/KID-ICARUS-DOWNLOAD-CODE.htm
  • https://www.virustotal.com/de/url/8e8fb70f7504c3fc967981edcb7bd1ba0d50832cd5366ebda348434398dc12a1/analysis/1393153202/
Express Files
  • https://www.virustotal.com/de/file/2edf84f8a5daef6398a5a44a730d6c7917c4f25e41cfaf2ff5ba144031aa006e/analysis/1393153844/
  • https://urlquery.net/report.php?id=9609071
------>

DOMAIN/IP:

http://93.174.88.93/
  • https://www.virustotal.com/de/url/97e56e02bb235d9b4d8603a2e189479745361911c618102fa066d4d3b26276cd/analysis/1393155556/
  • https://www.virustotal.com/de/file/94ee059335e587e501cc4bf90613e0814f00a7b08bc7c648fd865a2af6a22cc2/analysis/1393156281/
 
MALICIOUS LINK:
http://93.174.88.93/go.php?q=KID-ICARUS-DOWNLOAD-CODE
  • https://www.virustotal.com/de/url/1fa617458a620b8e6b4c10b903d987b5f1457d22e1addef94abe1da2012f8529/analysis/1393155418/

HTML
  • https://www.virustotal.com/de/file/663de60a22fb540bfd8fae57df84a29e6410b90956c7caaddeb60b7e4c438274/analysis/1393156233/
  • http://wepawet.iseclab.org/view.php?hash=cbe4a405fb132a836b5dd65a79936c98&t=1393155497&type=js
  • https://urlquery.net/report.php?id=9609326
------>

DOMAIN:

http://pushtraffic.net/
  • https://www.virustotal.com/de/url/36276552d4b9b922202792af9bb487791f37eacb6b84154cbef2b8ac07d9b0dd/analysis/1393156637/

HTML (Friendly Error Page...Looool)

  • https://www.virustotal.com/de/file/761bbfe842ec7b0a1861abddca602c1525cd4555a7a56d91cf582511f26f07b4/analysis/1393156583/

MALICIOUS LINK:

http://pushtraffic.net/TDS/?wmid=99934&uid=969&q=KID-ICARUS-DOWNLOAD-CODE
  • https://www.virustotal.com/de/url/043abe5c83ca189dde5ec8d475c706aa7d822fee1c5e57a553e1a9e1044fde89/analysis/1393155686/

HTML

  • https://www.virustotal.com/de/file/fe76e106d6e3f1e9ec900de0a09d3e55f25516ea7400ddef4d2bafc4c9f97be8/analysis/1393155858/
  • http://wepawet.iseclab.org/view.php?hash=be6ba6e4122acfb113c66af27b22fbd6&t=1393155899&type=js
  • https://urlquery.net/report.php?id=9609355
TO GET TO THE FULL REPORT, CLICK THE ICON .txt :


Document hosting: UploadEdit.com

1/23/2014

MALICIOUS DOMAIN: top100blogs.4you.cloudns.us
(PHISHING & Paid Links - Netherlands)





POTENTIALLY MALICIOUS DOMAIN:

top100blogs.4you.cloudns.us
  • https://www.virustotal.com/de/url/113d96e224923eceebeb484e92aacd0f6d929d81b79f014503a3c8276fb852e8/analysis/
  • http://www.browserdefender.com/site/top100blogs.4you.cloudns.us/
  • http://quttera.com/detailed_report/top100blogs.4you.cloudns.us
  • http://sitecheck.sucuri.net/results/top100blogs.4you.cloudns.us
  • http://www.urlvoid.com/scan/top100blogs.4you.cloudns.us/

12/27/2013

Cybercrime Review Who is Who:
Anil Kheda (Rampid Interactive Hacker)

In November 2012 Anil Kheda, a dutch National, got charged under federal constitution in the District of New Hampshire with allegedly conspiring to hack into and disable computer servers belonging to Rampid Interactive, a New Hampshire-based company that publishes and hosts a multi-player online role-playing game called “Outwar” (+75.000 active players).

From November 2007 to August 2008, Anil Kheda (the "Leader") and some additional members of the Plot, all of whom were avid “Outwar” players, accessed Rampid’s computer servers without authorization and rendered “Outwar” unplayable for days at a time.

They also used their unauthorized access to Rampid’s servers to alter user accounts, causing the restoration of suspended player accounts and the accrual of unearned game points, and to obtain a copy of all or portions of the “Outwar” computer source code, which they used to help create a competitor online game, named “Outcraft.”

The indictment also stated that Kheda and his alleged online buddies sent Rampid interstate communications threatening to continue to hack into Rampid’s computer systems unless Rampid agreed to pay them money or provide them with other benefits. Kheda claimed to have found vulnerabilities in the Rampid's network and the Outwar source code that allowed him to gain administrator access to the underlying functions of the game.

His ability to repeatedly delete a user database seems to indicate his claims were at least partially true. This lack although, caused Outwar to go down for a total of about two weeks over the nine-month stretch, causing Rampid to lose more than 100.000 USD in lost revenues, wages, hosting costs, long term loss of business, as well as the loss of exclusive use of their proprietary source code, which it had invested approximately 1.5 million USD in creating the Platform.

 According to court documents, Kheda earned approximately 10.000 USD in profits from operating “Outcraft,” which has approximately 10.000 players worldwide.

"You guys have the following three options," Kheda wrote in a December 2007 e-mail included in the federal indictment.":
1. Let me play again on my master account (with everything that was on it), and I will report everything when I come across a vulnerability. 
2. Pay me $1500 and you will never hear from me again. 
3. Don't reply to this e-mail and you are gonna wish you picked one of the other options.
During another exchange with Rampid employees, Kheda allegedly demanded he be given the name and address of a fellow hacker called Pimpster, who is listed as an unindicted co-conspirator in the indictment. Kheda ultimately demanded he be given contact details for the UK juvenile after he backed out of the alleged conspiracy to hack Rampid's network, according to prosecutors.

"Pimpster may have pussed out after [an employee at Rampid] called his mom, I'll never talk to that noob snitch again," Kheda wrote, according to the indictment. "However I am still around, you guys probably thought that pimpster has been doing this all by himself, think again noobs."



What finally Sentence Kheda received (or not) is so far unknown, as i checked the Web, but came up with nothing so far. Kepping an eye on it although.

12/25/2013

Malicious Site: www.itv-h.nl - Blackhat SEO Rogue Medications SCAM, SPAM, PHISHING

BLACKHAT SEO SPAM (Viagra, Cialis & co.) (TDS URL PATTERN)
https://www.google.com/search?q=%22Cheap%20Vista%20for%20Students%22%20site%3Awww.itv-h.nl#q=%22Viagra%22+site%3Awww.itv-h.nl



DOMAIN

www.itv-h.nl
https://www.virustotal.com/de/url/db0b7cacafa60e9af86d59ffd9cb50607746297dc4a696b44f90ebcd22166709/analysis/1387967753/

SPECIFIC URL:
www.itv-h.nl/viagra-kob.html
https://www.virustotal.com/de/url/dd8f10f702e672d1ec9dff469c0db539494b6dc782d80ec296d07f83782c4ee7/analysis/1387967607/

TDS URL PATTERN
https://urlquery.net/report.php?id=8541346

---> REMOTE DOMAIN
keycollector.pw
https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1386973287/

SPECIFIC URL:
keycollector.pw/go.php?sid=1
https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387967941/

TDS URL PATTERN
https://urlquery.net/report.php?id=8541376

--->
edapotek.eu
https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387967991/

12/17/2013

Hackers Gift or a Gift for Hackers: A Question to IT company's, why are they making hackers lives easy ?

IT companies are failing to secure devices connected to the internet, leaving them open to hackers and Malware. This shocking report reveals how anything from your pins to your passport could be accessed online right now !


"Is this your pin? Is this a letter you received from your bank? Do you have a HP e-Print scanner?"

The young man answers yes to every question, stunned that all of his information was accessible on the internet for anyone who wanted to see it.

And he's not alone: the wealth of information available is staggering. From shop owners whose security cameras can be watched and controlled remotely, to medical records and confidential documents for international companies like Unilever, Orange and KLM, it's a bonanza for any would-be hackers.



While it would be simple for the IT firms who provide printers, scanners and software to make the system more secure, they don't see it as their problem and argue that attending to basic safety protocols is a bit of a marketing nightmare. "There are people who know all about how this works, security-wise, but it's too much trouble to explain all that."

One company went so far as to call consumers who didn't know they had to change their passwords "idiots". As the rate of technological change continues at a frightening pace, do technology companies have a duty to prevent our privacy being eroded ? Find out yourself in the next 30 Minutes.

12/12/2013

VIDEO: Panopticon - The Rise of the Surveillance State


This Video (Netherlands) takes an insight into the growing Surveillance Strategies in the 21st Century.
9/11 started this Process, but can we limit the Size overpowering us. How is this exactly happening and in which way will it effect all our lives ? See the Video from 2012:


12/07/2013

Pony Botnet Controller - Facebook, Google, Twitter, Yahoo:
Almost 2 Million Usernames & Passwords Stolen in a Mass Hack

Almost 2 million accounts on Facebook, Google, Twitter, Yahoo and other social media and Internet sites have been breached, according to a Chicago-based cybersecurity firm.


The hackers stole 1.58 million website login credentials and 320.000 e-mail account credentials, among other items, the firm Trustwave reported in a blogpost. Included in the hacks were thefts of 318.121 passwords from Facebook, 59.549 from Yahoo, 54.437 from Google, 21.708 from Twitter and
8.490 from LinkedIn. The list also includes 7.978 from ADP, the payroll service provider.

According to Trustwave, "Payroll services accounts could actually have direct financial repercussions."

Stolen Passwords by Day
Most of those stolen passwords were from the Netherlands, followed by Thailand, Germany, Singapore, Indonesia and the United States, which accounted for 859 reports from machines and 1.943 passwords, according to Trustwave. All inn all, just over 100 countries were affected, and Trustwave said this shows the attack is "fairly global."



The hacking began October 21st 2013 and might still be taking place, according to a CNN article, on this case.

The massive data crack was a result of keylogging software maliciously installed on an untold number of CPUs around the world, according to researchers at Trustwave. The Malware was capturing log-in credentials for key websites over the past month and sending those usernames and passwords to a server controlled by the hackers. On November 24th 2013, Trustwave Analysts tracked that server, located in the Netherlands. Google itself declined to comment on this subject.

John Miller, a security research manager at Trustwave, told CNN, "We don't have evidence they logged into these accounts, but they probably did." (So what now....?)

Miller said the team doesn't yet know how the virus got onto so many personal computers. The hackers set up the keylogging software to rout information through a proxy server, so it's impossible to track down which computers are infected.

Among the compromised data are about 41.000 credentials used to connect to File Transfer Protocol (FTP, the standard network used when transferring big files) and 6.000 remote log-ins.

 There are several other servers Trustwave has not yet tracked down, Miller said. ADP, Facebook, LinkedIn and Twitter told CNN they have notified users and reset passwords for compromised accounts. Google declined to comment and Yahoo did not respond immediately.

In compiling the data, Trustwave also discovered that many users are doing just what computer specialists advise against, using simplistic passwords that can easily be guessed. For instance, the top five passwords Trustwave found in researching the breaches were: 123456, 123456789, 1234, password and 12345.

Read the whole Blogpost from Trustwave @:
Look What I Found: Moar Pony!

SOURCE: Money CNN