Translate

Posts mit dem Label PUA werden angezeigt. Alle Posts anzeigen
Posts mit dem Label PUA werden angezeigt. Alle Posts anzeigen

5/05/2014

ANALYZING HASHES
MD5: 589eb00c8d071f8b81a782772dde514a
PUA.Win32.Packer.Asprotect-2 (Heur.Win32.Veebee.3!O)

FROM:

http://athan.islamicfinder.org/screensavers/Ramadan1.exe
  • https://www.virustotal.com/de/url/2ffeb9ca413dc2756602d3650c0d178698b0b19c573bfeeedbb46584842934f4/analysis/1399297572/
PUA.Win32.Packer.Asprotect-2
  • https://www.virustotal.com/de/file/7e6b28c0b34dd2bf037e80016e38636e64e5d9e0f7ad939c69c4895e32e74200/analysis/1399297418/
  • https://urlquery.net/report.php?id=1399297906951


MD5: 589eb00c8d071f8b81a782772dde514a INCLUDES:

1) ConfigureScr.exe
  • https://www.virustotal.com/de/file/dd4d2dd4690f895ee3e4a6dc319e8ed4e7282f21bc818dfed49068873fc01353/analysis/1399298315/
2) Ramadan1.SCR
Heur.Win32.Veebee.3!O
PUA.Win32.Packer.Asprotect-2
  • https://www.virustotal.com/de/file/cdc9ed6d336b530f70adce5e836eccd5da7ec06447594a3830ed10af20f18dcd/analysis/
3) RemoveScr.exe
  • https://www.virustotal.com/de/file/52a7f3cb893fdaf4aa2a7f20b585047b2b128b07a10d7f0606222d990d40cd49/analysis/1399298943/

4/26/2014

PHISHING: Re: Bestellbestätigung.
"ACHTUNG ! Sondernewsletter !"
FROM:
Snowshoe Spammer mawamalai.com (IPs: 79.124.56.67 - 79.124.56.70)
PUA.JS.Xored

BULGARIA



ACHTUNG! Sondernewsletter!

Sie haben keine Bestellung bei uns getätigt. Sie werden es aber wie 97.2% der Leser tun, wenn Sie diese Mail gelesen haben!
Rührende Geschichte bringt Moderatorin von "Raus aus den Schulden" zu weinen!

Arbeitslos und mit über 130.000 Euro verschuldet!
Dieser Mann änderte sein Leben und verdient mit diesem System bis zu 263,69 Euro am Tag!
Bald von hohen Schulden zum Reichtum? RTL2 testete Live im TV!

Die Moderatoren waren verblüfft! Sie können es auch! Uns zwar absolut KOSTENLOS!
Doch es gibt einen Haken! Dieses Patent wird ist leider stark begrenzt.
Denn der Patentbesitzer hat dieses System an eine US Bank verkauft!

Nur Diejenigen, die sich noch rechtzeitig registrieren, dürfen das System lebenslänglich kostenfrei nutzen!

Schauen Sie sich schnell das Video an, das Ihr Leben verändern wird!


HIER GEHT ES ZUM VIDEO

Sollte der Link nicht funktionieren, dann kopieren Sie bitte die Domain in den Browser: http://b-unitd.com/9uy

Click here to unsubscribe


Mail Screenshot

PHISHING SPAM-DOMAIN: 
FROM BULGARIA
http://mawamalai.com/
  • https://www.virustotal.com/de/url/6896cabd8597b88bada31b7daa824a29a707f6ab3078291cc0fc256bdbdbdf12/analysis/1398514506/
HTML:
  • https://www.virustotal.com/de/file/dbb6e6caba47b4688bd5a128e57eb8d26620942b13d5b07a0fa51d75fde63d2a/analysis/1398514432/

*********************************************************************************************************************

ANALYSIS IP: 79.124.56.67
http://79.124.56.67/
  • https://www.virustotal.com/de/url/ef621203c8c566900d8a693072d085991dd8111f907a5a97aa828560f19ede02/analysis/1398517859/
Invalid HTML data
  • https://www.virustotal.com/de/file/b7bd64ddcc323a81ffc9806c613c863132802289e9bc57f62affcce235d996e9/analysis/1398517950/
  • https://www.virustotal.com/de/ip-address/79.124.56.67/information/
HOSTNAME:
http://news1.bowntymailer.com/
  • https://www.virustotal.com/de/url/73c6ee9f15bc9c283a3281fa27d6dc857f8a92ee572d3733bc96ebe6247f05d6/analysis/1398521012/
REDIRECTS TO:
http://79.124.56.67/cgi-sys/defaultwebpage.cgi
  • https://www.virustotal.com/de/url/aec08d798876325028714570d7ccaedfe9ac44e8c7001c4b7734aaa322657d64/analysis/1398519269/
IP 79.124.56.67 IS BLACKLISTED AT:

1)
SPAMHAUS (SBL): SNOWSHOE SPAMMER
  • http://www.spamhaus.org/query/bl?ip=79.124.56.67
  • http://www.spamhaus.org/sbl/query/SBL213606
  • http://www.spamhaus.org/sbl/listings/telehouse.bg
http://telehouse.bg/
  • https://www.virustotal.com/de/url/4a0a98bd45413718c532b3128cfc59a15f8b8ba7bc5195fab8c9042cab9d827b/analysis/
2)
WOT:
  • https://www.mywot.com/en/scorecard/79.124.56.67
3)
spam.abuse.ch:
  • http://dnsbl.abuse.ch/?ipaddress=79.124.56.67
4)
WEB-REP: POOR
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=79.124.56.67

*********************************************************************************************************************

Originating PHISHING-MAIL-IP Address: 79.124.56.70
http://79.124.56.70/
  • https://www.virustotal.com/de/url/94a3d7b252550f754c522cbee1ab45246f8c8ec7d5f69be7165d0f2289ffe12a/analysis/1398519845/
  • https://www.virustotal.com/de/ip-address/79.124.56.70/information/
Invalid HTML data
  • https://www.virustotal.com/de/file/b7bd64ddcc323a81ffc9806c613c863132802289e9bc57f62affcce235d996e9/analysis/1398517950/
  • https://www.virustotal.com/de/ip-address/79.124.56.70/information/
HOSTNAME:
http://news4.bowntymailer.com/
  • https://www.virustotal.com/de/url/07f76972f4be2bd08f85c65791eb977f9ae1eb70c410ca5a74dabe047c66ea2c/analysis/1398520764/
REDIRECTS TO:
http://79.124.56.70/cgi-sys/defaultwebpage.cgi
  • https://www.virustotal.com/de/url/1dff6d9729554c1422fd204c39c3c16d202a9ec6ac2822f2eeabfc6e921a7983/analysis/1398520085/
IP 79.124.56.70 IS BLACKLISTED AT:

1)
SPAMHAUS (SBL): SNOWSHOE SPAMMER
  • http://www.spamhaus.org/query/bl?ip=79.124.56.70
  • http://www.spamhaus.org/sbl/query/SBL213606
  • http://www.spamhaus.org/sbl/listings/telehouse.bg
http://telehouse.bg/
  • https://www.virustotal.com/de/url/4a0a98bd45413718c532b3128cfc59a15f8b8ba7bc5195fab8c9042cab9d827b/analysis/
2)
WOT:
  • https://www.mywot.com/en/scorecard/79.124.56.70
3)
spam.abuse.ch:
  • http://dnsbl.abuse.ch/?ipaddress=79.124.56.70
4)
WEB-REP: POOR
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=79.124.56.70

*********************************************************************************************************************

OTHER LINKS CONNECTED TO THE PHISHING MAIL:

1.0
http://mawamalai.com/link.php
  • https://www.virustotal.com/de/url/7db23e02d8d6153c472dc14a24fb6a995875b1bb2fb271bf57cd42f78a7196ba/analysis/1398514872/
  • https://www.virustotal.com/de/file/23d32b79f3e71e41c2eb3d8811f58f72a2b6b5eb04c0981f16f61ab009945054/analysis/1398434545/
1.1
http://mawamalai.com/open.php
  • https://www.virustotal.com/de/url/dab2df490d9409a591b7b634045eb4699e62a0e15409a21de06efc1b305d456d/analysis/1398514992/
  • https://www.virustotal.com/de/file/dd5bdccb831d1b19c505bd3e67553f6049cea2e20dba7eb231a02ed0103e521f/analysis/1398169420/
1.2
http://mawamalai.com/unsubscribe.php
  • https://www.virustotal.com/de/url/e46fa0421bfd53d4679c0d1fd2005a9b877cce218e9773c9302d4bacaa09cb1b/analysis/1398515065/
  • https://www.virustotal.com/de/file/baefeec3f91b70b39b03c556d29dd1ad4eff87fe7bb0ba91fc3b774e70089281/analysis/1397141557/
2.0 (AS YOU CAN SEE IN THE MAIL-SCREENSHOT)
http://b-unitd.com/9uy
  • https://www.virustotal.com/de/url/5509e6b6e3a8aea57a3d1f566f2823d2cfea8dc636069e390ac91a7de7985732/analysis/1398515235/
REDIRECTS TO:
http://tracker.regaloptions.com/9uy
  • https://www.virustotal.com/de/url/f264470eb6d29a18bd40c6451cf1a21ae7341a3db08bf4a34352c799c9cc7c95/analysis/1398515582/
REDIRECTS TO:
http://www.projekt95pro.com/?campaign=6739&ft=1&p=jsbfaeyJhIjoiMTAwODg4IiwiYyI6IjEzOTg1MTUyNjg2NzU0ODY5MDMifQ==
  • https://www.virustotal.com/de/url/9f7dbb1fb3caa99f8b80908ee4e17c5be0c176938a8953b5f58d66fbaf4c56a7/analysis/


HTML:
  • https://www.virustotal.com/de/file/876dfcc859ab841d81c38c7ae8195570475b176540797ace7223e0b2af998976/analysis/1398515488/

(FROM 2.0) OR TO !:
http://tracker.cedarfinance.com/
  • https://www.virustotal.com/de/url/b74481dafb943ce7417addb8795ca57b616850f4cb3b93950c215203b14f95ca/analysis/1398515998/
REDIRECTS TO:
https://www.cedarfinance.com/?ft=1
  • https://www.virustotal.com/de/url/89eb4f88e14c1c1b12a1ecdba00c72c4b360d70235b10b0db0a18437b79766ad/analysis/1398517210/

OTHER SUSPICIOUS LINK FROM mawamalai:
http://mawamalai.com/admin/includes/js/javascript.js
  • https://www.virustotal.com/de/url/f1d7cbde38ced99e4fc12d0265eeca61a5bdba41fd3aa60a8f04c36dc57b5e6c/analysis/1398516567/
PUA.JS.Xored
  • https://www.virustotal.com/de/file/40ea889122eaed21758c286ac2eb832a1f7263abc47e60f538e8360511c009be/analysis/
  • http://virusscan.jotti.org/de/scanresult/b14d12cc39c2a0ee18b3df555067046fdaa75169

3/29/2014

RECENTLY (RE-)DETECTED:
afristyle.com infected with HEUR:Trojan.Script.Iframer
IP: 160.124.112.100 - SOUTH AFRICA



MALWARE: HEUR:Trojan.Script.Iframer
DOMAIN:
http://afristyle.com/
  • https://www.virustotal.com/de/url/94e4f0d5dec56125cc4ac81ecd1aea5438e8ee9191f9a1ddee5729b370a5ee3f/analysis/1396113676/
HEUR:Trojan.Script.Iframer (PUA, document write)
  • https://www.virustotal.com/de/file/61b5f2266af649aeb40b3c12cb9b437da4c9b09492cff6aaf2fe4c33f46401e0/analysis/1396113489/
IP:
http://160.124.112.100/
  • https://www.virustotal.com/de/url/34dfd6f154e8f0f124b31235af491ff951386a432cf009980d5abed411171b24/analysis/1396114396/
  • https://www.virustotal.com/de/ip-address/160.124.112.100/information/
--->
http://find.uk.to/dns.htm
  • https://www.virustotal.com/de/url/9882d00fcdca159baba47dd3f0b38cb7277532978e54e483d51da98599153adf/analysis/1396114311/
  • https://urlquery.net/report.php?id=1396113767846

3/12/2014

BAYER 04 LEVERKUSEN TRACKING FANS:
www.bayer04.de & Obfuscated PUA
(Leverkusen, GERMANY)


MALICIOUS BACKGROUND INTENT:
OBFUSCATED JS (PUA, TRACKER, SPYING) OUTSIDE THE HTMLSRC-HEADER

http://www.bayer04.de/
  • https://www.virustotal.com/de/url/b7d931cbc1a767be418ce46c6a010fc0c55d8cf7efd19ea827c0efc7ba8b6f46/analysis/1394658933/
Obfuscated PUA Link:
http://www.bayer04.de/webtrekk/webtrekk.js
  • https://www.virustotal.com/de/url/8a7ee2b1aed1dbbf6ee9e775ad9e098523120650cbf3248df0b8d5b118a6151b/analysis/1394659517/
PUA.JS.Obfus-2
  • https://www.virustotal.com/de/file/e004c9f7e78fa72379e72f04b2b897ec3f57f74675d25966c9cd1b6b5ad1ba84/analysis/1394659379/
  • http://virusscan.jotti.org/de/scanresult/725ffacc8f21b11ad85a21ba3b1c435d501aba89
IP =
http://184.25.102.88/
  • https://www.virustotal.com/de/url/55b77a9dbfd0212684dd8e10f930ab2db452cb09099358806dc2f5ac05bf1dc0/analysis/1394661164/
  • https://www.virustotal.com/de/ip-address/184.25.102.88/information/

2/28/2014

Category MALICIOUS IP: 67.225.146.147 (wpnoupfront.authenticbd.com)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES & RUSSIAN FEDERATION)

The IP address 67.225.146.147 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "wpnoupfront.authenticbd.com", and this link is an example of the redirect: "http://wpnoupfront.authenticbd.com/invigorating.htm". In other words the website "wpnoupfront.authenticbd.com" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.

No Time to lay back...
In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "wpnoupfront.authenticbd.com" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly http://wpnoupfront.authenticbd.com itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.

Related Post: http://stayaway2.blogspot.com/2014/02/us-phishing-visitor-to-this-blog.html

REFERENCES:
67.225.146.147
  • https://www.virustotal.com/de/url/30de5a071652e44f8f6003ab0c22553e72808bfec8aa5982ae23fb7badde4857/analysis/1393510660/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=67.225.146.147
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=67.225.146.147
----------------------------------------------------------

http://wpnoupfront.authenticbd.com/
  • https://www.virustotal.com/de/url/1fb32860105dea70846f611020d9ba6c2a4557c5337ded5e1dcbe83b51b9641d/analysis/1393517602/
  • http://urlquery.net/report.php?id=9691230
http://wpnoupfront.authenticbd.com/invigorating.htm
  • https://www.virustotal.com/de/url/071ca9f4199a95b2d2824d0207e8c6287c20458ad1f87b80ac37a9a36ec2de9b/analysis/1393517601/
HTML:RedirME-inf [Trj]
  • https://www.virustotal.com/de/file/5f0925c559ea8e1285877f550f361a92770d54528f8800ab181bdc1a0c039427/analysis/1393520355/
  • (GETFILE: http://jsunpack.jeek.org/dec/getfile?hash=8ff9/ed8ea2a207c8f4ae5c70dac68556d6ff425a)
---> REDIRECTS TO
http://doctorxonft.ru/
  • https://www.virustotal.com/de/url/0512b24fcc96129c9951e4f5103bfed2312c9fe359403ed3a6ec36e6ced2e962/analysis/
HTML (PUA.JS.Obfus-7)
  • https://www.virustotal.com/de/file/8aad19003d4937d93cf60ff7f8457c231e4b72110d380a4c6a2e133b1e169fae/analysis/1393521420/
  • http://virusscan.jotti.org/de/scanresult/baf1b8fc0d963713dd61f1f9549226321e068189

FULL REPORT:
Document hosting: UploadEdit.com

2/27/2014

New Malware Code found on IRANIAN Blogsite (involved in Phishing):
model-irani.mihanblog.com infected with
Trojan.JS.StartPage.eg (Former HEUR:Trojan.Script.Generic)
(IP: 5.144.133.146)



FOLLOWUP:
New Malicious Code:
From: HEUR:Trojan.Script.Generic
To: Trojan.JS.StartPage.eg


MALWARE: HEUR:Trojan.Script.Generic (PHISHING ACTIVITIES) IRAN

DOMAIN:

http://model-irani.mihanblog.com/
  • https://www.virustotal.com/de/url/87e504b01108edfe5de0f78bee9f91b014661af9abf0bcbb8625b88ceeb18258/analysis/1393498401/

INFECTION:

HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/9ad90edf6be055ce40cdc01608f58783e6aa45bed1453e760b1afbfbbcb025b0/analysis/1393498623/
--->
http://static.mihanblog.com//public/scripts/run/g.other.v3.js
  • https://www.virustotal.com/de/url/0bdd1749892dbca59d44f29f3d008f5639aeb8be37ec4deb6873ada600e84505/analysis/1393498967/
PUA.Script.Packed-2
  • https://www.virustotal.com/de/file/9c7e6c2ebd2ac2b10978a8627e31d1cd287aa43f19e5a8233b018103dad507d2/analysis/1393498970/
FOR THE FULL REPORT CLICK THE .txt ICON:


Document hosting: UploadEdit.com

2/25/2014

Solimba Installer
Category MALICIOUS DOWNLOADS: dl.downloadohdooshieyei.com
(IP: 165.254.155.129) Englewood, Colorado, United States


MALWARE SITE: MALICIOUS DOWNLOADS (Solimba Installer)

DOMAIN:
http://dl.downloadohdooshieyei.com/
  • https://www.virustotal.com/de/url/ef7757bab9e69849807f527d515ab673778d76a3e3cb8f1d2da775a2d5dfb199/analysis/
MALICIOUS DOWNLOAD LINK:
http://dl.downloadohdooshieyei.com/n/11812101/N0636.exe
  • https://www.virustotal.com/de/url/7be861a3b2d6b26d20a103730f77fdbdc3248682700ebd2405ef0002db822494/analysis/1393347015/
FUNNY 2 DIFFERENT FILES:
  • FILE DOWNLOADED BY VT:
N0636.exe Solimba Installer
  • https://www.virustotal.com/de/file/6b76dc210986bb989da482ef6a8bd19cf8438c832e4c8b8984f15c8567c342e5/analysis/1393347021/
FILE FROM JSUNPACK:
  • http://jsunpack.jeek.org/?report=c631008f24cb11be18ffb6c52628296e2f878c79
  • https://www.virustotal.com/de/file/814f68ccb748f3bbe2cf34078ca219b6ce59f0c079d3e21b0320c8153fa15300/analysis/1393347080/

2/24/2014

GREATSOFTWARE.COM:
www.greatsoftware.com & dl.downloadohdooshieyei.com
(MALICIOUS DOWNLOADS from NORWAY & FRANCE)


MALWARE SITE (DIRECTLY & INDIRECTLY): MALICIOUS DOWNLOADS

DOMAIN:
http://www.greatsoftware.com/
  • https://www.virustotal.com/de/url/944ea52f2622d40e250fca3d82c5b01920482196479a88a5fc7aa55567828d0c/analysis/1393276144/
MALICIOUS LINK:
http://www.greatsoftware.com/image-merger-exe/
  • https://www.virustotal.com/de/url/ae080a4ba9dff79029475591902616ccde3860d512fc444d14f7d2fd0f313254/analysis/1393276105/
(DONT) CLICK THE DOWNLOAD BUTTON AND YOU WILL GET THE FILE (MALWARE) 

FROM:
http://dl.downloadohdooshieyei.com/n/12372005/Image%20Merger%20.EXE.exe
  • https://www.virustotal.com/de/url/e5a90ede66101c9b432ea464827a5d8c0f47bb8461520eacbea096b4ba9e823a/analysis/1393273342/
(PUA) Win32/FirseriaInstaller.F
  • https://www.virustotal.com/de/file/a43fc03c2fc7519029692d6666c54ea5d8ef478748ec893153ee479607324277/analysis/1393273348/
MALICIOUS DOMAIN:
http://dl.downloadohdooshieyei.com/
  • https://www.virustotal.com/de/url/ef7757bab9e69849807f527d515ab673778d76a3e3cb8f1d2da775a2d5dfb199/analysis/1393274740/


Category MALICIOUS DOMAIN & IP:
www.zbestclubreview2014.com (IP: 115.242.210.80)
Casino, Gambling
(PHISHING, SCAM, SPAM) (Ruby Palace, Mumbai, INDIA)


Auf unseren Webseiten finden Sie die besten Online Casinos mit exklusiven Angeboten, wenn Sie sich über unsere Webseiten registrieren.
Verschiedene Angebote wie Freispiele und Bonusse auf Einzahlungen erwarten Sie.

Besuchen Sie unsere Webseite, finden Sie Ihr neues Online Casino und profitieren Sie von einem exklusiven Angebot, das Ihnen am besten gefällt.

Klicken Sie hier, um unsere Webseite zu besuchen.
http://www.

zbestclubreview2014.com/
Mit freundlichen Grüßen

Bitte klicken Sie hier, wenn Sie von uns keine E-Mails mehr erhalten wollen:
http://unsubscribe.
zbestreview2014.com/


  • Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.
SPAM-Mail Screenshot
  • Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.

MALICIOUS DOMAIN(s): PHISHING, SCAM, SPAM

MAIL SENT THROUGH:
http://de-graaf.nl/
  • https://www.virustotal.com/de/url/9a2407169f616b2a2a036d1f5bdfdc1b586c3da935cbeb9586e394db4ebdb792/analysis/1393265245/
HTML (TITLE: test igr)
  • https://www.virustotal.com/de/file/897f06db515c21290c30c57dd1af5866fb260e19c213dd86af0c991bf5b2ab5f/analysis/1393265111/
IP:
http://109.109.120.43/
  • https://www.virustotal.com/de/url/3ea4a1d473e5c5d071795108a2ac018278483b00a9f78f903666ea1d8966dc72/analysis/1393265363/
  • https://www.virustotal.com/de/ip-address/109.109.120.43/information/
HOSTNAME:
http://pernis.cbizz.nl/
  • https://www.virustotal.com/de/url/1ffd59fd6c336547198255126d30d61be74c67d3ef51ad3dccac2037c71b43fa/analysis/1393265933/
HTML (PUA - LIKELY HOSTILE)
  • https://www.virustotal.com/de/file/b360defdc2da0baa651a970842c02965c9c7abf9aa64fc1313f4a4a1108faf3d/analysis/1393266111/
GETFILE: http://jsunpack.jeek.org/?report=516635988cbc568d4d2d43d0ad9c0e190325b4be
PUA.JS.Obfus-7
  • http://virusscan.jotti.org/de/scanresult/9bac55894b100053305d87eaf342fd1d7b967b33
  • http://www.UnmaskParasites.com/security-report/?page=pernis.cbizz.nl
DOMAIN:
http://cbizz.nl/
  • https://www.virustotal.com/de/url/1ef1ca00c396eeda1ca723d3780b7b912674431c8f5e5aff3d81e5c0b374a59b/analysis/1393266792/
----------------------

SPECIFIC "CASINO" (MALWARE) DOMAIN:
http://www.zbestclubreview2014.com/
  • https://www.virustotal.com/de/url/02ee438ea4071e0839c5b4f0839c174ff0413423e74f33227791241134dc444c/analysis/1393265668/
UNSUSCRIBE LINK:
http://unsubscribe.zbestreview2014.com/
  • https://www.virustotal.com/de/url/0e33f7e548f5d9685ac666974b4ded4025b0735f14b3e435b0c315555714a755/analysis/1393265770/
ORIGINATING IP ADDRESS:
http://115.242.210.80/
  • https://www.virustotal.com/de/url/98b43e7ad335c2310d1cb232e943d9bf9518613df8ba00d9f5dd41062a54e0c3/analysis/
LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/query/bl?ip=115.242.210.80
  • http://www.spamhaus.org/pbl/query/PBL386929
EMAIL REPUTATION: POOR
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=115.242.210.80




2/14/2014

ABBA (S.O.S.) & New Malware Code:
www.abba.it & IP 79.135.167.28
Trojan.JS.Iframe.ahh & Trojan.JS.Iframe.ahi (PUA) (ITALY & POLAND)






ABBA MALWARE AT LEAST SINCE 2012: HEUR:Trojan.Script.Iframer (PUA) (RBN 351, ITALY & POLAND)


http://www.abba.it/
  • https://www.virustotal.com/de/url/84645d2eca6550ebd7c47540670934f2383b374162aac5210fe7b6be7e5704e9/analysis/1392389097/

INFECTION:

HEUR:Trojan.Script.Iframer (PUA)
  •  https://www.virustotal.com/de/file/3f6d4bcd51b2a294897c1e76402fc2ec956a411ac92acbe7f89029748eae3522/analysis/1392389334/

The complete report (.txt) can be seen here:

Document hosting: UploadEdit.com


1/19/2014

Malicious U.K. Site: secure.rocketdlgo.com
POTENTIALLY MALICIOUS DOWNLOADS (PUA)


MALICIOUS DOMAIN: MALICIOUS DOWNLOADS (PUAs)
secure.rocketdlgo.com (LONDON)
  • https://www.virustotal.com/de/url/36ed680720c344c20d4265de97ffc49efd5c3932f21ef54938b5e260b55f66f1/analysis/1390121354/
MALWARE (PUA) LINK (out of many):
secure.rocketdlgo.com/nsi/nsis-html/Microtraffic_5485.exe
  • https://www.virustotal.com/de/url/fdb52ef1459d2cd2c98423e3f6cb0915b4ce2b0621a190257901013bdeefa7f2/analysis/1390121715/
INFECTED: Win32/InstallMonetizer.AG
  • https://www.virustotal.com/de/file/ca51c74ae63a852388ffa13f842a6c4e7b3d32be8afedb49705aaf837a2ea54a/analysis/1390121994/
  • http://www.urlvoid.com/scan/secure.rocketdlgo.com/
  • http://zulu.zscaler.com/submission/show/dfc38710b3e03079599ec5cb922e7113-1390121373

For additional Info see:

http://malwaretips.com/blogs/pup-optional-installmonetizer-a-removal/

11/18/2013

Category MALICIOUS IP: 46.165.228.246
(Interception of a Rogue ad Campaign) with Thanks to Dancho Danchev

Another rogue ad campaign (Not to be confused with Advertising campaign) has been intercepted, attempting to trick users into installing the EzDownloaderpro PUA (Potentially Unwanted Application). Primarily relying on that catchy attitude “Play Instantly, Download Now” banners, the visual social engineering tactic of this campaign is similar to other PUA related campaigns that had previously profiled. Let’s take a look at this new rogue ad campaign, and provide relevant threat intelligence on the infrastructure behind it.



Domain  surveillance of some specific Redirects: 

Location Data: San Francisco
------------------------------------
superfilesdocumentsy.asia/v944/?a=1
  • https://www.virustotal.com/de/url/062d123c7599a52d5cd1c42edc8a6971c91ddfe2f336b1bac72860611b8f2702/analysis/1384701938/
PUA: not-a-virus:Downloader.Win32.AdLoad.fwz
  • https://www.virustotal.com/de/file/8567bc9279ca8e7c2be23bfb513eb285d662233bd8528416afb509faef14b389/analysis/1384701943/
IPs:
141.101.117.252 (Cloudflare)
  • https://www.virustotal.com/de/url/89163a510d694d5717eb5dcb88036e7366c96620f36aec26e62e879efeddbc9e/analysis/1384702693/
  • https://www.virustotal.com/de/ip-address/141.101.117.252/information/
141.101.116.252 (Cloudflare)
  • https://www.virustotal.com/de/url/5df0642b589152b807eeb5910b26fe8e9c8c2bf4415f9e3a437d8f5ad4836c37/analysis/1384703661/

------------------------------------------------------------------------------------------------------------------------

applicationscenterforally.asia/v944/?INm
  • https://www.virustotal.com/de/url/110f167f8b1a5c45cfa1531db3226a1b1bd00f191529b3a3e8c222b992a82df9/analysis/1384704601/
Application.Win32.InstalleRex.LL
  • https://www.virustotal.com/de/file/242c3638ad824d612d6ed91823671aaefb503a83f744d6d472d402595d720aac/analysis/1384704604/
  • http://urlquery.net/report.php?id=7774362
  • http://app.webinspector.com/public/reports/18450113
IPs:
108.162.197.34 (Cloudflare)
  • https://www.virustotal.com/de/url/43ee0d2d8d7a39dc1791a85ded58b26f566d60f704069ebeadd465d2ce13a6e7/analysis/1384705270/
  • https://www.virustotal.com/de/ip-address/108.162.197.34/information/
108.162.196.34 (Cloudflare)
  • https://www.virustotal.com/de/url/9f497a74dc2bd7ea5c115c98199212d5bbdbaa625b7e612d17144191b5cec29a/analysis/1384707723/
  • https://www.virustotal.com/de/ip-address/108.162.196.34/information/

------------------------------------------------------------------------------------------------------------------------ 

op.applicationscenterforally.asia/sspcQA/ssa/
  • https://www.virustotal.com/de/url/5311fc57b109651eb8e1a49d70a580881a9e23e7de21e5676f20c6c4df0cd92d/analysis/1384708370/
ADWARE/InstallRex.Gen
  • https://www.virustotal.com/de/file/18a813f5bc905194c727424a17e9b2578d7ee8d76d23804799934b3d76001436/analysis/1384708600/

 ------------------------------------------------------------------------------------------------------------------------ 

Other Domains connecting to the same IP 46.165.228.246 :

• amu.downurfiles.info
• downloadkeeper.info
• driveridentifier-download.com
• ezdownloadpro.info
• iframe.applicationsforentirey.asia
• iframe.applicationsforeveryy.asia
• iframe.filesaredirecty.asia
• iframe.filesareonliney.asia
• iframe.superfilesdatay.asia
• lp.ezdownloadpro.info
• lp.livetrafficall.info
• op.alllinuxapplicationsy.asia
• op.applicationsforcompletey.asia
• op.applicationsforentirey.asia
• op.applicationsforeveryy.asia
• op.bestfilesarey.asia
• op.bestfilesdatay.asia
• op.documentsguidey.asia
• op.documentssitey.asia

Domains who responded to 141.101.117.252:

• 2upl.com
• amu.domainforcompany.info
• andyrohr.com
• bookmarkspiral.com
• filecm.net
• hackstore.net
• happysky.heartbrea.kr
• icephoenixbot.com
• krazywap.ws
• octavis.net

Malicious Message Digest Algorithm 5s known to have been downloaded from 141.101.117.252:

MD5: fd4195ef1af7fb49a673633ed57b87ab
MD5: c0d9713acfc46c2a466a9de77292636d
MD5: d3119ed48cb5896d41aeae4b51f2667a
MD5: c6799f5425fbe038778c4c4a22b35a41
MD5: 840fa1e6c0f81f6da1a347ecb3b2db2e
MD5: c27d4537d24aa55df9837479da2ae111
MD5: c77fc69c7b96c53ce762b87c98831327
MD5: dce1c89d7a267b2a4ae925b5a387e5cd
MD5: a868964e1fe66e4a7638f46ba7844b52
MD5: 2acc54f86694e8d7674e8e1afff86aa1
MD5: 5f078de83a9ce3ee2d9d2fe174cd234c
MD5: 0426e6c1fe2aa8681c683428bb3d2dd7
MD5: efcd92d3be23e624bca2db8515f0df20
MD5: 30ac6dd3290ab3c9281e81c2cba2097e
MD5: 9b35dcacd42e6ba1c596a8bc0425d646

Domains who responded to 108.162.197.34:

• 4agent.info
• advancedchirocenter.com
• albertomolteni.altervista.org
• applicationscenterforally.asia
• asoiaf.westeros.org
• br.singlesfind.us
• buker.ru
• chaochui88.com
• client.ferocitybooter.net
• habbokekos.net
• hentaimate.com
• horny-locals.com
• img.b2bage.com
• onvideogames.net
• op.applicationscenterforally.asia
• papermashup.com
• pdiva.ro
• pinoyhideout.com.ph
• prestamosdinerolosangeles.com
• sdx.cc

 -------------------------------------------------------------------------------



The following File has been downloaded from 108.162.197.34 :
Download.exe 

REFERENCE & Regards to Dancho