Translate

Posts mit dem Label Password Protection werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Password Protection werden angezeigt. Alle Posts anzeigen

3/30/2014

Malicious Blogspotvisitor snapchatpasswordgenerator.blogspot.com

(To this Blog, and probably to many others who
highlight the Snapchat Data-breach a while ago):

PHISHING FOR MOBILE PHONE NUMBERS
Pretending you will win some IPhone, or some other Malware Crap...




PHISHING BLOG: THE bit.ly LINK HAS BEEN FOUND ON THE FOLLOWING BLOGSPOT:
MALICIOUS COMMENT SPAMMER: (SPAMMED MY OWN BLOG)


COMMENT WAS GIVEN ON THIS POST:
stayaway2.blogspot.com/2014/01/hacked-skype-and-snapchat-compromised.html
http://snapchatpasswordgenerator.blogspot.com/
  • https://www.virustotal.com/de/url/d99d7a09c4fdd8b2bf19eae284261183d0884644de04b4e28dfc35a661cceca0/analysis/1396125921/

SUSPICIOUS ActiveX behaviour:
  • http://wepawet.iseclab.org/view.php?hash=a9a04c5facd1c77a6a57444abdb478d2&t=1396123149&type=js

THE OWNER OF THIS BLOG IS (should be) Saad Hashmi (SOUNDS LIKE HASH ME) AND HAS VIDs CALLED: How to Hack Twitter ETC. WHERE SEVERAL VIDs HAVE BEEN REMOVED OR NEVER EXISTED:
https://plus.google.com/101817228413013975367/posts
  • https://www.virustotal.com/de/url/1315983a69f47b3e7a91c6d4dc1148f7eb8ebd773ac7846caf907cd711affbed/analysis/1396127927/

PHISHING FOR MOBILE NUMBERS (SUPPOSING TO WIN SOMETHING) BEFORE DOWNLOADING (DOMAIN):
http://bit.ly/1h4aQgx
  • https://www.virustotal.com/de/url/775bedbd10540c804cd6045beaad4728754a8a35c3a673d9d4df0afaddfe1179/analysis/1396128854/

AT PHISH TANK:
  • http://sitecheck3.sucuri.net/results/bit.ly/1h4aqgx
  • http://www.phishtank.com/phish_detail.php?phish_id=2348877

REDIRECTS TO: --->
http://cleanfiles.net/?stj2nPC
  • https://www.virustotal.com/de/url/025997ab9b0805abdd4d83e9997a54085e2dfbc5ebc39893b1e5c76d27d87916/analysis/1396129645/
  • https://www.virustotal.com/de/file/ef8567646f6f7b246704a8550da770a2beb5f628b154bca2b89bc733a756c1a2/analysis/1396128932/

REDIRECTS TO: --->
http://jlyse.net/?stj2nPC
  • https://www.virustotal.com/de/url/a9e5e6fd72161667774a27f2ecaca3cd16d65a473ac4af8553ea41dea4dac749/analysis/1396129771/

---->
http://cleanfiles.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/4d26dd55eb21671c4b451ba271d1a4264d27c783e8bbda93608f8cdaf11c3a7c/analysis/1396129874/
FILE:
  • https://www.virustotal.com/de/file/bafc06f1e99e8ceb57dda20a1f97bc1ca1b347890d3ea8d057e6592306a896cb/analysis/1396130019/

----->
http://jlyse.net/includes/public/log_visitor.php
  • https://www.virustotal.com/de/url/18a2a109263c3ba20011e59974ef4bd5e49b44d7aeb0f4e7745dc7bb65106550/analysis/1396130315/

------>
http://jlyse.net/includes/offers/bootstrapWindow.php?file=143026
  • https://www.virustotal.com/de/url/38c9384d1eef60edb4173b22cd71a98361e104fa2ca2e71d2b942fc93506884c/analysis/1396130553/

------->
http://jlyse.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/e340b2c1a3e48ff193de46aaf0a5e60ebf3632fce7bd315f9b446d861c4429c0/analysis/1396130639/
  • https://www.virustotal.com/de/file/7cc16f897286710dfbb1e44ff8793113990ec3c9cac4df8aebefd95c7e11f35c/analysis/1394224032/

-------->
http://jlyse.net/bootstrap/assets/css/bootstrap.css
  • https://www.virustotal.com/de/url/6fd04f3ba5075a1dc73400b5f604307f4d3a613c76492870004ca216c64d6645/analysis/1396130730/
  • https://www.virustotal.com/de/file/03db46511bdaf1e131c2c9954c7b0cbd8f3c593aa4498b7f89ac3067511a5d60/analysis/1374039732/

--------->
http://cleanfiles.net/js/dwn8.js?v=17
  • https://www.virustotal.com/de/url/74ea97392f9c77ac88c303e9be63a528c9c36d26a3ba5baa7d3b5623c548b6f3/analysis/1396130811/
FILE:
  • https://www.virustotal.com/de/file/ff8b96ace5c518b297cb290bc797b9e26e794cd8d5cc2fdd05ed422eaa0e0a50/analysis/1396131053/

---------->
http://js-agent.newrelic.com/nr-361.min.js
  • https://www.virustotal.com/de/url/c593c58403de499701b64c2af0823e7f7d119ea39bb921ae6819c07057c52a88/analysis/1396131852/
  • https://www.virustotal.com/de/file/fce342d034fb770700ba7ac8421e05cd19d08bdc06ee0636f30fcdb3cd5db5fd/analysis/1396131856/

http://wepawet.iseclab.org/view.php?hash=d6973fc5d3786821ffb747ac7e431874&t=1396128982&type=js

3/13/2014

Beware of PASSWORD STEAM-PHISHING from POLAND:
8 SITES hosted on the same Server
carding.pl
staemcommnity.com
steamcommunity.com.kz
steamcommunly.com
steamcomnuinity.com
steamcomnunitu.com
steamcomnuntly.com
stearncommynity.com


THE FOLLOWING DOMAINS ARE SETUP TO PHISH 
YOUR PERSONAL INFORMATION LIKE PASSWORDS, E-MAIL ADRESS ETC from Steam:
DOMAINS ARE BLUE:
http://carding.pl
  • https://www.virustotal.com/de/url/cf559f3de9bbc8ec910a0c82b1219d7a73f1a180f48d36f61140c91b2891e943/analysis/
http://staemcommnity.com
  • https://www.virustotal.com/de/url/b71eae1b48b15e40c77ed5313f2ba168001e789bf22751e7bc66d4bfa5f02541/analysis/
http://steamcommunity.com.kz
  • https://www.virustotal.com/de/url/b703e98a91925b20103dfdee789405b1f6b7b06a7dafd522563dff3cf8871207/analysis/
http://steamcommunly.com
  • https://www.virustotal.com/de/url/a417baa1ba043ad0858ee2e5499763e373bdcf58fbe5a43cbfc089374059857e/analysis/
http://steamcomnuinity.com
  • https://www.virustotal.com/de/url/b40ad3922e0de4658aaac818f7bf6d867c224d65840af60b9711f70d442351fe/analysis/
http://steamcomnunitu.com
  • https://www.virustotal.com/de/url/ea9455325003675be1977842cd1b0e8c858762dcb0d3824227e9d13cdd2c1c07/analysis/
http://steamcomnuntly.com
  • https://www.virustotal.com/de/url/68b58963666dbb66f5501c091abff270551b66fc56175fd123802b3655e4d00c/analysis/
http://stearncommynity.com
  • https://www.virustotal.com/de/url/530e45299fce01a963c2e57182ae6e5f6ded4f76ad313662a9ea9a21b833b138/analysis/

IP =
http://91.188.124.157
  • https://www.virustotal.com/de/url/5c57e04dde30362f07ca72a10e36cbae0d475336197138e26ef986bf5f570612/analysis/1394729002/

2/08/2014

Category MALICIOUS IP: 217.74.66.183 (komsta.biz)
Infected with a spam or malware forwarding link - Botnet
(POLAND) Also: mecsohesti.strefa.pl & berlokava.strefa.pl


The IP address 217.74.66.183 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "komsta.biz", and this link is an example of the redirect: "http://komsta.biz/xmlrpc/r1.php". In other words the website "komsta.biz" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.




Most probably, the infection is a Cpanel, Plesk, Joomla or Wordpress CMS install, that has become infected either through a vulnerability (meaning the CMS software is out of date and needs patching), or the owner of "komsta.biz" has had their account information (userids/passwords) compromised. Then malicious software/files are being uploaded by ftp or ssl.

In many cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "komsta.biz" needs to be examined very carefully for signs of tampering. Further, the criminals will even modify existing web pages (particularly http://komsta.biz itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.


REFERENCES:
217.74.66.183
  • https://www.virustotal.com/de/url/0a6cbec1348cf0d336786144d8ac8b3392a06044ea45210c1ff7164b935138d3/analysis/1391867416/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=217.74.66.183
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=217.74.66.183 
----------------------------------------------------------
komsta.biz
  • https://www.virustotal.com/de/url/d075ee0a046bf5b9061d6516f74a2a8a896f6d645b500b82b8e5621cdd347af3/analysis/1391868630/
komsta.biz/xmlrpc/r1.php
  • https://www.virustotal.com/de/url/13fe2e198d34cfb1180de459f3cdc711cd35315653a442f5ea4cfae49d771803/analysis/ 
---------------------------------------------------------

Other Malicious Domains connected to this IP:
mecsohesti.strefa.pl
  • https://www.virustotal.com/de/url/7b8461c8134626cc15ae094d9ae3c6fa82c82a417cc6936693dbaac78829481e/analysis/1391866196/
mecsohesti.strefa.pl/908juare3rm.js
  • https://www.virustotal.com/de/url/e953124d50e1310dd2812e263931848b00d462470c676a634e4cb399cfa6b92a/analysis/1391866188/
  • https://www.virustotal.com/de/file/b16b4bdb5699e781801c38303ff0843681d622683b1edfaefe7d9255da7cdc36/analysis/1391865764/
  • http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=mecsohesti.strefa.pl
---------------------------------------------------------
berlokava.strefa.pl
  • https://www.virustotal.com/de/url/3ade4568cc4b8450928f22fdc2ef3961f253073f5854b1cecc26274ddce8afc6/analysis/1391865399/

INFECTED WITH: HTML:Script-inf
  • https://www.virustotal.com/de/file/1b9c71d4ede9b1b74f6a228fd391b1532e2dbe90c78ef3bbb77effbebac9693c/analysis/1391865730/
  • http://wepawet.iseclab.org/view.php?hash=f54d99392772ab74cc133e0920e5a658&t=1391865424&type=js
  • http://zulu.zscaler.com/submission/show/4f05692eb30713ac8402cef9ce93cb06-1391865434


1/29/2014

SpyEye: Aleksandr Andreevich Panin Pleads Guilty to
Developing and Distributing Notorious Malware

In summer last year, Moscow voiced outrage over the arrest of a Russian national in the Dominican Republic and his swift transfer to a US jail without Russia’s consent or knowledge and deemed Aleksander Panin’s extradition “unacceptable." Panins friend Anton Pilyugin, who was traveling with him at the time of his arrest stated: “We don’t even know what he has been accused of.  We have no clue about what to expect,”. Now, Pilyugin has closure: Aleksandr Panin, also known as “Gribodemon” and “Harderman”, pleaded Guilty to developing and distributing the infamous SpyEye Malware.

Mean, mean Boy: Aleksandr Panin
Therewith Panin acknowledged before United States District Judge Amy Totenberg, on January 28th, 2014, to conspiracy to commit wire and bank fraud for his role as the primary developer and distributor of the malicious software known as “SpyEye,” which, according to industry estimates, has infected more than 1.4 million computers in the United States and abroad.

Sally Quillian Yates
United States Attorney Sally Quillian Yates said: “As several recent and widely reported data breaches have shown, cyber attacks pose a critical threat to our nation’s economic security,” and “Today’s plea is a great leap forward in our campaign against those attacks. Panin was the architect of a pernicious malware known as SpyEye that infected computers worldwide. He commercialized the wholesale theft of financial and personal information. And now he is being held to account for his actions. Cyber criminals be forewarned - you cannot hide in the shadows of the Internet. We will find you and bring you to justice.” (I tend to say: You can run, but you cannot hide)


Mythili Raman
“Given the recent revelations of massive thefts of financial information from large retail stores across the country, Americans do not need to be reminded how devastating it is when cyber criminals surreptitiously install malicious code on computer networks and then siphon away private information from unsuspecting consumers,” said Acting Assistant Attorney General Mythili Raman.“Today, thanks to the tireless work of prosecutors and law enforcement agents, Aleksandr Panin has admitted to his orchestration of this criminal scheme to use SpyEye to invade the privacy of Americans by infecting their computers through a dangerous botnet. As this prosecution shows, cyber criminals - even when they sit on the other side of the world and attempt to hide behind online aliases - are never outside the reach of U.S. law enforcement.”

According to United States Attorney Yates, SpyEye is a sophisticated malicious computer code that is designed to automate the theft of confidential personal and financial information, such as online banking credentials, credit card information, usernames, passwords, PINs, and other personally identifying information. The SpyEye Malware facilitates this theft of information by secretly infecting the victims’ computer, enabling cyber criminals to remotely control the infected computer through command and control (C2C) servers. Once a computer is infected and under control, cyber criminals can remotely access the infected computers, without authorization, and steal victims’ personal and financial information through a variety of techniques, including malicious injections, keystroke logging, and credit card grabbing. The victims’ stolen personal and financial data is then stealthily transmitted to the C2C server, where it is used to steal money from the victims’ financial accounts.

Not Panins eye...
Panin was the primary developer and distributor of SpyEye. Operating out of Russia, from 2009 to 2011, Panin cooperated with other Cybercriminals, including co-defendant Hamza Bendelladj, an Algerian national also known as “Bx1,” to develop, market, and sell various versions of the SpyEye Trojan. Panin allowed cyber criminals to customize their purchases to include tailor-made methods of obtaining victims’ personal and financial information, as well as marketed versions that targeted information about specific financial institutions including banks and credit card companies. Panin advertised the SpyEye virus on online, invite-only criminal forums. He sold those versions for prices ranging from 1.000 to 8.500 USD. Panin is believed to have sold the Malware packet to at least 150 “clients” who, in turn, used them to set up their own C2C servers. One of Panin’s clients, “Soldier” is reported to have made over 3.2 million Dollars in a six-month period.


As on the pictures you can see, Hamza Bendelladj seems to enjoy the attention he received after his arrest in Thailand














SpyEye was the most dominant Malware toolkit used from approximately 2009 to 2011. Based on information received from the financial services industry, more than 10.000 bank accounts have been compromised by SpyEye infections in 2013 alone. Some cyber criminals continue to use SpyEye today, although its effectiveness has been limited since Anti-Virus Vendors makers have added SpyEye to their AV-programs.

In February 2011, compatible to a federal search warrant, the FBI searched and seized a SpyEye C2C server allegedly operated by Bendelladj in the Northern District of Georgia, that controlled more than 200 computers infected with SpyEye and contained information from numerous financial institutions.

In June and July 2011, the FBI covert sources communicated directly with Panin, who was using his online nicknames Gribodemon and Harderman, about the SpyEye virus. FBI sources then purchased a version of SpyEye from Panin that contained features designed to steal confidential financial information, initiate fraudulent online banking transactions, install keystroke loggers, and initiate distributed denial of service (DDoS) attacks from computers infected with the SpyEye malware.


On December 20, 2011, a Northern District of Georgia grand jury returned a 23-count indictment against Panin, who had yet to be fully identified, and Bendelladj.

The indictment charged one count of conspiracy to commit wire and bank fraud, 10 counts of wire fraud, one count of conspiracy to commit computer fraud, and 11 counts of computer fraud. A overruled indictment was subsequently returned, after identifying Panin by his true name.

Bendelladj was apprehended at Suvarnabhumi Airport in Bangkok, Thailand, on January 5th, 2013, while he was in transit from Malaysia to Algeria. "The smiling Hacker" was extradited from Thailand to the United States on May 2nd, 2013. His charges are currently pendin. 

The investigation also has led to the arrests by international authorities of four of Panin’s SpyEye clients and associates in the United Kingdom and Bulgaria.

Sentencing for Panin is scheduled for April 29th, 2014.


12/07/2013

Pony Botnet Controller - Facebook, Google, Twitter, Yahoo:
Almost 2 Million Usernames & Passwords Stolen in a Mass Hack

Almost 2 million accounts on Facebook, Google, Twitter, Yahoo and other social media and Internet sites have been breached, according to a Chicago-based cybersecurity firm.


The hackers stole 1.58 million website login credentials and 320.000 e-mail account credentials, among other items, the firm Trustwave reported in a blogpost. Included in the hacks were thefts of 318.121 passwords from Facebook, 59.549 from Yahoo, 54.437 from Google, 21.708 from Twitter and
8.490 from LinkedIn. The list also includes 7.978 from ADP, the payroll service provider.

According to Trustwave, "Payroll services accounts could actually have direct financial repercussions."

Stolen Passwords by Day
Most of those stolen passwords were from the Netherlands, followed by Thailand, Germany, Singapore, Indonesia and the United States, which accounted for 859 reports from machines and 1.943 passwords, according to Trustwave. All inn all, just over 100 countries were affected, and Trustwave said this shows the attack is "fairly global."



The hacking began October 21st 2013 and might still be taking place, according to a CNN article, on this case.

The massive data crack was a result of keylogging software maliciously installed on an untold number of CPUs around the world, according to researchers at Trustwave. The Malware was capturing log-in credentials for key websites over the past month and sending those usernames and passwords to a server controlled by the hackers. On November 24th 2013, Trustwave Analysts tracked that server, located in the Netherlands. Google itself declined to comment on this subject.

John Miller, a security research manager at Trustwave, told CNN, "We don't have evidence they logged into these accounts, but they probably did." (So what now....?)

Miller said the team doesn't yet know how the virus got onto so many personal computers. The hackers set up the keylogging software to rout information through a proxy server, so it's impossible to track down which computers are infected.

Among the compromised data are about 41.000 credentials used to connect to File Transfer Protocol (FTP, the standard network used when transferring big files) and 6.000 remote log-ins.

 There are several other servers Trustwave has not yet tracked down, Miller said. ADP, Facebook, LinkedIn and Twitter told CNN they have notified users and reset passwords for compromised accounts. Google declined to comment and Yahoo did not respond immediately.

In compiling the data, Trustwave also discovered that many users are doing just what computer specialists advise against, using simplistic passwords that can easily be guessed. For instance, the top five passwords Trustwave found in researching the breaches were: 123456, 123456789, 1234, password and 12345.

Read the whole Blogpost from Trustwave @:
Look What I Found: Moar Pony!

SOURCE: Money CNN

11/04/2013

Password Protection !

Check THIS LINK:
http://stayaway2.blogspot.com/2014/05/password-protection-and-glenn-greenwald.html

If you care about your Password Security that noone can look at you typing behind your back, this might be an interesting Feature