Translate

Posts mit dem Label Phishing werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Phishing werden angezeigt. Alle Posts anzeigen

4/01/2014

Introducing COMMENT SPAMMERS (so the NET will not FORGET)
Helping those sorrow ones out in Publicity,
otherwise no one would notice them....


www.home-staging-montreal.com
IP: 66.43.56.89
(Montréal)


Anonymous wrote on February 8th, 2014:

Pretty great post. I just stumbled upon your blog and wished to mention that I have truly loved surfing around your weblog posts. After all I will be subscribing in your feed and I am hoping you write once more very soon! 
My weblog: www.home-staging-montreal.com...



COMMENT SCREENSHOT



On this Post:



Screenshot of the Webpage:

One important Question remains: Would you buy something at a place where the Spammer is trying to Advertise through an Article thats subject to Cild Predators & Pedophiles harming Children ??? I BET NOT !!!
----------------------------------------------------------------------------------------------------------------------------------------------

SCAM OF THE DAY from:
"WIR BIETEN DARLEHEN" ("We Offer Credits")
With Greetings from Coquitlam (CANADA), Australia &...& ratgeberplatz.com

IHR SEID IN ALLE FINANZNÖTE ODER BENÖTIGEN SIE MITTEL ZU STARTEN IHR EIGENES GESCHÄFT? BRAUCHEN SIE DARLEHEN FÜR IHRE SCHULD ZU BEGLEICHEN ODER ZAHLEN SIE IHRE RECHNUNGEN?
Wir geben Kredite im Bereich von 7000 US-Dollar (sieben Tausend Dollar) bis zu 50.000.000 US-Dollar (50 Millionen Dollar) mit 3 % Zinssatz.



Füllen Sie das nachstehende Formular (ist kein Formular, nur Text im Mail) für die Anwendung von Darlehen durch:



Persönliche e-Mail-Adresse:

Name: Adresse:

Land:

Telefonnummer:

Menge, die benötigt werden:

Darlehen-Dauer:

Monatliches Einkommen:

Alter:

Geschlecht:



Sie sind Beratung senden Ihre Daten an diese e-Mail-Adresse ein: scoth_smitt@ymail.com



Alles Gute
Herr Rev Scoth Smitt (Blöder gehts wohl nicht!)
Screenshot of HOCHwürden.....

MALICIOUS: HIDDEN IfRAMES ALL OVER THE PLACE & INVOLVED IN PHISHING SCAM
http://sd43.bc.ca/
  • https://www.virustotal.com/de/url/8290fd493074a03e4b9c2e28e27d880175519bba5ec36b12f16aae864214fe44/analysis/1396302819/
http://sd43.bc.ca/Pages/default.aspx
  • https://www.virustotal.com/de/url/3430aa5e2fcb1a7be76346576a55c9179acb649e9ab39d83843e692dbf2eca0e/analysis/1396302945/
HTML: 
W32.HfsIframe.420f (WHATEVER IT MEANS REFERS TO A HIDDEN IFRAME)
  • https://www.virustotal.com/de/file/701247cb9f12329ce5558b3ceff20ab16a4f4880606b86cfe7fe474480f7299b/analysis/1396302682/
ORIGINATING IP(s) (ratgeberplatz.com again involved): Coquitlam (CANADA)
http://142.35.6.131/
  • https://www.virustotal.com/de/url/0878044af1696c27903ac4978f8113c96b1222f5461fbc8f2e9db3191934f1f1/analysis/1396304403/
http://14.2.27.4/   (Adelaide, Australia)
  • https://www.virustotal.com/de/url/3bdc4ddd451c4313001e49b924ff7ff7022ee6cec34bf8ec7b614487b5de2bf8/analysis/1396304621/

3/30/2014

Malicious Blogspotvisitor snapchatpasswordgenerator.blogspot.com

(To this Blog, and probably to many others who
highlight the Snapchat Data-breach a while ago):

PHISHING FOR MOBILE PHONE NUMBERS
Pretending you will win some IPhone, or some other Malware Crap...




PHISHING BLOG: THE bit.ly LINK HAS BEEN FOUND ON THE FOLLOWING BLOGSPOT:
MALICIOUS COMMENT SPAMMER: (SPAMMED MY OWN BLOG)


COMMENT WAS GIVEN ON THIS POST:
stayaway2.blogspot.com/2014/01/hacked-skype-and-snapchat-compromised.html
http://snapchatpasswordgenerator.blogspot.com/
  • https://www.virustotal.com/de/url/d99d7a09c4fdd8b2bf19eae284261183d0884644de04b4e28dfc35a661cceca0/analysis/1396125921/

SUSPICIOUS ActiveX behaviour:
  • http://wepawet.iseclab.org/view.php?hash=a9a04c5facd1c77a6a57444abdb478d2&t=1396123149&type=js

THE OWNER OF THIS BLOG IS (should be) Saad Hashmi (SOUNDS LIKE HASH ME) AND HAS VIDs CALLED: How to Hack Twitter ETC. WHERE SEVERAL VIDs HAVE BEEN REMOVED OR NEVER EXISTED:
https://plus.google.com/101817228413013975367/posts
  • https://www.virustotal.com/de/url/1315983a69f47b3e7a91c6d4dc1148f7eb8ebd773ac7846caf907cd711affbed/analysis/1396127927/

PHISHING FOR MOBILE NUMBERS (SUPPOSING TO WIN SOMETHING) BEFORE DOWNLOADING (DOMAIN):
http://bit.ly/1h4aQgx
  • https://www.virustotal.com/de/url/775bedbd10540c804cd6045beaad4728754a8a35c3a673d9d4df0afaddfe1179/analysis/1396128854/

AT PHISH TANK:
  • http://sitecheck3.sucuri.net/results/bit.ly/1h4aqgx
  • http://www.phishtank.com/phish_detail.php?phish_id=2348877

REDIRECTS TO: --->
http://cleanfiles.net/?stj2nPC
  • https://www.virustotal.com/de/url/025997ab9b0805abdd4d83e9997a54085e2dfbc5ebc39893b1e5c76d27d87916/analysis/1396129645/
  • https://www.virustotal.com/de/file/ef8567646f6f7b246704a8550da770a2beb5f628b154bca2b89bc733a756c1a2/analysis/1396128932/

REDIRECTS TO: --->
http://jlyse.net/?stj2nPC
  • https://www.virustotal.com/de/url/a9e5e6fd72161667774a27f2ecaca3cd16d65a473ac4af8553ea41dea4dac749/analysis/1396129771/

---->
http://cleanfiles.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/4d26dd55eb21671c4b451ba271d1a4264d27c783e8bbda93608f8cdaf11c3a7c/analysis/1396129874/
FILE:
  • https://www.virustotal.com/de/file/bafc06f1e99e8ceb57dda20a1f97bc1ca1b347890d3ea8d057e6592306a896cb/analysis/1396130019/

----->
http://jlyse.net/includes/public/log_visitor.php
  • https://www.virustotal.com/de/url/18a2a109263c3ba20011e59974ef4bd5e49b44d7aeb0f4e7745dc7bb65106550/analysis/1396130315/

------>
http://jlyse.net/includes/offers/bootstrapWindow.php?file=143026
  • https://www.virustotal.com/de/url/38c9384d1eef60edb4173b22cd71a98361e104fa2ca2e71d2b942fc93506884c/analysis/1396130553/

------->
http://jlyse.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/e340b2c1a3e48ff193de46aaf0a5e60ebf3632fce7bd315f9b446d861c4429c0/analysis/1396130639/
  • https://www.virustotal.com/de/file/7cc16f897286710dfbb1e44ff8793113990ec3c9cac4df8aebefd95c7e11f35c/analysis/1394224032/

-------->
http://jlyse.net/bootstrap/assets/css/bootstrap.css
  • https://www.virustotal.com/de/url/6fd04f3ba5075a1dc73400b5f604307f4d3a613c76492870004ca216c64d6645/analysis/1396130730/
  • https://www.virustotal.com/de/file/03db46511bdaf1e131c2c9954c7b0cbd8f3c593aa4498b7f89ac3067511a5d60/analysis/1374039732/

--------->
http://cleanfiles.net/js/dwn8.js?v=17
  • https://www.virustotal.com/de/url/74ea97392f9c77ac88c303e9be63a528c9c36d26a3ba5baa7d3b5623c548b6f3/analysis/1396130811/
FILE:
  • https://www.virustotal.com/de/file/ff8b96ace5c518b297cb290bc797b9e26e794cd8d5cc2fdd05ed422eaa0e0a50/analysis/1396131053/

---------->
http://js-agent.newrelic.com/nr-361.min.js
  • https://www.virustotal.com/de/url/c593c58403de499701b64c2af0823e7f7d119ea39bb921ae6819c07057c52a88/analysis/1396131852/
  • https://www.virustotal.com/de/file/fce342d034fb770700ba7ac8421e05cd19d08bdc06ee0636f30fcdb3cd5db5fd/analysis/1396131856/

http://wepawet.iseclab.org/view.php?hash=d6973fc5d3786821ffb747ac7e431874&t=1396128982&type=js

3/16/2014

PHISHING SITE:
"Observations on film art" www.davidbordwell.net (IP: 70.39.234.97)
PUA.Phishing.Bank (UNITED STATES)

PHISHING SITE: PUA.Phishing.Bank
http://www.davidbordwell.net/blog/index.html
  • https://www.virustotal.com/de/url/2adce51d608b3c939dc1a2c19a9b387aa2e6fe66e750bebf737767133506d85e/analysis/1394996663/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/853a64746b075e1b5d0d7b2eb41c605ddfbfbd4c4b03302ccdde31464ee0f44f/analysis/1394996609/
  • http://virusscan.jotti.org/de/scanresult/7be1f7e378ee2d12adabc4bde73a129e28260178
  • http://jsunpack.jeek.org/?report=22adb95eb82f0ea13915cb3bf77dbae3d100e346
IP:
http://70.39.234.97/
  • https://www.virustotal.com/de/url/56d002a4058f32470c9a5e3add7ffcc5143e77faf1d304a975afbfe9c78ab544/analysis/1394998293/
  • https://www.virustotal.com/de/ip-address/70.39.234.97/information/

PHISHING SITE:
"Ihr Versicherungs Info Blog" isore.de (IP: 141.0.23.37)
PUA.Phishing.Bank GERMANY


MALICIOUS DOMAIN: PUA.Phishing.Bank
http://isore.de/
  • https://www.virustotal.com/de/url/cd05f3ccda0c44e076fbef633074dfaf92f162e60532181f6f89c56cfe1fdf2d/analysis/1394969151/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/b8d40881840b183b2a270ceea0c4e0832766ff61c0cbee3a5e33f182d55614c5/analysis/1394968898/
  • http://virusscan.jotti.org/de/scanresult/907bdcf1d4ce04602e10f6515090ab131201912a
  • http://jsunpack.jeek.org/?report=e7eb3bb765ed738fe2a1390cdf65014d15d6f2a1
IP:
http://141.0.23.37/
  • https://www.virustotal.com/de/url/5d08ba1be1ae978c9a6f17ffc4998aea90204e76ec77f8e5e2d569e93c9f7ea1/analysis/1394970114/
  • https://www.virustotal.com/de/ip-address/141.0.23.37/information/

3/13/2014

Beware of PASSWORD STEAM-PHISHING from POLAND:
8 SITES hosted on the same Server
carding.pl
staemcommnity.com
steamcommunity.com.kz
steamcommunly.com
steamcomnuinity.com
steamcomnunitu.com
steamcomnuntly.com
stearncommynity.com


THE FOLLOWING DOMAINS ARE SETUP TO PHISH 
YOUR PERSONAL INFORMATION LIKE PASSWORDS, E-MAIL ADRESS ETC from Steam:
DOMAINS ARE BLUE:
http://carding.pl
  • https://www.virustotal.com/de/url/cf559f3de9bbc8ec910a0c82b1219d7a73f1a180f48d36f61140c91b2891e943/analysis/
http://staemcommnity.com
  • https://www.virustotal.com/de/url/b71eae1b48b15e40c77ed5313f2ba168001e789bf22751e7bc66d4bfa5f02541/analysis/
http://steamcommunity.com.kz
  • https://www.virustotal.com/de/url/b703e98a91925b20103dfdee789405b1f6b7b06a7dafd522563dff3cf8871207/analysis/
http://steamcommunly.com
  • https://www.virustotal.com/de/url/a417baa1ba043ad0858ee2e5499763e373bdcf58fbe5a43cbfc089374059857e/analysis/
http://steamcomnuinity.com
  • https://www.virustotal.com/de/url/b40ad3922e0de4658aaac818f7bf6d867c224d65840af60b9711f70d442351fe/analysis/
http://steamcomnunitu.com
  • https://www.virustotal.com/de/url/ea9455325003675be1977842cd1b0e8c858762dcb0d3824227e9d13cdd2c1c07/analysis/
http://steamcomnuntly.com
  • https://www.virustotal.com/de/url/68b58963666dbb66f5501c091abff270551b66fc56175fd123802b3655e4d00c/analysis/
http://stearncommynity.com
  • https://www.virustotal.com/de/url/530e45299fce01a963c2e57182ae6e5f6ded4f76ad313662a9ea9a21b833b138/analysis/

IP =
http://91.188.124.157
  • https://www.virustotal.com/de/url/5c57e04dde30362f07ca72a10e36cbae0d475336197138e26ef986bf5f570612/analysis/1394729002/

3/09/2014

RECENT DETECTION: alkhaleejperfumes.com
Redirects with Trojan.JS.Redirector.aaw to Russian (Perfume)-Phishing
Russian Federation & United States


MALWARE: Trojan.JS.Redirector.aaw
(PERFUME PHISHING)

DOMAIN:
http://alkhaleejperfumes.com/
  • https://www.virustotal.com/de/url/4bba656a716030859df99c8ecb9dd5dee4a6ba47fd1e8ddb8e80fdbf0eb4ccf9/analysis/1394391837/
Trojan.JS.Redirector.aaw
  • https://www.virustotal.com/de/file/709c7765d82d32cdfa2654b58703b439a41b8e75d88d8ed31026c469264b98b4/analysis/1394391738/
--->

Spamhaus DROP Listed Traffic Inbound group 5
http://91.239.15.61/google.js
  • https://www.virustotal.com/de/url/afcd08ea9a1a624f0151b849b1d1b3d92be1aa89624c7ca7aa621122e71d7182/analysis/1394392195/
OTHER IP:
http://205.251.156.146/
  • https://www.virustotal.com/de/url/6ff1953bbfa5881e8ea13c832d049bca05ea53875180e59abf9dd53b872e4aa1/analysis/1394392398/
  • https://www.virustotal.com/de/ip-address/205.251.156.146/information/

3/06/2014

Category MALICIOUS IP: 72.8.190.39 (ezuvekury.tk)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES) HTML:RedirME-inf [Trj]

The IP address 72.8.190.39 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "ezuvekury.tk", and this link is an example of the redirect: "http://ezuvekury.tk?q". In other words the website "ezuvekury.tk" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.


In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "ezuvekury.tk" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly ezuvekury.tk itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.


REFERENCES:
72.8.190.39
  • https://www.virustotal.com/de/url/d402ba3e37849bfcab82b8de74d860729defcf62cbe3244ed2aa7e62d6fc1fbd/analysis/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=72.8.190.39
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=72.8.190.39
--------------------------------------------------------
 
MALICIOUS SITE & IP: SPAMBOT PHISHING (VIAGRA & CO.)
 

http://ezuvekury.tk/
https://www.virustotal.com/de/url/c1fbcded30036142e1f72bb0c2e51b02f82143cfe1a203d8a0c696cf0c569259/analysis/1394109439/
HTML
https://www.virustotal.com/de/file/b4bc40d341c4ba868d0b4c350c16e45255a3ef0228f5559a7083fb903717ee5f/analysis/1394110104/


http://ezuvekury.tk/?q
https://www.virustotal.com/de/url/2c7095e8f7ce859b887a11de197516a0967f6e82c43a263f356c7609590bb499/analysis/1394109442/
 

HTML
https://www.virustotal.com/de/file/0191d7cb7b3f637aa74fceb86c5c6575b2b08e0765ca2da8635b1c7ea9538a28/analysis/1394110251/
 

--->

http://csbakhita.com/unsurpassable.html
https://www.virustotal.com/de/url/ea34f52e3fd906449af0c3be62218acd913bafb820752a841887a83baa97a854/analysis/1394110601/


HTML:RedirME-inf [Trj]
https://www.virustotal.com/de/file/983395c456d29de19308294e8a2e9de64ca643fa93d1005114d1fece45c7d1bd/analysis/1394110385/
 

---->

http://rx69.ru/
https://www.virustotal.com/de/url/afcb00221df516d2d5a6f95163ab18e3cdc7984103981f9aa20f9ca0995a2e96/analysis/1394111089/
 

HTMLs
https://www.virustotal.com/de/file/e579b048df4b4306705de79a4ff523b0c84f31e723449609c62026bb86020726/analysis/1394110754/
https://www.virustotal.com/de/file/5515e3e32b05d79f21752af75eca9eaa8150097d5280a08b2f017bcafd6fb94e/analysis/1394110741/
 

---->

http://www.doctortern.ru/
https://www.virustotal.com/de/url/d2ebc69875257b228bc3f76ebe89afd30249e66674f63bac247f90d6546bc842/analysis/1394111231/

 

 

3/04/2014

Bien faire l'amour a votre conjoint:
Phishing from b2b-onlinemarketers.com
(Originating IP: 14.01.31.00 & 193.180.116.211)
United States & Germany
(clara@b2b-onlinemarketers.com)

Etes vous frustrés parce que votre vie intime n'est plus aussi magique
et romantique qu'avant ?

Vous n'êtes pas seuls.

Vivre avec le même partenaire pendant longtemps peut devenir stable et
confortable mais cela peut aussi tuer l'étincelle qui a rendu votre
couple si spécial au début.

Voici quelques idées simples, créatives pour raviver la magie:
Découvrez ces Astuces en cliquant ici >>

Votre vie amoureuse va repartir comme au premier jour
souvenez-vous...

Screenshot from Clara Phishing Mail...
PHISHING DOMAIN:
http://b2b-onlinemarketers.com/
  • https://www.virustotal.com/de/url/cd8c82234f83bf6d42a840f62543264c8cfb8e640cd4b02764ffaa650516f7c9/analysis/1393969667/
http://b2b-onlinemarketers.com/link.php
  • https://www.virustotal.com/de/url/fa353260bb569872664ee9ad837a5a46bf2bb0b3ff442f718c5120e8c589ea61/analysis/1393969679/
http://b2b-onlinemarketers.com/open.php
  • https://www.virustotal.com/de/url/21f7ecb30723abfe40f8d6883e2c9f613381ed0e43bcbf4ee14a6b5cc9d83fcb/analysis/1393969697/
http://b2b-onlinemarketers.com/unsubscribe.php
  • https://www.virustotal.com/de/url/ea7cdf99f93a066717a977172796cea4f7919eebfdc3b133735dfe9496131e54/analysis/1393969708/

ORIGINATING IP(s):
http://14.01.31.00 (UNTRACEABLE)
  • https://www.virustotal.com/de/url/0ca02226514f94be9240ae3de880927998f331b03dfcb694af9c39483cdb8f64/analysis/
http://193.180.116.211 (GERMANY)
  • https://www.virustotal.com/de/url/6d431e65d4d69140dc204e2be1c72073c17213c1fe7c10d392d8f27688e98d0e/analysis/1393969801/
Fwd/Rev DNS Match: No

E-MAIL REPUTATION: POOR
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=193.180.116.211
HOSTNAME:
http://1931801162111.b2b-onlinemarketers.com
  • https://www.virustotal.com/de/url/34c449a687e7a6ef3ed276f545169531cf24198f113f666c3ccffcf7731a8901/analysis/1393969877/
WEB REPUTATION: POOR
  • http://www.senderbase.org/lookup/host/?search_string=1931801162111.b2b-onlinemarketers.com

MALWARE-SPAM from Levitra (PHISHING):
variographics.de - keydiscover.pw - edapotek.eu
(GERMANY) (Rogue Medications) KAUFEN, KAUFEN, KAUFEN




MALWARE-SPAM: TDS PATTERN (sid) SEO SPAM

COMPROISED DOMAIN:
http://www.variographics.de/
  • https://www.virustotal.com/de/url/826914f71c772081a4006a4b8d4a0052e94516f5fd367fa9e2664a6f43ab1d61/analysis/1393897768/
MALICIOUS URL:
http://www.variographics.de/levitra-generika-europa-kaufen
  • https://www.virustotal.com/de/url/4fdef3349ed2cc0f01d33729e0a98343d598ec47357eb19349b80c4753566085/analysis/1393896321/
SimpleTDS (go.php)
  • https://urlquery.net/report.php?id=9761299
--->
http://keydiscover.pw/
  • https://www.virustotal.com/de/url/79c16dc3063a395db04e63cc452803dc5dd7f20272f919868c31c31f462c301c/analysis/1393898631/
---->
http://edapotek.eu/
  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1393898671/


2/27/2014

U.S. PHISHING Visitor to THIS Blog:
winnerhousingbd.com & cloudfront.net IP: 67.225.146.147
(GOOGLEDRIVE)
Trojan.JS.Iframe.ahd (PHISH Remax)



PHISHING SITE (IN THE NAME OF GO(D)OGLE) WITH MALWARE: Trojan.JS.Iframe.ahd (PHISH Remax)

DOMAIN:
http://www.winnerhousingbd.com/
  • https://www.virustotal.com/de/url/a017e5db1d1486a70dadfddfdbc356b76d580559c9228b77aba6a5acb92a8492/analysis/1393506758/
PHISHING LINK:
http://www.winnerhousingbd.com/images/googledrive
  • https://www.virustotal.com/de/url/fceefd5470a2ca79d822b0c021315541f51484d421cd5bd865c0cd8fb39b70de/analysis/1393506767/
INFECTION:
Trojan.JS.Iframe.ahd
  • https://www.virustotal.com/de/file/6843e6f0d4cbfbae6a0baeb12ec548e3a2a8a0d732c521574ab6e0ecb1bcc8e3/analysis/1392021552/
---> REDIRECTS TO (A SLASH +)
http://www.winnerhousingbd.com/images/googledrive/
  • https://www.virustotal.com/de/url/e1e7b671eb7a97d535cbc998116465c59d58161c210405f66220159a75e0ea7f/analysis/1393507443/
INFECTION:
Trojan.JS.Iframe.ahd
  • https://www.virustotal.com/de/file/6843e6f0d4cbfbae6a0baeb12ec548e3a2a8a0d732c521574ab6e0ecb1bcc8e3/analysis/1392021552/
Related Post: http://stayaway2.blogspot.com/2014/02/category-malicious-ip-67225146147.html

TO SEE THE FULL REPORT, SEE THE .txt ICON:


Document hosting: UploadEdit.com

2/24/2014

Category MALICIOUS DOMAIN & IP:
www.zbestclubreview2014.com (IP: 115.242.210.80)
Casino, Gambling
(PHISHING, SCAM, SPAM) (Ruby Palace, Mumbai, INDIA)


Auf unseren Webseiten finden Sie die besten Online Casinos mit exklusiven Angeboten, wenn Sie sich über unsere Webseiten registrieren.
Verschiedene Angebote wie Freispiele und Bonusse auf Einzahlungen erwarten Sie.

Besuchen Sie unsere Webseite, finden Sie Ihr neues Online Casino und profitieren Sie von einem exklusiven Angebot, das Ihnen am besten gefällt.

Klicken Sie hier, um unsere Webseite zu besuchen.
http://www.

zbestclubreview2014.com/
Mit freundlichen Grüßen

Bitte klicken Sie hier, wenn Sie von uns keine E-Mails mehr erhalten wollen:
http://unsubscribe.
zbestreview2014.com/


  • Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.
SPAM-Mail Screenshot
  • Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.

MALICIOUS DOMAIN(s): PHISHING, SCAM, SPAM

MAIL SENT THROUGH:
http://de-graaf.nl/
  • https://www.virustotal.com/de/url/9a2407169f616b2a2a036d1f5bdfdc1b586c3da935cbeb9586e394db4ebdb792/analysis/1393265245/
HTML (TITLE: test igr)
  • https://www.virustotal.com/de/file/897f06db515c21290c30c57dd1af5866fb260e19c213dd86af0c991bf5b2ab5f/analysis/1393265111/
IP:
http://109.109.120.43/
  • https://www.virustotal.com/de/url/3ea4a1d473e5c5d071795108a2ac018278483b00a9f78f903666ea1d8966dc72/analysis/1393265363/
  • https://www.virustotal.com/de/ip-address/109.109.120.43/information/
HOSTNAME:
http://pernis.cbizz.nl/
  • https://www.virustotal.com/de/url/1ffd59fd6c336547198255126d30d61be74c67d3ef51ad3dccac2037c71b43fa/analysis/1393265933/
HTML (PUA - LIKELY HOSTILE)
  • https://www.virustotal.com/de/file/b360defdc2da0baa651a970842c02965c9c7abf9aa64fc1313f4a4a1108faf3d/analysis/1393266111/
GETFILE: http://jsunpack.jeek.org/?report=516635988cbc568d4d2d43d0ad9c0e190325b4be
PUA.JS.Obfus-7
  • http://virusscan.jotti.org/de/scanresult/9bac55894b100053305d87eaf342fd1d7b967b33
  • http://www.UnmaskParasites.com/security-report/?page=pernis.cbizz.nl
DOMAIN:
http://cbizz.nl/
  • https://www.virustotal.com/de/url/1ef1ca00c396eeda1ca723d3780b7b912674431c8f5e5aff3d81e5c0b374a59b/analysis/1393266792/
----------------------

SPECIFIC "CASINO" (MALWARE) DOMAIN:
http://www.zbestclubreview2014.com/
  • https://www.virustotal.com/de/url/02ee438ea4071e0839c5b4f0839c174ff0413423e74f33227791241134dc444c/analysis/1393265668/
UNSUSCRIBE LINK:
http://unsubscribe.zbestreview2014.com/
  • https://www.virustotal.com/de/url/0e33f7e548f5d9685ac666974b4ded4025b0735f14b3e435b0c315555714a755/analysis/1393265770/
ORIGINATING IP ADDRESS:
http://115.242.210.80/
  • https://www.virustotal.com/de/url/98b43e7ad335c2310d1cb232e943d9bf9518613df8ba00d9f5dd41062a54e0c3/analysis/
LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/query/bl?ip=115.242.210.80
  • http://www.spamhaus.org/pbl/query/PBL386929
EMAIL REPUTATION: POOR
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=115.242.210.80




2/19/2014

kidron.oh.us.mennonite.net
SEO SPAM (Cigarettes)
Simple TDS URL Pattern (Germany & Goshen, Indiana, U.S.A.)
IP: 198.51.243.90



MALICIOUS: PHISHING URL
(Germany & Goshen, Indiana, U.S.A.)


TDS URL pattern

DOMAIN:

http://kidron.oh.us.mennonite.net/
  • https://www.virustotal.com/de/url/53747d933ebf776f1245f20e825c9e4417df556835c2dc75d4f9272cd893a307/analysis/1392820035/

MALICIOUS URL:

http://kidron.oh.us.mennonite.net/buy-cigarettes-license
  • https://www.virustotal.com/de/url/0e57417d97e949ee814a6a75b7e6e8d0b8b32bd8740b6355ad71cd935740c537/analysis/1392819470/
W32.HfsIframe.448b
  • https://www.virustotal.com/de/file/f05a3ff1fabe7871c9e5bbc54b491243d3bafc95dcb189bf6b5fe8e576e5987f/analysis/1392820241/
TDS URL pattern
  • https://urlquery.net/report.php?id=9530534
FULL REPORT:
Document hosting: UploadEdit.com



2/13/2014

Just another Spam from: www.ratgeberplatz.com:
„Herzlichen Glückwunsch“ („Congratulations“)
from Germany

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM SCREENSHOT from ratgeberplatz.com...


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel:

2/05/2014

Snowshoe Spammers - MALICIOUS DOMAIN & IP:
b2bdigitalapps.com & 193.180.115.48
"Les 5 astuces pour faire encore mieux l'amour"
(PHISHING-SCAM, AUSTRIA, SWEDEN)


Bonjour,

Tu trouves que tes relations sexuelles deviennent monotones ? Tu n'est
pas seul. Comme toi, je me suis rendu compte que ma femme et moi, on ne
faisait plus l'amour aussi souvent qu'avant.  Et quand ça nous arrive,
c'est toujours les mêmes vieilles recettes.

En fait, j'avais perdu l'enthousiasme et, ça m'ennuie de le dire, il
m'est même arrivé d'éviter de faire l'amour plusieurs fois. Ce n'était
plus comme avant et je savais qu'il fallait faire quelque chose avant
que ca n'aille trop loin.

Alors je suis allé sur le net pour trouver des idées et j'ai trouvé un
livre qui s'appelle  “500 Astuces Amoureuses” En fait, c'est drôle.
Pendant que je lisais le livre, ma femme est venue voir ce que je
faisais. Quand elle a su de quoi il s'agissait elle m'a viré de
l'ordinateur pour lire elle-même.

Alors finalement, il a marché, ce livre ?

Je te laisse juger : la nuit même, elle a apporté des fraises et du
coulis de chocolat à grignoter devant la télé (évidemment inspiré du
livre).

Ca m'a complètement surpris. Je n'aurais jamais pensé qu'une chose
simple comme manger des fruits et du chocolat pendant les préliminaires
pouvait être aussi excitant.

Je n'irai pas dans les “détails” de la suite … :D… mais je dois dire que
je suis devenu fan de ce livre !
Et notre sexualité est extraordinaire maintenant. Nous ne sommes jamais à
court d'idées pour rendre les choses excitantes. Et si on a besoin
d'une idée, il nous suffit d'ouvrir le livre. C'est top !

Si tu penses que ta sexualité est devenue un peu ordinaire, ou si tu veux
simplement l'améliorer un peu, regardes ce livre

en cliquant ici>>

A bientôt

MALICIOUS PHISHING-SCAM DOMAIN: (SNOWSHOE SPAMMERS)
b2bdigitalapps.com
  • https://www.virustotal.com/de/url/c7c6daf58332d34d90b1234b1bdd40c922f4a3bed5174f9b2d561bff8d66a706/analysis/1391621955/
b2bdigitalapps.com/link.php
  • https://www.virustotal.com/de/url/7e06bfb6d9730edbbacc4189f36681e84aaa585dd580e2e53543c4aa10d14d0e/analysis/
  • https://www.virustotal.com/de/file/22fc373d3b3ab36009613adfd7bb60f7135a4f510aa31808856e721dd5799d0c/analysis/
b2bdigitalapps.com/open.php
  • https://www.virustotal.com/de/url/21e996363e94694017a766295f26702b7d6fe9c605a57d30965b3c6be6f9027a/analysis/1391622030/
  • https://www.virustotal.com/de/file/dd5bdccb831d1b19c505bd3e67553f6049cea2e20dba7eb231a02ed0103e521f/analysis/1390580473/
b2bdigitalapps.com/unsubscribe.php
  • https://www.virustotal.com/de/url/c7f6d051298f7b524bcf37fa3bc9ac2cab53cfff8081d9cf78d2f095f85e8e19/analysis/1391622053/
  • https://www.virustotal.com/de/file/fb18ec2dc45858efd8a69d17873eb1a92801a4af8e6b6a44b03e9e7a69d11ffd/analysis/


Snowshoe Spam (Screenshot)

ORIGIN IP:
193.180.115.48
  • https://www.virustotal.com/de/url/9c8a9262baa8df9d848573706b4bcf2eeb9c8d23404f1951accff6b123ff9e64/analysis/1391620870/
  • https://www.virustotal.com/de/file/18f256b9f1807fe04ee416b47643bae7ed150f37cf79e24c4e2b9646cf3cf908/analysis/1391622765/
 
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=193.180.115.48
 
Email Reputation: Poor
Web Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=193.180.115.48
 

2/01/2014

PHISHING: Vier gute Gründe Mitglied zu werden (Ruby Palace) www.krubylotclub.com
Casino, Gambling
(PHISHING, SCAM, SPAM)








Wir von Ruby Palace wissen, was unsere Mitglieder am meisten schätzen und tun immer unser bestes, ihnen jeden Wunsch von den Augen abzulesen.

Dies bedeutet, sicherzustellen, dass wir Ihnen ein unglaubliches Casinoerlebnis bereiten. Hier ist ein Vorgeschmack auf die tollen Dinge, die Sie erwarten, wenn Sie ein Mitglied im Ruby Palace werden:

1.      Ein 200% Willkommensbonus, der Ihre erste Einzahlung verdreifacht.
2.      Mehr als 400 Premium-Casinospiele
3.      24/7 Kundenservice und schnelle & einfache Banking-Methoden
4.      Eine Auszahlungsquote von mehr als 97%

Melden Sie sich heute an, um von allen diesen exzellenten Vorteilen zu profitieren.

http://www.krubylotclub.com/

Alles Gute
Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.

Mail from www.krubylotclub.com

Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.

DOMAIN:
www.krubylotclub.com
  • https://www.virustotal.com/de/url/e0430bd5da60f34a52b77962ff8db3f58db3de15e0ac81a4ed7bf867e2805077/analysis/1391263051/
unsubscribe.krubylotream.com
  • https://www.virustotal.com/de/url/a318f68f910e57cb8578128b707107060b92ad451f98809bf4f102ed81567733/analysis/1391263054/
------------------------------------

LISTED AT SURBL:
  • http://www.surbl.org/surbl-analysis
SEE ALSO:
  • https://www.mywot.com/en/scorecard/krubylotream.com

1/30/2014

Category MALICIOUS IP: 87.106.142.17
PHISHING & SPAM MAIL SERVER - GERMANY


EXAMPLE


MALICIOUS IP (MAIL SERVER): BEING USED FOR PHISHING
87.106.142.17
  • https://www.virustotal.com/de/url/f2897cfdf793e51f81e995aef1a48b3751546f698727e72da60f480f8c8d438a/analysis/1391096503/
HTML
  • https://www.virustotal.com/de/file/777d10257ab159c11dac1feac1a2e2b648af9361ef0da6267247be5e499c638d/analysis/1391096602/
--------------------------------

MAIL EXAMPLES SENT FROM THIS IP:
  • From: "Barclays Bank Plc."<secure@barclays.co.uk>
  • Subject: Multiple login errors on your Barclays Online acco
  • From: "Barclays Bank PLC."<secure@barclays.co.uk>
  • Subject: Barclays important notification!
  • From: "FedEx.com Online Services"<onlineservice@fedex.co
  • Subject: Your fedex.com profile needs to be updated.
  • From: "HSBC Bank Plc."<secure@hsbc.co.uk>
  • Subject: Important security notification!
REFERENCE: https://www.projecthoneypot.org/ip_87.106.142.17

-----------------------------------------
Email Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=87.106.142.17
 HOSTNAME:
http://s15271957.onlinehome-server.info
  • https://www.virustotal.com/de/url/250c273763076212b3ea9f7ade08d2a2db600797633a6c9acf9180e8494ef6f3/analysis/1391097072/

1/29/2014

Just another Spam from: www.ratgeberplatz.com:
„Exklusives Neujahrs-Angebot: o2 DSL + 50 Euro Willkommensbonus“
(„Exclusive New Years Deal: o2 DSL + 50 Bucks Welcome Bonus“)
Germany

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM SCREENSHOT from ratgeberplatz.com...


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel: 

MALICIOUS PHISHERS:
learnhacker.com & www.microhacking.com




MALICIOUS PHISHERS:

DOMAIN:
learnhacker.com
  • https://www.virustotal.com/de/url/1a6b2b1f7323042e2682540eed0352abf70c6d39a2ae221363cd3d73a81cba2a/analysis/1390951492/
SPECIFIC LINK:
learnhacker.com/go/1
  • https://www.virustotal.com/de/url/02e782f1978762845c94af7bf4f0d181aa9d09df0e3714c78dc96c750c336f8e/analysis/1390981128/
AS WELL AS:
www.microhacking.com
  • https://www.virustotal.com/de/url/a54b34b146ad5ab94fea479f2b164a253af0627b9323e612ba186aa4bd960094/analysis/1390981694/
  • https://www.mywot.com/en/scorecard/microhacking.com
  • http://hosts-file.net/?s=microhacking.com
  • http://www.urlvoid.com/scan/microhacking.com/