Translate

Posts mit dem Label Rogue Medication werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Rogue Medication werden angezeigt. Alle Posts anzeigen

4/15/2014

www.ensemble-berlin.de
infected with SEO SPAM (Viagra & Co.)
ROGUE MEDICATIONS PHISHING
IP: 80.67.31.164 & 5.61.42.211
GERMANY



MALICIOUS RUSSIAN PILLS PHISHING URL:
TDS URL pattern
http://www.ensemble-berlin.de/
  • https://www.virustotal.com/de/url/fa621d60d52c535f849c29fe9327a46e2248dedcc24fbe3ccf58388cad5c5c85/analysis/1397567841/
http://www.ensemble-berlin.de/viagra-rezeptfrei-lander.html
  • https://www.virustotal.com/de/url/c516b883ef52e0fef2b2884bcad2b97ecb7db4c9cd1037a847e1d082523cc5a7/analysis/1397566470/
TDS URL pattern
  • https://urlquery.net/report.php?id=1397566888166

  • https://urlquery.net/report.php?id=1397566887262

  • https://urlquery.net/report.php?id=1397566892018
---->
http://tds.cigarettescheap.net/
  • https://www.virustotal.com/de/url/108ea225a2cbc221f9a087fbcc49495921fa191d9fb0358385673df27b0a805d/analysis/1397567431/
TDS URL pattern
  • https://urlquery.net/report.php?id=1397567579389
----->
http://apharmshop.com/
  • https://www.virustotal.com/de/url/a0cf825561616bba65374be8a7b676cbfeb2964a47b08a7a566c186b4d511158/analysis/1397567650/
------>
http://edapotek.eu/
  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1397567302/

3/06/2014

Category MALICIOUS IP: 72.8.190.39 (ezuvekury.tk)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES) HTML:RedirME-inf [Trj]

The IP address 72.8.190.39 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "ezuvekury.tk", and this link is an example of the redirect: "http://ezuvekury.tk?q". In other words the website "ezuvekury.tk" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.


In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "ezuvekury.tk" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly ezuvekury.tk itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.


REFERENCES:
72.8.190.39
  • https://www.virustotal.com/de/url/d402ba3e37849bfcab82b8de74d860729defcf62cbe3244ed2aa7e62d6fc1fbd/analysis/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=72.8.190.39
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=72.8.190.39
--------------------------------------------------------
 
MALICIOUS SITE & IP: SPAMBOT PHISHING (VIAGRA & CO.)
 

http://ezuvekury.tk/
https://www.virustotal.com/de/url/c1fbcded30036142e1f72bb0c2e51b02f82143cfe1a203d8a0c696cf0c569259/analysis/1394109439/
HTML
https://www.virustotal.com/de/file/b4bc40d341c4ba868d0b4c350c16e45255a3ef0228f5559a7083fb903717ee5f/analysis/1394110104/


http://ezuvekury.tk/?q
https://www.virustotal.com/de/url/2c7095e8f7ce859b887a11de197516a0967f6e82c43a263f356c7609590bb499/analysis/1394109442/
 

HTML
https://www.virustotal.com/de/file/0191d7cb7b3f637aa74fceb86c5c6575b2b08e0765ca2da8635b1c7ea9538a28/analysis/1394110251/
 

--->

http://csbakhita.com/unsurpassable.html
https://www.virustotal.com/de/url/ea34f52e3fd906449af0c3be62218acd913bafb820752a841887a83baa97a854/analysis/1394110601/


HTML:RedirME-inf [Trj]
https://www.virustotal.com/de/file/983395c456d29de19308294e8a2e9de64ca643fa93d1005114d1fece45c7d1bd/analysis/1394110385/
 

---->

http://rx69.ru/
https://www.virustotal.com/de/url/afcb00221df516d2d5a6f95163ab18e3cdc7984103981f9aa20f9ca0995a2e96/analysis/1394111089/
 

HTMLs
https://www.virustotal.com/de/file/e579b048df4b4306705de79a4ff523b0c84f31e723449609c62026bb86020726/analysis/1394110754/
https://www.virustotal.com/de/file/5515e3e32b05d79f21752af75eca9eaa8150097d5280a08b2f017bcafd6fb94e/analysis/1394110741/
 

---->

http://www.doctortern.ru/
https://www.virustotal.com/de/url/d2ebc69875257b228bc3f76ebe89afd30249e66674f63bac247f90d6546bc842/analysis/1394111231/

 

 

3/04/2014

MALWARE-SPAM from Levitra (PHISHING):
variographics.de - keydiscover.pw - edapotek.eu
(GERMANY) (Rogue Medications) KAUFEN, KAUFEN, KAUFEN




MALWARE-SPAM: TDS PATTERN (sid) SEO SPAM

COMPROISED DOMAIN:
http://www.variographics.de/
  • https://www.virustotal.com/de/url/826914f71c772081a4006a4b8d4a0052e94516f5fd367fa9e2664a6f43ab1d61/analysis/1393897768/
MALICIOUS URL:
http://www.variographics.de/levitra-generika-europa-kaufen
  • https://www.virustotal.com/de/url/4fdef3349ed2cc0f01d33729e0a98343d598ec47357eb19349b80c4753566085/analysis/1393896321/
SimpleTDS (go.php)
  • https://urlquery.net/report.php?id=9761299
--->
http://keydiscover.pw/
  • https://www.virustotal.com/de/url/79c16dc3063a395db04e63cc452803dc5dd7f20272f919868c31c31f462c301c/analysis/1393898631/
---->
http://edapotek.eu/
  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1393898671/


2/28/2014

Category MALICIOUS IP: 68.178.254.121 (www.bonsaihacker.com)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES)

The IP address 68.178.254.121 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "www.bonsaihacker.com", and this link is an example of the redirect: "http://www.bonsaihacker.com/infantile.htm?vixe". In other words the website "www.bonsaihacker.com" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.


In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "www.bonsaihacker.com" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly www.bonsaihacker.com itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.

REFERENCES:
68.178.254.121
  • https://www.virustotal.com/de/url/66dfd5856d9fd790189a5f8242c3eb4828b0e02c4e5a3932610e225e9d30e2be/analysis/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=68.178.254.121
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=68.178.254.121

FULL REPORT:


Document hosting: UploadEdit.com

Category MALICIOUS IP: 67.225.146.147 (wpnoupfront.authenticbd.com)
Infected with a spam or malware forwarding link - Botnet
(UNITED STATES & RUSSIAN FEDERATION)

The IP address 67.225.146.147 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "wpnoupfront.authenticbd.com", and this link is an example of the redirect: "http://wpnoupfront.authenticbd.com/invigorating.htm". In other words the website "wpnoupfront.authenticbd.com" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.

No Time to lay back...
In several cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "wpnoupfront.authenticbd.com" needs to be examined very carefully for signs of tampering. Further, the criminal will even modify existing web pages (particularly http://wpnoupfront.authenticbd.com itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.

Related Post: http://stayaway2.blogspot.com/2014/02/us-phishing-visitor-to-this-blog.html

REFERENCES:
67.225.146.147
  • https://www.virustotal.com/de/url/30de5a071652e44f8f6003ab0c22553e72808bfec8aa5982ae23fb7badde4857/analysis/1393510660/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=67.225.146.147
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=67.225.146.147
----------------------------------------------------------

http://wpnoupfront.authenticbd.com/
  • https://www.virustotal.com/de/url/1fb32860105dea70846f611020d9ba6c2a4557c5337ded5e1dcbe83b51b9641d/analysis/1393517602/
  • http://urlquery.net/report.php?id=9691230
http://wpnoupfront.authenticbd.com/invigorating.htm
  • https://www.virustotal.com/de/url/071ca9f4199a95b2d2824d0207e8c6287c20458ad1f87b80ac37a9a36ec2de9b/analysis/1393517601/
HTML:RedirME-inf [Trj]
  • https://www.virustotal.com/de/file/5f0925c559ea8e1285877f550f361a92770d54528f8800ab181bdc1a0c039427/analysis/1393520355/
  • (GETFILE: http://jsunpack.jeek.org/dec/getfile?hash=8ff9/ed8ea2a207c8f4ae5c70dac68556d6ff425a)
---> REDIRECTS TO
http://doctorxonft.ru/
  • https://www.virustotal.com/de/url/0512b24fcc96129c9951e4f5103bfed2312c9fe359403ed3a6ec36e6ced2e962/analysis/
HTML (PUA.JS.Obfus-7)
  • https://www.virustotal.com/de/file/8aad19003d4937d93cf60ff7f8457c231e4b72110d380a4c6a2e133b1e169fae/analysis/1393521420/
  • http://virusscan.jotti.org/de/scanresult/baf1b8fc0d963713dd61f1f9549226321e068189

FULL REPORT:
Document hosting: UploadEdit.com

2/22/2014

Compromised Website:
fresh-vital-drink.de
(SEO SPAM, VIAGRA & CO., ROGUE MEDS)
GERMANY SimpleTDS





Compromised Website: SimpleTDS go.php (sid)
http://www.fresh-vital-drink.de/
  • https://www.virustotal.com/de/url/bc0e1cc2bd28f61cde38cdada7a67d0d6a73daaf46b605eb3a7fe9ff0a93edc1/analysis/1393083183/
http://www.fresh-vital-drink.de/levitra-grossen.html
  • https://www.virustotal.com/de/url/16ab17043771a2dd113ade0718e5f41cef0e99b6ce0a64f055304e690b443dcd/analysis/1393083158/
  • https://urlquery.net/report.php?id=9584003
  • https://urlquery.net/report.php?id=9584007
  • https://urlquery.net/report.php?id=9584005

1/26/2014

MALICIOUS SITE: rukiyehayran.com
(PHISHING, MALWARE, SCAM, SEO SPAM)
TURKEY (Rogue Medications - Zymbiotix)


MALICIOUS SITE: PHISHING, MALWARE, SCAM, SEO SPAM (Zymbiotix Cleanse)

"Are you sure you don\'t want to take advantage of the Garcinia Cambogia offer?\n\nDon\'t forget - it will only be available for a LIMITED TIME.

Since this offer is so cheap, there is no risk to you. You can also give them away if you\'d like. Or give it a shot, and get Garcinia Cambogia.\n\nIf you are wondering why this offer is so cheap, the simple answer is because the manufacturer is confident that their products will help you, and that you will continue to use their products, and refer friends and family.

Celebrities like Kim Kardashian and Britney Spears have lost a
signifcant amount of body fat with just these 2 diet cleanses. The duo
cleanse is clinically proven to flush out all the junk in your body and
melt away body fat without harming your immune system. Keep reading and
you'll find out why we created this report."

DOMAIN:
rukiyehayran.com
  • https://www.virustotal.com/de/url/2f6ab6c39c5b436e410ec66f2f62be5d8f1156c38b48b63c8d5062128605e9f2/analysis/1390758337/

HTML
  • https://www.virustotal.com/de/file/1f1218e4661f525ee1fcd70a043b7c0a3709ab33b39af313ffec819f59e24ffa/analysis/1390751239/


LINK 2
rukiyehayran.com/likeit.php
  • https://www.virustotal.com/de/url/6ebf42c21c420e1b2d377bbd335ed3b3317373a895c8e29566deb40650e4bfe3/analysis/

HTML
  • https://www.virustotal.com/de/file/70c6546a370ccedbdbf101bfd0124adc537fc4cccb7c022a0300071c3f09afcd/analysis/
  • http://jsunpack.jeek.org/dec/getfile?hash=3585/7a7fe26eb28c4a47ccd31474b3944cefef41
  

LINK 3 (SPECIFIC)
rukiyehayran.com/likeit.php?nwqmqztem1151qapb
  • https://www.virustotal.com/de/url/9f589ceabb55b17f43769500f860b201ff60715e36bff0cc6422728b93b92232/analysis/1390758346/

HTML
  • https://www.virustotal.com/de/file/70c6546a370ccedbdbf101bfd0124adc537fc4cccb7c022a0300071c3f09afcd/analysis/

POSSIBLE ORIGINATING IP ADRESS: 108.166.43.117

Screenshot of E-Mail Scam from rukiyehayran.com

 

1/15/2014

Category MALICIOUS DOMAIN: rheumatoidarthritisgout49419.soup.io
Rogue Medications & Phishing Risk (AUSTRIA)
(GOOGLE PHISHING)

Potentially Malicious Site: Drugs & Medications (PHISHING RISK)








DOMAIN:
rheumatoidarthritisgout49419.soup.io
  • https://www.virustotal.com/de/url/52b67f6d4e0d46e81f5e560297c575c638a9ba33b43e1229718fc6929a9a1c91/analysis/
MALICIOUS LINK FOUND TO: (DOMAIN)
is.gd (U.K.)
  • https://www.virustotal.com/de/url/47a68b786b0e7abcc8263d257b7fe90a26be583647d9371b38ceb24c09332a3b/analysis/1389627324/
SPECIFIC LINK:
is.gd/fpnxbB
  • https://www.virustotal.com/de/url/61b5b6b25706c0ab0bde93ea941fbea8d7334f699957f88072ea49eb2a19e8e1/analysis/1389804055/



ADDITIONAL MALICIOUS LINK FOUND TO: (DOMAIN)
stomsk.ru (Lithuania)
  • https://www.virustotal.com/de/url/c2cb23d08ab0e0430674bda1ede032890408106f0c480b81423f85a38ba09716/analysis/1389626637/
SPECIFIC LINK:
stomsk.ru/pics/doc.jpg
  • https://www.virustotal.com/de/url/7dd47a1cf793aa3da415720b51e6d6452bfad57f42bc9c494322ea79a4363601/analysis/1389626639/



Category MALICIOUS DOMAIN: bleacherreport.com
Phishing Risk
(GOOGLE PHISHING, ROGUE MEDICATIONS)





MALWARE SITE: (PHISHING, SCAM, SPAM, FRAUD)


DOMAIN:


bleacherreport.com
  • https://www.virustotal.com/de/url/73e7cf76bf1c58ce62ab54cf4a28f320766b249d72cf66c7d210f87a1b7544b2/analysis/

IP bleacherreport.com: 54.225.139.135
  • https://www.virustotal.com/de/url/14f09c097abffce28cca7fd184550619551ff1f8d6b6451d417986f53e69e57b/analysis/1389788841/

POTENTIALLY SUSPICIOUS FILES: 24
  • http://quttera.com/detailed_report/54.225.139.135

SPECIFIC LINK:
bleacherreport.com/users/3821374-suhagra-100-reviews-alprostadil-injection
  • https://www.virustotal.com/de/url/55c49329a6f064acbf9464d02d2e796ebf9a7f6556299ec7d20145eb50168c8f/analysis/1389788405/

SPECIFIC LINK HAS A DIFFERENT IP: 23.23.134.171
  • https://www.virustotal.com/de/url/cf6b75943c44872f1e6da28708b1d7f3fcf39a05efdfc11eab3012c5f3e81815/analysis/1389788766/

POTENTIALLY SUSPICIOUS FILES: 40
  • http://quttera.com/detailed_report/23.23.134.171

http_inspect: UNKNOWN METHOD
  • https://urlquery.net/report.php?id=8823259 

DESTINATION IP: 195.159.219.10 (NORWAY, MALICIOUS)
  • https://www.virustotal.com/de/url/2124f63fafe3b2ad6f32d647633508a27ad79a2aee4cbc424baec79be1c3b327/analysis/1389789045/

Web Reputation: POOR
  • http://www.senderbase.org/lookup/?search_string=195.159.219.10

LISTED AT hPHosts:
  • http://hosts-file.net/?s=bleacherreport.com

LISTED AT TreatLog: Spam/Scam/Fraud
  • http://threatlog.com/search/bleacherreport.com/domain/
  • http://www.urlvoid.com/scan/bleacherreport.com/

POTENTIALLY SUSPICIOUS FILES: 139
  • http://quttera.com/detailed_report/bleacherreport.com

CLICKING GOES TO: (RBN 398)
is.gd/YixLnc
  • https://www.virustotal.com/de/url/686b3e88a398c31a7ffbaaafc874064f92e51133dc3f257b3dcf49a1183cf28c/analysis/1389794625/
----> URL after Redirection: GOOGLE.COM (PHISHING)

  •  https://urlquery.net/report.php?id=8824810

1/13/2014

Category MALICIOUS DOMAIN: goutytophisurgery88758.soup.io
Rogue Medication Phishing Risk (AUSTRIA)
(GOOGLE PHISHING)

Potentially Malicious Site: Drugs & Medications (PHISHING RISK)


DOMAIN:
goutytophisurgery88758.soup.io
  • https://www.virustotal.com/de/url/9c76a54622c7037c90bffa40f734845fb4a36bdbe3c3807845151e7bc3ccb7bd/analysis/1389627071/
MALICIOUS LINK FOUND TO: (DOMAIN)
is.gd (U.K.)
  • https://www.virustotal.com/de/url/d92eb9fedadf8ef87d077931d558dbb058bc35f38251ddefc6cc4addba929439/analysis/1389804529/
SPECIFIC LINK:
is.gd/OFliej
  • https://www.virustotal.com/de/url/47a68b786b0e7abcc8263d257b7fe90a26be583647d9371b38ceb24c09332a3b/analysis/
ADDITIONAL MALICIOUS LINK FOUND TO: (DOMAIN)
stomsk.ru (Lithuania)
  • https://www.virustotal.com/de/url/c2cb23d08ab0e0430674bda1ede032890408106f0c480b81423f85a38ba09716/analysis/1389626637/
SPECIFIC LINK:
stomsk.ru/pics/doc.jpg
  • https://www.virustotal.com/de/url/7dd47a1cf793aa3da415720b51e6d6452bfad57f42bc9c494322ea79a4363601/analysis/1389626639/

Category MALICIOUS DOMAIN: potenzmittelcialis26471.soup.io
Cialis Phishing Risk (AUSTRIA)
(GOOGLE PHISHING)

Potentially Malicious Site: Drugs & Medications (PHISHING RISK)


DOMAIN:
potenzmittelcialis26471.soup.io
  • https://www.virustotal.com/de/url/235b3ff9bc5531c30a46d21413ab2967d150ccf26828070641ebbd39951673c9/analysis/1389564598/
MALICIOUS LINK FOUND TO: (DOMAIN)
is.gd (U.K.)
  • https://www.virustotal.com/de/url/d92eb9fedadf8ef87d077931d558dbb058bc35f38251ddefc6cc4addba929439/analysis/1389626217/
SPECIFIC LINK:
is.gd/yGa80d
  • https://www.virustotal.com/de/url/d7d0fbfe93759463be0317981370e4186c5814168847ea1a49d1ea606aed2f7b/analysis/1389626417/
ADDITIONAL MALICIOUS LINK FOUND TO: (DOMAIN)
stomsk.ru (Lithuania)
  • https://www.virustotal.com/de/url/c2cb23d08ab0e0430674bda1ede032890408106f0c480b81423f85a38ba09716/analysis/1389626637/
SPECIFIC LINK:
stomsk.ru/pics/doc.jpg
  • https://www.virustotal.com/de/url/7dd47a1cf793aa3da415720b51e6d6452bfad57f42bc9c494322ea79a4363601/analysis/1389626639/

12/25/2013

Malicious Site: www.itv-h.nl - Blackhat SEO Rogue Medications SCAM, SPAM, PHISHING

BLACKHAT SEO SPAM (Viagra, Cialis & co.) (TDS URL PATTERN)
https://www.google.com/search?q=%22Cheap%20Vista%20for%20Students%22%20site%3Awww.itv-h.nl#q=%22Viagra%22+site%3Awww.itv-h.nl



DOMAIN

www.itv-h.nl
https://www.virustotal.com/de/url/db0b7cacafa60e9af86d59ffd9cb50607746297dc4a696b44f90ebcd22166709/analysis/1387967753/

SPECIFIC URL:
www.itv-h.nl/viagra-kob.html
https://www.virustotal.com/de/url/dd8f10f702e672d1ec9dff469c0db539494b6dc782d80ec296d07f83782c4ee7/analysis/1387967607/

TDS URL PATTERN
https://urlquery.net/report.php?id=8541346

---> REMOTE DOMAIN
keycollector.pw
https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1386973287/

SPECIFIC URL:
keycollector.pw/go.php?sid=1
https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387967941/

TDS URL PATTERN
https://urlquery.net/report.php?id=8541376

--->
edapotek.eu
https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387967991/

12/16/2013

Deutsche Kentucky Fried Chicken Website (HESSEN) infiziert mit Blackhat SEO SPAM (PHISHING inklusive)

KOMPROMITTIERTE URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL PFAD - PHISHING


KFC Logo
URL:


www.kfc-hessen.de/viagra-fur-die-frau-online-kaufen

  • https://www.virustotal.com/de/url/fa0ce0aed0980ed05dc97032971980f4536b6c04fd66227e46b0b7605f962906/analysis/1387219444/



TDS URL PFAD
INDICATOR-COMPROMISE Suspicious .pw dns query



  • https://urlquery.net/report.php?id=8404039


---> TDS PFAD

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387220505/
  • https://urlquery.net/report.php?id=8404170

---> LEITET WEITER AN PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387220706/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.61.42.211

  • https://www.virustotal.com/de/url/14c84d8d823c8a2dd31c0dad9aaecd39a5bc6b183093196acf12ea1f2fb0c7c3/analysis/1387223113/
ENGLISH POST:

German Kentucky Fried Chicken Website Infected with Blackhat SEO SPAM (Phishing included)

MALICIOUS URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL pattern - PHISHING


KFC Logo
URL:


www.kfc-hessen.de/viagra-fur-die-frau-online-kaufen

  • https://www.virustotal.com/de/url/fa0ce0aed0980ed05dc97032971980f4536b6c04fd66227e46b0b7605f962906/analysis/1387219444/


TDS URL pattern
INDICATOR-COMPROMISE Suspicious .pw dns query



  • https://urlquery.net/report.php?id=8404039

---> TDS PATH

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1387220505/
  • https://urlquery.net/report.php?id=8404170

---> TO PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387220706/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.61.42.211

  • https://www.virustotal.com/de/url/14c84d8d823c8a2dd31c0dad9aaecd39a5bc6b183093196acf12ea1f2fb0c7c3/analysis/1387223113/

Deutsches POSTING:
http://stayaway2.blogspot.com/2013/12/deutsche-kentucky-fried-chicken-website.html

12/15/2013

Malicious URL: www.ramada-friedrichroda.de - Rogue Medications
SCAM, SPAM, PHISHING

MALICIOUS URL: 
Blackhat SEO SPAM (VIAGRA, CIALIS & Co.) - TDS URL pattern - PHISHING



URL:

www.ramada-friedrichroda.de/apotheke-niederlande-cialis

  • https://www.virustotal.com/de/url/440d20e3414b328c712cd2b8f239eedcd4384017bb38147ca9892f6d456ce261/analysis/1387125985/

TDS URL pattern
INDICATOR-COMPROMISE Suspicious .pw dns query

  • https://urlquery.net/report.php?id=8396692

---> TDS PATH

keycollector.pw/got.php?sid=1

  • https://www.virustotal.com/de/url/b0059244125b4a42d4ed3fee193cf1c19300c7a4499f5cfe6e1d8b51c833796a/analysis/1387126405/
  • https://urlquery.net/report.php?id=8396782

---> TO PHISHING DOMAIN

edapotek.eu

  • https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1387126466/

MALICIOUS IP used for Rogue Meds & Cigarettes etc.:   5.152.215.126

  • https://www.virustotal.com/de/url/09f69d67216a170c75e9e24f1ce49a682e2af481d34c54948168b78daf829c85/analysis/1387127170/
  • https://www.virustotal.com/de/ip-address/5.152.215.126/information/

12/14/2013

Malicious Site: www.karlavagnencatering.se - Rogue Medications
SCAM, SPAM, PHISHING

BLACKHAT SEO SPAM (Viagra, Cialis & co.) (TDS URL PATTERN)


Much to laugh about...?


DOMAIN
www.karlavagnencatering.se
https://www.virustotal.com/de/url/e3e2b39d694b0cd06f9ac6c829fc0e6bf0c1665e3cd38e2155aefc008b0806ea/analysis/1386971594

SPECIFIC URL:
www.karlavagnencatering.se/index.php?q=tablet-viagra-women
https://www.virustotal.com/de/url/d8e9c623a21b171b1a8ac58104517b98335ed9d93159a0fb8fcfa1707f9b40a6/analysis/1386969306/

TDS URL PATTERN
https://urlquery.net/report.php?id=8383382

---> REMOTE DOMAIN
keycollector.pw
https://www.virustotal.com/de/url/9a068164c93a7846ee42bde821b8945b72dde17688857863abcf750dcff2fe37/analysis/1386973287/

SPECIFIC URL:
keycollector.pw/go.php?sid=1
https://www.virustotal.com/de/url/e16207dfb15b888a78ad46df3e92878d177c415c2667e9e438c34a6c0cc9bd63/analysis/1386972436/

TDS URL PATTERN
https://urlquery.net/report.php?id=8383945

12/06/2013

Malicious Site: cialis2au.com - Rogue Medications
SCAM, SPAM, PHISHING


KEEP OFF OF SITES LIKE THIS (VIAGRA, CIALIS, VALIUM ETC.)

It is not only that you will harm yourself with those rogue medications, they more likely will harm you, in stealing your personal information (like credit Card Number &&&). You will likely become a Phishing Victim and more.

Analysis:

Domain @:

This Site will then redirect you to the Following Malicious Domains:

Malicious DOMAIN 1 @:

Malicious DOMAIN 2 @:

Malicious IPs Involved:

12/02/2013

United Kingdom: Governmental Website with Malicious Hidden Blackhat SEO SPAM revealed - www.kidwelly.gov.uk

Blackhat SEO SPAM (also defined as Spamdexing. Rogue Medications like Viagra, Cialis etc.) have been placed on a U.K. (.gov)-Domain has been identified, Phishing Risk included.

From Kidwelly Town Council to Ordering Viagra...
Analysis:

DOMAIN: www.kidwelly.gov.uk

https://www.virustotal.com/de/url/260c4e69c8b67d926d2dd35855943e73fc4686018563119216333e30f86fa065/analysis/1386001577/
Detection of a TDS URL pattern
www.kidwelly.gov.uk @ Urlquery 1
www.kidwelly.gov.uk @ Urlquery 2
---> Pattern 1
https://www.virustotal.com/de/url/108ea225a2cbc221f9a087fbcc49495921fa191d9fb0358385673df27b0a805d/analysis/1386002253/
https://www.virustotal.com/de/url/e66426cf99e99ffef07c60a6733e9bd3e28ea9531e0a8888651ed0a0ab6368a0/analysis/1386002281/
Detection of a TDS URL pattern
Reference 1
---> Pattern 2
https://www.virustotal.com/de/url/796f23f603e37c30c96323a5a17e9240452213df055795e53fc2d94b4965c37c/analysis/1386002386/

Check This Link, there are several Links to find at Google (for now at least):

https://www.google.com/search?q=%22Viagra%22+site%3Awww.kidwelly.gov.uk&cad=h