Translate

Posts mit dem Label SCAM werden angezeigt. Alle Posts anzeigen
Posts mit dem Label SCAM werden angezeigt. Alle Posts anzeigen

5/04/2014

PHISHING SCAM !
Subject: The hottest sex positions in the world from:
wonder-save.de (IP: 46.137.116.197)



SPAM - SCAM - PHISHING DOMAIN
(MAIL THROUGH sexpositions@load-next.com)

http://www.wonder-save.de/
  • https://www.virustotal.com/de/url/4cbee3944f626152a7b0e565989dfcdfa97128d9e1661e8b2f881544bdcf38a7/analysis/1399057180/
HTML=LOOOOOOOLLL (Rattenscharfe Amateute am laufenden Band)
  • https://www.virustotal.com/de/file/d079714ab2586e4eb1d64bdea7ea0904160f2c848b0cb84b1c4040e82f79e501/analysis/1399057765/


BitDefender DOMAIN information: "This URL domain/host was seen to host badware at some point in time"


DOMAIN BLACKLISTED AT:
1) WOT
  • https://www.mywot.com/en/scorecard/wonder-save.de
2) SURBL
  • http://www.surbl.org/lists
3) JoeWein
  • http://www.joewein.net/
ADDITIONAL LINK:
http://www.wonder-save.de/o/e181067801c9b41237c8ca23126a2754c00befbb41d019e0470c71483874f92d
  • https://www.virustotal.com/de/url/2a9d116e843f5d5ca49d2b1e8fecb2be80998c6d79b9fccfeacd62a13a0f4ee3/analysis/1399063964/
HTMLSRC
  • https://www.virustotal.com/de/file/b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b/analysis/1398895856/
REDIRECTION TO --->
http://www.medusa.mx/open/e181067801c9b41237c8ca23126a2754c00befbb41d019e0470c71483874f92d
  • https://www.virustotal.com/de/url/d8053385191d602cccc3bde8afc22a3f99814f27d239f74787787b55b110a46f/analysis/
HTMLSRC
  • https://www.virustotal.com/de/file/b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b/analysis/1398895856/
DOMAIN:
http://www.medusa.mx/
  • https://www.virustotal.com/de/url/a451ede892082c712db5d49ed9152ed9bb0dd59aad190acb4be3d4d1320b8bfc/analysis/1399064361/
IP:
http://176.34.253.56/
  • https://www.virustotal.com/de/url/d4999bea2206837dff08b433a4c099eb794b7f1e3c5aafb7cad21895a2382f86/analysis/1399065373/
  • https://www.virustotal.com/de/ip-address/176.34.253.56/information/
REDIRECTS TO --->
http://newsletterabo.com/
  • https://www.virustotal.com/de/url/53fb33f8aea6cfadcd5fcaea7cf34509d2e95721acefa4058490a024d37eb9bd/analysis/1399064949/
IP:
http://62.129.143.124/
  • https://www.virustotal.com/de/url/753211dc1d21447d75875e36d3dd36c195078e99d32c3039c3dbee0232c96cd6/analysis/1399066574/
  • https://www.virustotal.com/de/ip-address/62.129.143.124/information/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=62.129.143.124
Some 5000 SPAMVERTIZED DOMAINS ARE hosted HERE:
  • http://www.spamhaus.org/sbl/query/SBL112409
WEB-REP: POOR
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=62.129.143.124
HTMLSRC
  • https://www.virustotal.com/de/file/ed3d4bf96a6e2c0c0f9ac7b27701b8dbab3fbfeb8078a3b4a847c1a797d8cd6d/analysis/1399064611/
SEE AS WELL:
  • http://sitecheck.sucuri.net/results/www.medusa.mx
  • http://sitecheck.sucuri.net/results/newsletterabo.com
-----------------------

MAIL SENT THROUGH:
http://load-next.com/
  • https://www.virustotal.com/de/url/7ac028fb0869d91755fb1a260da32b7189872856761e98b271bbf7c54283b670/analysis/1399061768/
  • https://www.virustotal.com/de/file/989e7a7c0680624b684c78468a1a1909c98a96dbce68c3a6d9a7d9122314aceb/analysis/1399061565/
  • https://www.virustotal.com/de/file/4ee70fe07827224c29f73047c71569c8fe740b370506cdd8b13e203a0ea5244d/analysis/1399061582/
IP:
http://95.130.125.232/ (AUSTRIA)
  • https://www.virustotal.com/de/url/e75688860b8f4224a5c62a7bfdb9c424a7a1e97e237eb40730d991c7d7e2ea42/analysis/1399063376/
  • https://www.virustotal.com/de/ip-address/95.130.125.232/information/
Fwd/Rev DNS Match: NO
  • http://www.senderbase.org/lookup/?search_string=95.130.125.232
-----------------------

IP:
http://46.137.116.197/
  • https://www.virustotal.com/de/url/1475cbe1f128f13cfbc44a6ef054af0e4edbfe87b1a881fcf912045eb62ab857/analysis/1399059664/
  • https://www.virustotal.com/de/ip-address/46.137.116.197/information/

4/05/2014

ZDF ++EILT++ACHTUNG++SCHOCKIERENDE MELDUNG++:
German PHISHING MAIL from:
www.redcappi.com
arbeit-von-zuhause-aus.com
goo.gl/p3rL07

(United States)

++EILT++ACHTUNG++SCHOCKIERENDE MELDUNG++

ZDF berichtete HEUTE im Fernsehen!: Deutschland ist schockiert über diese Geldmaschine!
Vergessen Sie alles, aber wirklich ALLES was Sie bisher in Ihrem Leben gesehen haben!
So etwas haben Sie noch NIE gesehen! 100% GARANTIERT

Das wird sicher Ihr Leben komplett ändern!

Nur noch 429 Mal verfügbar!

Schauen Sie sich das Video an!

Hier klicken: >»ZUM VIDEO«<

Screenshot Mail
SPAM - SCAM - PHISHING MAIL:
http://arbeit-von-zuhause-aus.com/
  • https://www.virustotal.com/de/url/e7a5745161f044e06b3f75c5ec2b10cd724b9214dfd0d2b714ea9dee2eaf9d61/analysis/1396714323/
  • https://www.virustotal.com/de/file/06e076babd1bc5d7cd32d34f28fa54c4bdd37db5b50eb8328e0469ab29659bf3/analysis/1396714606/
OTHER LINK FOUND IN HTMLSRC:
http://www.mega-ways.com/index.php?d=forum&s=24
  • https://www.virustotal.com/de/url/e33e88bc05bacb38a97d9c73f111a852651edb02f5fcc9c5e99c1f10fc566ecd/analysis/1396718339/
TO MENTION HERE IS:
http://www.mega-ways.com/javascript/alphanumeric.js
  • https://www.virustotal.com/de/url/50d7f3901c7599a6af623faf05cf912b2e8ab05b4566ccd8ed69b6719c7308d0/analysis/1396716791/
Virus.exp.js.1
  • https://www.virustotal.com/de/file/bae1f370c9a4ae19a9bd6d68d98629c115f1f764a844691bfd406211ca321575/analysis/
Ihr Einkommen wird EXPLODIEREN - LOOOL

THROUGH:
http://www.redcappi.com/
  • https://www.virustotal.com/de/url/67dc853cd6c065dae93edf295021f261c0c3a2b181cdd28f6780119554a3cfca/analysis/
  • https://www.virustotal.com/de/file/c2bcdd9e4362bcb2341d8c18525b49f23bf5b5fc530ef43b4f13846bdb94a875/analysis/1396717343/
SPECIFIC MALICIOUS URL IN PHISH-MAIL:
http://www.redcappi.com/newsletter/clickrate/create/35671/MzY3NjczNjItZ2FyeWR1bnNtb3JlQGdtYWlsLmNvbQ/1
  • https://www.virustotal.com/de/url/39917f03a8488217564a62a540548c328a95b6aff48249951027f2b50aafd9d9/analysis/
---> REDIRECTS TO: (PHISHING INTENDED)
http://goo.gl/p3rL07
  • https://www.virustotal.com/de/url/5cab9105b00691593c6decf0b4702ba2798cbcfcd46331bed86f089e5913f759/analysis/
http://goo.gl/p3rL07 – this URL has been disabled. Note that goo.gl short URLs may be disabled for spam, security or legal reasons.


FULL REPORT:


Document hosting: UploadEdit.com

4/04/2014

"La Crise m'a frappe de plein fouet"
FRENCH SPAM of the Moment (March 2nd 2014):
globalmrkt.net (IPs: 14.3.2.2 & 66.111.202.245)
JAPAN & USA
SPAM, SCAM, PHISHING

La Crise m'a frappe de plein fouet, et pourtant cela
m'a rendu Riche tres rapidement.

En 2011, une catastrophe arrive au garage pour lequel
je travaillais. Le patron est tomber malade et nous
n'avons trouve personne pour reprendre cette petite
affaire sans grand interet...

Du coup nous les 5 employes, nous nous sommes retrouves
au chomage sans grand avenir devant nous surtout dans
notre région.

Cela a ete un coup terrible ...

Je n'avais nulle part ou aller, aucune idee de quoi
faire, avec un simple diplome de mecanicien obtenu
en travaillant dans ce meme garage...

Et pourtant, un amis tres aise a decide de me
prendre par la main et de m'expliquer comment
faire fortune avec un PC et une connexion internet.

Rendez-vous est pris chez lui, je n'en reviens pas
du luxe qui l'entoure, voiture, piscine, hifi,
le reve pour toute personne...

On s'installe devant son PC et il me fait voir
comment en quelques minutes il gagne 100€, c'est
tout simplement incroyable je n'en revenais pas.

Presser de rentrer a la maison pour me mettre
au travail j'en oublie presque de le remercier.

Bref fini les blablas...en quelques semaines j'ai
gagne plus d'argent quand 5 annee de travail au
garage c'est stupefiant et dur a croire.

Du coup comme je sais que beaucoup galere avec
cette crise mondiale, j'ai cree une page web
pour vous expliquer en details comment vous
aussi commencer a mettre en place ce systeme.

Pour vous y rendre cliquez simplement ici >>

Je suis content de pouvoir vous aider alors
n'hesitez pas a venir me parler sur MSN
si vous avez besoin de moi...

E-MAIL SCAM SCREENSHOT

MALICIOUS DOMAIN: SPAM, SCAM, PHISHING
http://globalmrkt.net/
  • https://www.virustotal.com/de/url/fc9354101dde316cc480db2faaa4a9cb4d67c1c83b442b437b271d798c3af9c3/analysis/1396623727/
http://globalmrkt.net/link.php
  • https://www.virustotal.com/de/url/f6ba43bb07d8bd0b29bd10e4c38a2ab65f5954d51bf4f297088d918ba2a76872/analysis/1396623762/
http://globalmrkt.net/open.php
  • https://www.virustotal.com/de/url/a0d3800e98aa335b3bd3e39ed0b0bc32fc3f46febeced00ebef054ceab3a4645/analysis/1396623856/
ORIGINATING IPs:
http://14.3.2.2/ (Asahi, JAPAN)
  • https://www.virustotal.com/de/url/452305e81bc2b995dadee0ad7a30c2a4071b6c5ad9d20d0aa7f3b049fa130c9f/analysis/1396623426/
  • http://www.senderbase.org/lookup/?search_string=14.3.2.2
MALICIOUS IP:
http://66.111.202.245/ (Santa Monica, USA)
  • https://www.virustotal.com/de/url/b4b642acac605882a2012b00bd46454690e5bcd475930800b2a21e95d517960e/analysis/1396624250/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=66.111.202.245
  • http://www.spamhaus.org/sbl/listings/ARIN
Fwd/Rev DNS Match: NO
EMAIL-REP: POOR
WEB-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=66.111.202.245
SEE AS WELL:
  • https://www.mywot.com/en/scorecard/globalmrkt.net
LISTED AT SURBL:
  • http://www.surbl.org/surbl-analysis


MALICIOUS ADs:
www.xforex.com (IP: 23.8.245.172)
risking with
Bad Reputation
Scam, Spam, Poor customer experience,
Misleading claims or unethical & Phishing
Cambridge, Massachusetts, USA


FOR WEBMASTERS & BLOGGERS
If you own a Website or a Blog and are affiliated with Google AdSense, in order to your own Reputation, should block the Domain www.xforex.com in your AdSense Dashboard. The Site is potentially Blacklisted. See the following Report:

Screenshot of XForeX.com

MALICIOUS AD: LEADS TO BAD REPUTATION DOMAIN 
Domain/host was seen to host badware at some point in time


SEE AS WELL:
Scam
Spam
Poor customer experience
Misleading claims or unethical
Phishing
  • https://www.mywot.com/en/scorecard/xforex.com


LINK:
http://www.googleadservices.com/pagead/aclk?sa=L&ai=C7kIPTbA-U9r2MqLu7Qa34oGICKiNkI4FiOvztmOE05t5EAEgjsCUI1DHtrnlBmC7A6AB-rD19APIAQKoAwHIA8EEqgTAAU_Q1g4toONI8eh4XQEyxHCFFEpgkD3s3VJSDzQPbzQ47fu8UJOB4_RNiCTdxf4vK_LKSdNczlvgb_vd2pb_mxTanR-wYBEI9aQX6KoWcCLae1OAI277O6w9N3KSo20c9UZMuh_-gNPlGVV7Cd8UnTVHSdTzazgwo_zpaKyeOiXHAgE_vEjWqA83eftbjPMD4XZsdyuLms2tiV8UB_jLN2NEzZjGZpxAkY_b6sFs54LPl8Vc7X3gP2wNAWpUH5NUc4gGAaAGAoAH7s6KCw&num=1&cid=5Gjyw7ojawW0czFIzezfwp9h&sig=AOD64_3DIimc5hTEw20ICdz_UVXHn3iwIQ&client=ca-pub-5585202032329389&adurl=http://www.xforex.com/ForexTradingTL%3Ftlid%3D115069%26src%3DAdWords%26medium%3DPPC%26campaign%3DAdGroupName%26ad%3D26652225616%26SiteTarget%3Dstayaway2.blogspot.com&nm=3&mb=2&bg=!A0TOlq2_SVCfUQIAAAA6UgAAABEqAPHBcvoWfHjKrzYiCXP8K18SMcCKicgztc2N1qFlSFwV-JoauJojxqe0p7gbnlnhPr1_XrKGNVLJLetSDJNw8-oa0_5Atqssh7YnQ1iAdBlL_sYFFUUD661JesYOjpxKL2xo4eHYTOWo8Rrim73oi0rkDTdIRZGqChSPt3--pLJ7IBdbaA1A_zkNhCvgo3w5evKr3lGHbnUQx_2lr0G5SiJf0SH6miR9ZfMSWPvWE39JGjUiQZ4OP8BHNHCJG-LK8EdzB4Dbu2JQ-RgdA0zCRBcrIEHy5EXJQ4vFdMaulhVEaD_q7cAC5jDhxi5Vtn-lDj5O
  • https://www.virustotal.com/de/url/d2a5d5d9bf918228e5cb654ae3798e09b8256ed110d5f633f18d60da82c56ded/analysis/1396617728/
URL after REDIRECT:
http://www.xforex.com/cms/lp/GSplit_FR/?cid=45&tid=115069&lid=fr&pubid=-1&reqt=1396617729225
  • https://www.virustotal.com/de/url/29ee4b6d441d8430c95f6f01b58c0eabbd1b3677f00cef5b6fd4a2faeb8d8d79/analysis/
DOMAIN ITSELF:
http://www.xforex.com/
  • https://www.virustotal.com/de/url/da5478eab00be730cd930a7dce16ecc2666df8586a018d366c83e8856d6064b5/analysis/
IP:
http://23.8.245.172/  (Cambridge, Massachusetts)
  • https://www.virustotal.com/de/url/28c450178989e65f572bff524c8cd114bdaf81864c8a5e9de52c89950428fceb/analysis/1396618830/
  • https://www.virustotal.com/de/ip-address/23.8.245.172/information/

4/01/2014

Introducing COMMENT SPAMMERS (so the NET will not FORGET)
Helping those sorrow ones out in Publicity,
otherwise no one would notice them....


www.home-staging-montreal.com
IP: 66.43.56.89
(Montréal)


Anonymous wrote on February 8th, 2014:

Pretty great post. I just stumbled upon your blog and wished to mention that I have truly loved surfing around your weblog posts. After all I will be subscribing in your feed and I am hoping you write once more very soon! 
My weblog: www.home-staging-montreal.com...



COMMENT SCREENSHOT



On this Post:



Screenshot of the Webpage:

One important Question remains: Would you buy something at a place where the Spammer is trying to Advertise through an Article thats subject to Cild Predators & Pedophiles harming Children ??? I BET NOT !!!
----------------------------------------------------------------------------------------------------------------------------------------------

SCAM OF THE DAY from:
"WIR BIETEN DARLEHEN" ("We Offer Credits")
With Greetings from Coquitlam (CANADA), Australia &...& ratgeberplatz.com

IHR SEID IN ALLE FINANZNÖTE ODER BENÖTIGEN SIE MITTEL ZU STARTEN IHR EIGENES GESCHÄFT? BRAUCHEN SIE DARLEHEN FÜR IHRE SCHULD ZU BEGLEICHEN ODER ZAHLEN SIE IHRE RECHNUNGEN?
Wir geben Kredite im Bereich von 7000 US-Dollar (sieben Tausend Dollar) bis zu 50.000.000 US-Dollar (50 Millionen Dollar) mit 3 % Zinssatz.



Füllen Sie das nachstehende Formular (ist kein Formular, nur Text im Mail) für die Anwendung von Darlehen durch:



Persönliche e-Mail-Adresse:

Name: Adresse:

Land:

Telefonnummer:

Menge, die benötigt werden:

Darlehen-Dauer:

Monatliches Einkommen:

Alter:

Geschlecht:



Sie sind Beratung senden Ihre Daten an diese e-Mail-Adresse ein: scoth_smitt@ymail.com



Alles Gute
Herr Rev Scoth Smitt (Blöder gehts wohl nicht!)
Screenshot of HOCHwürden.....

MALICIOUS: HIDDEN IfRAMES ALL OVER THE PLACE & INVOLVED IN PHISHING SCAM
http://sd43.bc.ca/
  • https://www.virustotal.com/de/url/8290fd493074a03e4b9c2e28e27d880175519bba5ec36b12f16aae864214fe44/analysis/1396302819/
http://sd43.bc.ca/Pages/default.aspx
  • https://www.virustotal.com/de/url/3430aa5e2fcb1a7be76346576a55c9179acb649e9ab39d83843e692dbf2eca0e/analysis/1396302945/
HTML: 
W32.HfsIframe.420f (WHATEVER IT MEANS REFERS TO A HIDDEN IFRAME)
  • https://www.virustotal.com/de/file/701247cb9f12329ce5558b3ceff20ab16a4f4880606b86cfe7fe474480f7299b/analysis/1396302682/
ORIGINATING IP(s) (ratgeberplatz.com again involved): Coquitlam (CANADA)
http://142.35.6.131/
  • https://www.virustotal.com/de/url/0878044af1696c27903ac4978f8113c96b1222f5461fbc8f2e9db3191934f1f1/analysis/1396304403/
http://14.2.27.4/   (Adelaide, Australia)
  • https://www.virustotal.com/de/url/3bdc4ddd451c4313001e49b924ff7ff7022ee6cec34bf8ec7b614487b5de2bf8/analysis/1396304621/

3/11/2014

DAILY PHISH, SPAM & SCAM:
news.online-surftipps.com & gratisinfoservice.de (IP 2.1.8.110)
"Revolutionäre Geschäftsidee:
Steigen Sie ein, und verlieren Sie dabei ihr ganzes Vermögen"

FRANCE & GERMANY

Sehr geehrte Damen und Herren,

Jetzt gibt es ein neues revolutionäres Geschäftsmodell, mit dem Sie in einen der größten Märkte weltweit einsteigen können.

Welcher das ist, erfahren Sie hier.
http://gratisinfoservice.de/ilead.php?prodid=_&agent=_
SCAM-Screenshot
http://gratisinfoservice.de/
  • https://www.virustotal.com/de/url/e1b612f6268292103b7df2845a421146f141143c714ef342b3a66f20b20eea8b/analysis/1394563241/
http://gratisinfoservice.de/ilead.php
  • https://www.virustotal.com/de/url/5a7fbc141a4903d49a1ef4f967d29681d710596b9497007d9319d6f4f6f29ddf/analysis/
Originating IP

2.1.8.110
  • https://www.virustotal.com/de/url/f511e3823cedc584bdcd55ec4b788197390a851dcf630c4398caba3cbc929d36/analysis/1394563757/

LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/query/bl?ip=2.1.8.110

Email Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=2.1.8.110
------------------------------------------------------------------------------------------------------------------------

http://news.online-surftipps.com/
  • https://www.virustotal.com/de/url/9b289c2e28e2790291f4b6fad96c31623ea5894c4867379652d4adbda52f3b38/analysis/1394563975/

2/24/2014

Category MALICIOUS DOMAIN & IP:
www.zbestclubreview2014.com (IP: 115.242.210.80)
Casino, Gambling
(PHISHING, SCAM, SPAM) (Ruby Palace, Mumbai, INDIA)


Auf unseren Webseiten finden Sie die besten Online Casinos mit exklusiven Angeboten, wenn Sie sich über unsere Webseiten registrieren.
Verschiedene Angebote wie Freispiele und Bonusse auf Einzahlungen erwarten Sie.

Besuchen Sie unsere Webseite, finden Sie Ihr neues Online Casino und profitieren Sie von einem exklusiven Angebot, das Ihnen am besten gefällt.

Klicken Sie hier, um unsere Webseite zu besuchen.
http://www.

zbestclubreview2014.com/
Mit freundlichen Grüßen

Bitte klicken Sie hier, wenn Sie von uns keine E-Mails mehr erhalten wollen:
http://unsubscribe.
zbestreview2014.com/


  • Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.
SPAM-Mail Screenshot
  • Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.

MALICIOUS DOMAIN(s): PHISHING, SCAM, SPAM

MAIL SENT THROUGH:
http://de-graaf.nl/
  • https://www.virustotal.com/de/url/9a2407169f616b2a2a036d1f5bdfdc1b586c3da935cbeb9586e394db4ebdb792/analysis/1393265245/
HTML (TITLE: test igr)
  • https://www.virustotal.com/de/file/897f06db515c21290c30c57dd1af5866fb260e19c213dd86af0c991bf5b2ab5f/analysis/1393265111/
IP:
http://109.109.120.43/
  • https://www.virustotal.com/de/url/3ea4a1d473e5c5d071795108a2ac018278483b00a9f78f903666ea1d8966dc72/analysis/1393265363/
  • https://www.virustotal.com/de/ip-address/109.109.120.43/information/
HOSTNAME:
http://pernis.cbizz.nl/
  • https://www.virustotal.com/de/url/1ffd59fd6c336547198255126d30d61be74c67d3ef51ad3dccac2037c71b43fa/analysis/1393265933/
HTML (PUA - LIKELY HOSTILE)
  • https://www.virustotal.com/de/file/b360defdc2da0baa651a970842c02965c9c7abf9aa64fc1313f4a4a1108faf3d/analysis/1393266111/
GETFILE: http://jsunpack.jeek.org/?report=516635988cbc568d4d2d43d0ad9c0e190325b4be
PUA.JS.Obfus-7
  • http://virusscan.jotti.org/de/scanresult/9bac55894b100053305d87eaf342fd1d7b967b33
  • http://www.UnmaskParasites.com/security-report/?page=pernis.cbizz.nl
DOMAIN:
http://cbizz.nl/
  • https://www.virustotal.com/de/url/1ef1ca00c396eeda1ca723d3780b7b912674431c8f5e5aff3d81e5c0b374a59b/analysis/1393266792/
----------------------

SPECIFIC "CASINO" (MALWARE) DOMAIN:
http://www.zbestclubreview2014.com/
  • https://www.virustotal.com/de/url/02ee438ea4071e0839c5b4f0839c174ff0413423e74f33227791241134dc444c/analysis/1393265668/
UNSUSCRIBE LINK:
http://unsubscribe.zbestreview2014.com/
  • https://www.virustotal.com/de/url/0e33f7e548f5d9685ac666974b4ded4025b0735f14b3e435b0c315555714a755/analysis/1393265770/
ORIGINATING IP ADDRESS:
http://115.242.210.80/
  • https://www.virustotal.com/de/url/98b43e7ad335c2310d1cb232e943d9bf9518613df8ba00d9f5dd41062a54e0c3/analysis/
LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/query/bl?ip=115.242.210.80
  • http://www.spamhaus.org/pbl/query/PBL386929
EMAIL REPUTATION: POOR
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=115.242.210.80




2/13/2014

Just another Spam from: www.ratgeberplatz.com:
„Herzlichen Glückwunsch“ („Congratulations“)
from Germany

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM SCREENSHOT from ratgeberplatz.com...


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel:

2/01/2014

PHISHING: Vier gute Gründe Mitglied zu werden (Ruby Palace) www.krubylotclub.com
Casino, Gambling
(PHISHING, SCAM, SPAM)








Wir von Ruby Palace wissen, was unsere Mitglieder am meisten schätzen und tun immer unser bestes, ihnen jeden Wunsch von den Augen abzulesen.

Dies bedeutet, sicherzustellen, dass wir Ihnen ein unglaubliches Casinoerlebnis bereiten. Hier ist ein Vorgeschmack auf die tollen Dinge, die Sie erwarten, wenn Sie ein Mitglied im Ruby Palace werden:

1.      Ein 200% Willkommensbonus, der Ihre erste Einzahlung verdreifacht.
2.      Mehr als 400 Premium-Casinospiele
3.      24/7 Kundenservice und schnelle & einfache Banking-Methoden
4.      Eine Auszahlungsquote von mehr als 97%

Melden Sie sich heute an, um von allen diesen exzellenten Vorteilen zu profitieren.

http://www.krubylotclub.com/

Alles Gute
Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.

Mail from www.krubylotclub.com

Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.

DOMAIN:
www.krubylotclub.com
  • https://www.virustotal.com/de/url/e0430bd5da60f34a52b77962ff8db3f58db3de15e0ac81a4ed7bf867e2805077/analysis/1391263051/
unsubscribe.krubylotream.com
  • https://www.virustotal.com/de/url/a318f68f910e57cb8578128b707107060b92ad451f98809bf4f102ed81567733/analysis/1391263054/
------------------------------------

LISTED AT SURBL:
  • http://www.surbl.org/surbl-analysis
SEE ALSO:
  • https://www.mywot.com/en/scorecard/krubylotream.com

1/31/2014

www.evensi.com
PHISHING DOMAIN for Facebook data (ITALY)

PHISING DOMAIN:


www.evensi.com
  • https://www.virustotal.com/de/url/7cf7ebcbf5bca37ad35d9e4a834aaececb7c63124cc899f41a452ca8b1aaa70f/analysis/1391182438/

IP:
149.3.145.97 
  • https://www.virustotal.com/de/url/3eea87e1338e148f193adbe50f76cd36a0fbefea6fc8b7282055d7b5c3d2b992/analysis/1391183069/

  • https://www.virustotal.com/de/ip-address/149.3.145.97/information/


Fwd/Rev DNS Match: NO

  • http://www.senderbase.org/lookup/?search_string=149.3.145.97



1/29/2014

Just another Spam from: www.ratgeberplatz.com:
„Exklusives Neujahrs-Angebot: o2 DSL + 50 Euro Willkommensbonus“
(„Exclusive New Years Deal: o2 DSL + 50 Bucks Welcome Bonus“)
Germany

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM SCREENSHOT from ratgeberplatz.com...


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel: 

1/28/2014

SPAM:
www.globalcitybusiness.com (LISTED AT DBL SPAMHAUS) &
www.streamlife.de (GERMANY)

Dieser Newsletter ist kein SPAM. Sie erhalten ihn, weil Sie bei
ihrer Anmeldung bei uns bzw. auf unserer Partnerseite dem
Newsletterempfang zugestimmt haben.

Die Angebote sind Anzeigen der jeweiligen Werbekunden, die für den Inhalt verantwortlich sind. Bei Fragen zum Inhalt, wenden Sie sich bitte an den Anbieter und nicht an die Adress Butler Ltd. da diese ausschliesslich der technische Versender dieser Nachricht ist!
Bitte antworten Sie nicht direkt auf diese E-Mail, da diese nicht zugestellt werden kann.

Technischer Versender der E-Mail ist die AdressButler Ltd,
Karl-Heinz-Beckurts-Str. 13, 52428 Jülich
Selbstverständlich können Sie der Nutzung Ihrer Daten jederzeit wiedersprechen. Sie wünschen keine weiteren Informationen,
klicken Sie bitte hier um sich abzumelden.
http://www.globalcitybusiness.com/unsubscribe.php

POTENTIALLY MALICIOUS SPAM DOMAIN(s): 
SCAM, PHISHING ETC. (LISTED AT SPAMHAUS)
www.globalcitybusiness.com
  • https://www.virustotal.com/de/url/111618ab5b6305880338fff2038a6dbdd5007efe2b7ae7886a91a25fb04cc1d9/analysis/1390927191/
www.globalcitybusiness.com/link.php
  • https://www.virustotal.com/de/url/352dbbd057b010a71041a76563b676358c7b98297fba1fda87b24f0386bb7b24/analysis/1390927504/
  • https://www.virustotal.com/de/file/23d32b79f3e71e41c2eb3d8811f58f72a2b6b5eb04c0981f16f61ab009945054/analysis/1386786113/
www.globalcitybusiness.com/open.php
  • https://www.virustotal.com/de/url/7a7a15b5d7f022340d21f099685c49ea8ff4f291b190d7ecb5cdd6417c8fa46d/analysis/1390927570/
  • https://www.virustotal.com/de/file/dd5bdccb831d1b19c505bd3e67553f6049cea2e20dba7eb231a02ed0103e521f/analysis/1390580473/
www.globalcitybusiness.com/unsubscribe.php
  • https://www.virustotal.com/de/url/a52381179dbe95f686a83ef039f938f62d3ddd1ac90c0898d1ed898f4cbf3745/analysis/1390927632/
  • https://www.virustotal.com/de/file/baefeec3f91b70b39b03c556d29dd1ad4eff87fe7bb0ba91fc3b774e70089281/analysis/1386768007/
  • http://www.urlvoid.com/scan/globalcitybusiness.com/
LISTED AT SPAMHAUS (DBL): 
(and not without reason, as they state in the e-mail: THIS IS NO SPAM)
  • http://www.spamhaus.org/query/domain/globalcitybusiness.com
 
E-Mail SS (ScreenShot)

www.streamlife.de
  • https://www.virustotal.com/de/url/87771b9dd41a23e777709022835837a7f32da2b361c54e3f6805bc6a9c554312/analysis/1390934550/
  • https://www.mywot.com/en/scorecard/streamlife.de
  • http://www.urlvoid.com/scan/streamlife.de/

1/25/2014

www.eldiamantis.com
"Rogue Affiliate Reveals $100m Loophole"
(PHISHING, SCAM & SPAM)


You need to see this...

It's the most important website you'll visit
this year.

Here's why...

On that site you'll discover about a new
automated system that exploits a $100m
loophole.

Now this system was put to the test and
here's the results...

From scratch it produced $4,264 in the first
7 days.

And on to generate $27,353 in it's first
month.

Now next is where this gets very interesting.

The momentum of this system grows and grows
and last month it earned a massive $221,555!

Yes... Almost a quarter of a million dollars
in a single month just a few months after
starting.

Just click below to watch a free video all
about this amazing new system...

http://imoffers.systemx.clicksurecpa.com


With $221,555 a month in profits I think
you understand why this website will be
the most important you visit all year... If
not the most important of your entire life.

You now have a VERY REAL chance to start
making some serious money online.

With this underground loophole you DON'T
need to worry about:

- Having an exiting website or blog

- Having lots of capital for investing
in advertising... Just a few dollars
needed

- Having any technical knowledge... It's
all explained in a simple step-by-step
process anyone can follow

And it doesn't even matter if you've
earned a single cent online before.

You can start from scratch today knowing
nothing and follow along to be making
money tomorrow.

In the test... $4,264 was generated in
the first 7 days.

Just visit the site now to get started
and watch the free video...

http://imoffers.systemx.clicksurecpa.com


Now the creators and guys who have been
testing this system are super confident
anyone can make this work.

THIS MEANS YOU!

So if YOU download the system and follow
it they're going to GUARANTEE your success

No joke!

If you don't make at least $1,000 in the
first 7 days then their going to hand
you a $500 for giving it a shot.

YOU CAN'T LOSE

Think about it, you can try it out and
the very worst case is you'll pocket
a $100 in a week.

BUT... Just think if you do just half
as good as what the test showed...

... You'd be pocketing over $2,000
this very week.

And around $14,000 in 30 days time.

... And with the growth momentum this
system has you'll be cashing in over
a million dollars in less than a year.

AND THATS IF YOU ONLY DO HALF AS GOOD
AS THE TEST RESULTS PROVED THIS SYSTEM
IS CAPABLE OF!

You really need to check this out and
download a copy while you can.

Click below to do it now:

http://imoffers.systemx.clicksurecpa.com


Regards

El Diamantis


POTENTIALLY MALICIOUS DOMAIN:
www.eldiamantis.com
  • https://www.virustotal.com/de/url/d34a9a3946b4b6ea780f93fba6b72ccebf6d9206ca93219e082417d1ac695c4f/analysis/1390660102/
  • http://urlquery.net/report.php?id=8988794
  • https://www.mywot.com/en/scorecard/eldiamantis.com
  • http://www.urlvoid.com/scan/eldiamantis.com/

Link shown in the Mail (3x):
imoffers.systemx.clicksurecpa.com
  • https://www.virustotal.com/de/url/ab3a5964037476981e23759423d85b4a118ab7c8ebac53daddf62cf429a47472/analysis/1390661644/

IP of imoffers.systemx.clicksurecpa.com: 78.137.119.93
  • https://www.virustotal.com/de/url/86d48e7997dc929a776bdfe5f0ab721d7b74bee3ebae2535efe9b167cff9f3a7/analysis/1390662412/
  • https://www.mywot.com/en/scorecard/78.137.119.93

imoffers.systemx.clicksurecpa.com REDIRECTS TO:
www.autocommissionsystemx.com
  The website was registered 28 days ago, surf with caution.
  • https://www.virustotal.com/de/url/a58a8b08388b1e554ccb4683ba479b660f479fc98c8e83078a55ae3f8af06ef2/analysis/1390661783/
  • http://www.urlvoid.com/scan/autocommissionsystemx.com/

IP of imoffers.systemx.clicksurecpa.com: 198.143.162.154

  • https://www.virustotal.com/de/url/e1c25855b8d97c544b059910e386735a892b8d5dc1203786df3dd373479e451e/analysis/1390663057/

IP is Listed at SPAMCOP:
  • http://www.spamcop.net/w3m?action=checkblock&ip=198.143.162.154

SCAM-Mail SCREENSHOT

1/20/2014

Category MALICIOUS DOMAIN & IP:
newquickonline.com & 66.111.239.213
"Comment Devenir Riche ?" (How getting Rich ?)
PHISHING, SCAM, SPAM


Salut, ce secret me rend malade
et je ne peux plus le garder pour
moi uniquement. J'ai donc decidé
de le partager avec vous, vous
allez découvrir comment des
centaines de personnes sont devenu
riche avec...

Ce système est très simple et un
enfant de 10 ans pourrait l'appliquer
sans aucune connaissance.

Allez je ne vous fait pas plus
attendre et je vous donne les
explications maintenant

Cliquez ici pour accèder au site>>>


Tenez-moi informe svp et si
besoin revenez vers moi.

How will i get rich...

Screenshot from newquick.blablabla SPAM-Mail
MALICIOUS DOMAIN: PHISHING, SCAM, SPAM
newquickonline.com
  • https://www.virustotal.com/de/url/8dc180690322fb938db7d494d01be61b662bd29f4bdf29833ba7ad15d15aeedb/analysis/1390244230/
HTML:
  • https://www.virustotal.com/de/file/faf4a27477bc73e59cb23ca28c0a2f7e8c0e687b380a14bf587118be749b52e0/analysis/1390244772/
  • http://jsunpack.jeek.org/?report=ec57c2558a8d13640f7875169e82616b25fab79e
newquickonline.com/unsubscribe.php
  • https://www.virustotal.com/de/url/995fa55fb73aa1d432a8a14dc9f517d0c8cb1ada8f5697b785f118f9fffce323/analysis/1390245841/
  • http://zulu.zscaler.com/submission/show/f38f148811a55cb99c4cc61af4b3b92c-1390244259
  • https://www.mywot.com/en/scorecard/newquickonline.com
  • http://www.urlvoid.com/scan/newquickonline.com/
LISTED AT SPAMHAUS:
  • http://www.spamhaus.org/query/domain/newquickonline.com
LISTED AT SURBL:
  • http://www.surbl.org/surbl-analysis
-----------------------------------------------------------------------------------------------------------------------------------

IP: 66.111.239.213
  • https://www.virustotal.com/de/url/7ea04d745a797e563f76710b1962e6d1c712eebead72ce2e17d17669a9cf1ebf/analysis/1390246347/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/ip/66.111.239.213

Email Reputation: POOR
WEB Reputation: POOR

  • http://www.senderbase.org/lookup/?search_string=66.111.239.213


1/19/2014

Just another Spam from: www.ratgeberplatz.com:
„Attraktive Singlefrauen suchen Sie, Herr“
(„Attractive single women are looking for you, Mister“)
Germany (Düsseldorf)

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM SCREENSHOT from ratgeberplatz.com...


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel: 

1/16/2014

Just another Spam from: www.ratgeberplatz.com:
„Entfliehen Sie der Schuldenfalle - gute Vorsätze 2014“
(„Avoid outstanding debts - in 2014 with Ratgeberplatz“)
Germany (Düsseldorf)

English:

www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

SPAM SCREENSHOT from ratgeberplatz.com



Für Deutsche Leser:

www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel: 


Category MALICIOUS DOMAIN: ustyutskoe.pestovskiy.okpmo.nov.ru
Casino, Gambling
(PHISHING, SCAM, SPAM)




Hallo!

Kannst du Dich erinnern, dass wir uns fur den 200% Willkommens-Bonus im Ruby Palace anmelden wollten?

Worauf warten wir noch? Lass uns noch heute registrieren, denn bis zu 300 Euro erhalt man nicht jeden furs Anmelden!

Das Warten hat ein Ende, jetzt registrieren und gleich spielen.


  • Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.

Mail from ustyutskoe.pestovskiy.okpmo.nov.ru

  • Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.


MALICIOUS DOMAIN:

ustyutskoe.pestovskiy.okpmo.nov.ru
  • https://www.virustotal.com/de/url/30ad4549e0264c9a27703b171e40715566d8112ad7aee36d170c0879d951dc37/analysis/
SPECIFIC LINK:

ustyutskoe.pestovskiy.okpmo.nov.ru/selected.htm
  • https://www.virustotal.com/de/url/da65c08e56f0564170939172bc0edea1e516ed89f86435b2fb57e698bd9f2341/analysis/1389875029/

INFECTED WITH:
RedirME-inf [Trj]
  • https://www.virustotal.com/de/file/19a15d7ad510575e5e83d9bfce898da071c7ca6a31a5e904f8d16275248b14ab/analysis/1389875518/
---> REDIRECTS TO:
rubyultragame.com
  • https://www.virustotal.com/de/url/02036856b00ada689a2ea3905d1b5be3bb2801b42c39e1eb88ff4e1a5ec671ce/analysis/1389876401/
  • https://www.mywot.com/en/scorecard/rubyultragame.com
LISTED AT SURBL:
  • http://www.surbl.org/surbl-analysis
LISTED AT hpHOSTS:
  • http://hosts-file.net/?s=rubyultragame.com
-----------------------------------
IP for ustyutskoe.pestovskiy.okpmo.nov.ru

62.118.131.170 (Russia)
  • https://www.virustotal.com/de/url/47e087a76843c97d526f1e48e20069bbd7291805610030cd31f3ca6079af2c9a/analysis/1389876928/
LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/pbl/query/PBL014097
  • https://www.virustotal.com/de/ip-address/62.118.131.170/information/
  • http://safeweb.norton.com/report/show?url=ustyutskoe.pestovskiy.okpmo.nov.ru
  • http://www.browserdefender.com/site/ustyutskoe.pestovskiy.okpmo.nov.ru

1/15/2014

Category MALICIOUS DOMAIN: rheumatoidarthritisgout49419.soup.io
Rogue Medications & Phishing Risk (AUSTRIA)
(GOOGLE PHISHING)

Potentially Malicious Site: Drugs & Medications (PHISHING RISK)








DOMAIN:
rheumatoidarthritisgout49419.soup.io
  • https://www.virustotal.com/de/url/52b67f6d4e0d46e81f5e560297c575c638a9ba33b43e1229718fc6929a9a1c91/analysis/
MALICIOUS LINK FOUND TO: (DOMAIN)
is.gd (U.K.)
  • https://www.virustotal.com/de/url/47a68b786b0e7abcc8263d257b7fe90a26be583647d9371b38ceb24c09332a3b/analysis/1389627324/
SPECIFIC LINK:
is.gd/fpnxbB
  • https://www.virustotal.com/de/url/61b5b6b25706c0ab0bde93ea941fbea8d7334f699957f88072ea49eb2a19e8e1/analysis/1389804055/



ADDITIONAL MALICIOUS LINK FOUND TO: (DOMAIN)
stomsk.ru (Lithuania)
  • https://www.virustotal.com/de/url/c2cb23d08ab0e0430674bda1ede032890408106f0c480b81423f85a38ba09716/analysis/1389626637/
SPECIFIC LINK:
stomsk.ru/pics/doc.jpg
  • https://www.virustotal.com/de/url/7dd47a1cf793aa3da415720b51e6d6452bfad57f42bc9c494322ea79a4363601/analysis/1389626639/



Category MALICIOUS DOMAIN: bleacherreport.com
Phishing Risk
(GOOGLE PHISHING, ROGUE MEDICATIONS)





MALWARE SITE: (PHISHING, SCAM, SPAM, FRAUD)


DOMAIN:


bleacherreport.com
  • https://www.virustotal.com/de/url/73e7cf76bf1c58ce62ab54cf4a28f320766b249d72cf66c7d210f87a1b7544b2/analysis/

IP bleacherreport.com: 54.225.139.135
  • https://www.virustotal.com/de/url/14f09c097abffce28cca7fd184550619551ff1f8d6b6451d417986f53e69e57b/analysis/1389788841/

POTENTIALLY SUSPICIOUS FILES: 24
  • http://quttera.com/detailed_report/54.225.139.135

SPECIFIC LINK:
bleacherreport.com/users/3821374-suhagra-100-reviews-alprostadil-injection
  • https://www.virustotal.com/de/url/55c49329a6f064acbf9464d02d2e796ebf9a7f6556299ec7d20145eb50168c8f/analysis/1389788405/

SPECIFIC LINK HAS A DIFFERENT IP: 23.23.134.171
  • https://www.virustotal.com/de/url/cf6b75943c44872f1e6da28708b1d7f3fcf39a05efdfc11eab3012c5f3e81815/analysis/1389788766/

POTENTIALLY SUSPICIOUS FILES: 40
  • http://quttera.com/detailed_report/23.23.134.171

http_inspect: UNKNOWN METHOD
  • https://urlquery.net/report.php?id=8823259 

DESTINATION IP: 195.159.219.10 (NORWAY, MALICIOUS)
  • https://www.virustotal.com/de/url/2124f63fafe3b2ad6f32d647633508a27ad79a2aee4cbc424baec79be1c3b327/analysis/1389789045/

Web Reputation: POOR
  • http://www.senderbase.org/lookup/?search_string=195.159.219.10

LISTED AT hPHosts:
  • http://hosts-file.net/?s=bleacherreport.com

LISTED AT TreatLog: Spam/Scam/Fraud
  • http://threatlog.com/search/bleacherreport.com/domain/
  • http://www.urlvoid.com/scan/bleacherreport.com/

POTENTIALLY SUSPICIOUS FILES: 139
  • http://quttera.com/detailed_report/bleacherreport.com

CLICKING GOES TO: (RBN 398)
is.gd/YixLnc
  • https://www.virustotal.com/de/url/686b3e88a398c31a7ffbaaafc874064f92e51133dc3f257b3dcf49a1183cf28c/analysis/1389794625/
----> URL after Redirection: GOOGLE.COM (PHISHING)

  •  https://urlquery.net/report.php?id=8824810