Translate

Posts mit dem Label Sanayi werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Sanayi werden angezeigt. Alle Posts anzeigen

4/16/2014

PUA.Phishing.Bank @ www.sinaafra.com
PHISHING URLs FROM Sanayi, TURKEY
(IP: 212.68.50.31)

PHISHING LINKS: 
PUA (PHISHBANK)

DOMAIN:
http://www.sinaafra.com/
  • https://www.virustotal.com/de/url/918c5ec31a6f15e91d44cd1aa9cd40efa5b93e44dac77b212f4faf471d9f8894/analysis/1397667269/
PHISHING URLs:
1)
http://www.sinaafra.com/detroit-ve-istanbul-aslinda-birbirine-cok-yakin
  • https://www.virustotal.com/de/url/7ffa8b6b95e71ee3cac62063009b0d0f70c9f0f1770070208d9e8fa772895682/analysis/1397667413/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/b0be1f8cf908f6ac5e508c4d1a0386c890193655bd419c4b88a74cfbda37f483/analysis/1397666858/
  • http://virusscan.jotti.org/de/scanresult/f439c8d1c4cdf2efb3ae8c6b4448ed0175c1f538

2)
http://www.sinaafra.com/sosyal-ticaretin-kirilma-noktasi-daha-ufukta-gozukmuyor
  • https://www.virustotal.com/de/url/e40dd9a4b165bd4a8e274017f30c18141289ca4d5aec039424874af6788a490d/analysis/1397667642/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/d60d5d52ffbd6bf038b5dc5ba8b6ef004a4914a68dd6d2b9f7928f3880af1e09/analysis/1397667089/
  • http://virusscan.jotti.org/de/scanresult/1904fa37af41fe728a89a251a6097700ffc3e3d7
IP:
http://212.68.50.31/  (Sanayi, TURKEY)
  • https://www.virustotal.com/de/url/8741b7d59e97bedf742d7fe933fa278819d651ba8d295931f093146c3a8f5e6e/analysis/1397668079/
  • https://www.virustotal.com/de/ip-address/212.68.50.31/information/

2/20/2014

Trojan Smartasses try to fool with underscore:
www.doymus.net infected by Trojan-Downloader.JS.Iframe.cba
(Sanayi, TURKEY)







MALWARE: Trojan-Downloader (RBN 368)

http://www.doymus.net/Domains/domainname.jpg_/
  • https://www.virustotal.com/de/url/bcf3c8d06a94352143e87576c1e33f2d96704165d5eea0a65e44c9294c042b7f/analysis/1392890782/
Trojan-Downloader.JS.Iframe.cba
  • https://www.virustotal.com/de/file/e735971a24c6c3cfc59ccbdd455f353734fe3c11484f3461071628b4e7728b94/analysis/1392891118/




EITHER

http://afonya123.com/r/g.php
  • https://www.virustotal.com/de/url/9a529a399ed40360a792e5bb92b09d68fe6c3b54beb7152108ce279910160b69/analysis/1392892392/
JS:ScriptIP-inf [Trj]
  • https://www.virustotal.com/de/file/5a9b0eab6c9ea56986c8530f9cec3286ca339738b370f3e99285178470c0cac6/analysis/1392891103/
  • https://www.virustotal.com/de/file/9d8ab0819fbc70b5b813b5494ea7b2d265ba9d17539be6d0f5e9687843bd04ea/analysis/1392892609/
  • https://www.virustotal.com/de/file/ed6cf4753e2ead2289eb857df21df42d6ef61e120013552d36e04a036e46a98c/analysis/1392892669/

OR

http://sandiiegoexpo.ru/expocity.html
  • https://www.virustotal.com/de/url/e10e79b4164439018d53e5e5c2292249139f22847952d6a698f579c2ce1dcc18/analysis/1392892505/

------------

  • http://jsunpack.jeek.org/?report=8e80d2752b1684ccb8932f9fcacd6aba48781b73
  • http://jsunpack.jeek.org/?report=54d2ad555e3ffbfe355275443ee1dcd9ecc779b9