Translate

Posts mit dem Label Spambot werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Spambot werden angezeigt. Alle Posts anzeigen

6/07/2014

MALICIOUS UKRAINIAN BLOG VISITOR TO THIS SITE:
Domain: www.trustcombat.com
IP: 193.169.86.16
Both listed at SPAMHAUS (CBL & DBL)
Darkmailer, DirectMailer, r57shell



MALICIOUS UKRAINIAN BLOG VISITOR
DOMAIN:
http://www.trustcombat.com/
  • https://www.virustotal.com/de/url/2cf65d9d85697456c083934f86a3ff2ebe33957bdeb4a46bfcfade3757943dba/analysis/1402156166/
  • https://www.virustotal.com/de/file/7c480e29f808effb1f06aa2dfd0a97a3192fc649293ecb39679716f16c000a1a/analysis/1402155972/
SPECIFIC VISITING LINK:
http://www.trustcombat.com/faq.htm
  • https://www.virustotal.com/de/url/f82e2bab033491836777d7b66c735884473f12a8f2bc05cb94994411ab0729cc/analysis/
  • https://www.virustotal.com/de/file/dac8b8d3f068796c7eda0e4fc1e529c151fc069f0788ac2992f166f47a47b944/analysis/1402155861/
LISTED AT SPAMHAUS (DBL):
  • http://www.spamhaus.org/query/domain/trustcombat.com
SEE ALSO:
  • http://zulu.zscaler.com/submission/show/3c2cb0b556a921a810249fdbc9203e5a-1402155759
  • https://www.mywot.com/en/scorecard/trustcombat.com
ALSO:
Nginx Server SOFTWARE OUTDATED. VULNERABLE !
IP:
http://193.169.86.16/
  • https://www.virustotal.com/de/url/71b23f991cac80f7ca367f2d91c835c62b6b6bdb1e15965813640c1172e91429/analysis/1402157283/
  • https://www.virustotal.com/de/file/2c16cd2a73dd803fda6f64ad50e507d0d6e72474036008c13e01bbd188f22a75/analysis/1402157590/
  • https://www.virustotal.com/de/ip-address/193.169.86.16/information/

The IP Address 193.169.86.16 (IP LOCATION: Ukraine) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. It was last detected at 2014-06-06 07:00 GMT (+/- 30 minutes), approximately 1 days, 9 hours, 29 minutes ago.

It has been relisted following a previous removal at 2014-06-01 06:17 GMT (6 days, 10 hours, 21 minutes ago).

This IP is sending email in such a way to indicate that it is, or is NATting for a web server that is infected with a spam sending script, like Darkmailer, DirectMailer, r57shell, or some analogous Perl, PHP or CGI script.

IP LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=193.169.86.16
  • http://cbl.abuseat.org/lookup.cgi?ip=193.169.86.16
EMAIL REP: POOR
  • http://www.senderbase.org/lookup/?search_string=193.169.86.16

4/27/2014

What is Snowshoe Spamming ?

Snowshoe spamming is a spamming procedure in which the spammer (mostly a Spambot) uses a wide range of IP addresses in order to spread out the prepared spam load. The large spread of IP addresses makes it difficult to identify and trap the spam from where its originating from, allowing at least some of it to reach email inboxes. For companies which specialize in trapping spam, Snowshoe Spamming is particularly harmful, because it is difficult to trap it with traditional spam filters.


Like a snowshoe spreads the load of a traveler across a wide area of snow, snowshoe spamming is a technique used by spammers to spread spam output across many IPs and domains, in order to reduce reputation metrics and evade filters. Snowshoes are designed to spread a large weight across a wide area so that the wearer does not break through crusts of snow and ice, as snowshoe spam distributes a broad load of spam across a varied array of IP addresses in much the same way.

IP addresses in the United States were responsible for almost 27% of snowshoe campaigns

Like all spammers, snowshoe spammers anticipate that some of their unwanted emails will be trapped by spam filters. Snowshoe spamming gives more email a chance at getting through to an inbox, where it can reach a computer user.

Setting up a snowshoe spamming operation requires some resources and knowledge, as the spammer must have access to an array of IP addresses. Snowshoe spammers typically use an assortment of domains, which may be linked to different servers and providers to further spread the spam load. In a sampling of emails sent by a snowshoe spammer, repeating IP addresses are fairly rare, which means that filters must focus on the content, rather than the sender, to trap spam.

Legitimate providers of email services use a very narrow range of IP addresses for sending email. This is generally viewed as a mark of integrity, as is the use of clear disclosure about who owns the originating domain. By contrast, snowshoe spamming often involves domains which are hidden behind layers of anonymity, making it difficult to track down the owner and report abuse. Especially in nations with anti-spam legislation, tracking down the parties responsible for spam, spyware, and other malicious activities can be extremely difficult, because perpetrators are good at covering their tracks.

Several anti-spam attempts have focused on targeting specific domain registrars and hosts. Certain registrars are infamous for harboring spammers, and by identifying large numbers of spam sites in their client lists, anti-spam advocates hope to take down those sites or humiliate the registrar into tightening its terms of service. Snowshoe spamming sometimes exposes a systemic problem with a particular host, as anti-spam advocates realize that large amounts of spam originates from domains managed by the same company.

Snowshoe spam accounted for all but about 5% of spam from the U.S. top 10
Snowshoers use many fictitious business names (DBA - Doing Business As), fake names and identities, and frequently changing postal dropboxes and voicemail drops. Conversely, legitimate mailers try hard to build brand reputation based on a real business address, a known domain and a small, permanent, well-identified range of sending IPs. Snowshoers often use anonymized or unidentifiable whois records, whereas legitimate senders are proud to provide their bona fide identity.

Some showshoers use tunneled connections from their back-end spam cannon to the spam egress IP. The back-end IP address is not in the spam headers. ISPs, you are in a position to detect those back-end spam cannons by checking where traffic flows are coming from. Remember, the tunneled connection is not necessarily on port 25. Spamhaus always appreciates such information.

http://www.spamhaus.org/faq/section/Glossary#233

4/18/2014

Category MALICIOUS IP: 203.153.100.82

Infected with a spam sending trojan, proxy or some other form of botnet.
It HELOs as a bare IP address
(INDONESIA)

The IP Address 203.153.100.82 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-04-18 18:00 GMT (+/- 30 minutes), approximately 1 hours ago.

It has been relisted following a previous removal at 2014-04-09 01:07 GMT (9 days, 17 hours, 55 minutes ago).

The listing of this IP is because it HELOs as a bare IP address (A bare ip address looks like: "54.33.33.5"). It is not HELO'ing as itself ("203.153.100.82"). Not only is this a violation of RFC2821/5321 section 4.1.1.1, it's even more frequently a sign of infection.




These listings are often a sign of a compromised SSH account. If you are running a SSH service (especially on Linux), please check your ssh server logs (often/var/log/auth.log) for logins from unusual IP addresses not normally associated with that login id. If you find any, secure the associated account. This usually means changing the password or disabling the account.

If it's a mail server, see naming problems for details on how to diagnose and fix the problem. If you are running Symantec Protection Center, this appeared to be a known issue in the past. See this Knowlege Base item. Their KB item was updated October 18, 2010 to indicate that they now understand the issue. The KB item indicates that the problem will be resolved in a "future build", but no ETA was provided. If you have SPC's email notification feature turned on, we recommend checking through the Knowledge Base item to see if your version has this issue fixed. If not we recommend turning SPC's notification feature off before delisting your IP address as a temporary workaround.

--------------------------------------------------------------------------------------------------------------------------------------------

MALICIOUS IP:




Heuristic.LooksLike.HTML.Suspicious-URL.K
SPAMBOTSERVER, COMMENT SPAMMER, DICTIONARY ATTACKER, MALWARE
http://203.153.100.82/
  • https://www.virustotal.com/de/url/4d0bf7e41c8dceaebbafa1bf0c70c8b1560a49ce397a92df5a1913a979f70f37/analysis/1397848027/
  • https://www.virustotal.com/de/ip-address/203.153.100.82/information/
Heuristic.LooksLike.HTML.Suspicious-URL.K
  • https://www.virustotal.com/de/file/8822bad3d62e9fbc8dc272644c42f81e4fec540ef7f05c9fd7bcaa26aee7a61b/analysis/
HOSTNAME:
http://ip-82-100-static.velo.net.id/
  • https://www.virustotal.com/de/url/85f9e6aa401e85da826c0d9590b8b671a24afac3000580f79754982b0f9ffadf/analysis/1397850756/

IP BLACKLISTED AT:
1) SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/ip/203.153.100.82
2) COMPOSITE BLOCKING LIST:
  • http://cbl.abuseat.org/lookup.cgi?ip=203.153.100.82
3) SPAMCOP:
  • http://www.spamcop.net/w3m?action=checkblock&ip=203.153.100.82
4) CISCO SENDERBASE:
  • http://www.senderbase.org/lookup/?search_string=203.153.100.82
5) BLOCKLIST.DE:
  • http://www.blocklist.de/en/view.html?ip=203.153.100.82
6) PSBL.ORG:
  • http://psbl.org/listing?ip=203.153.100.82
7) WPBL.INFO:
  • http://www.wpbl.info/cgi-bin/detail.cgi?ip=203.153.100.82
8) PROJECT HONEYPOT:
  • https://www.projecthoneypot.org/ip_203.153.100.82
9) SORBS:
  • http://www.au.sorbs.net/lookup.shtml
10) NiX SPAM:
  • http://www.dnsbl.manitu.net/lookup.php?language=en&value=203.153.100.82
------------------------------------------

SEE ALSO:
  • https://urlquery.net/report.php?id=1397848399616
  • http://zulu.zscaler.com/submission/show/0d60892bc9e925ace8bf7a1c422b7358-1397848147
http://203.153.100.82/winbox/winbox.exe
  • https://www.virustotal.com/de/url/2e48031a59a5f99f23b91508988285232203405cb8640f3c8c40c24e1a702284/analysis/1397848218/
  • https://www.virustotal.com/de/file/eabfa1fd55a53367b901364486f5a5607b9ab04ad94403b7d0fc12509ad85321/analysis/

4/13/2014

Category MALICIOUS IP: Cutwail Spambot on IP 213.144.13.74 (Karlsruhe, GERMANY)
Pushdo Malware and Zeus Botnet - Dictionary Attacker


The IP Address 213.144.13.74 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-04-10 13:00 GMT (+/- 30 minutes), approximately 2 days, 23 hours, 29 minutes ago.

This IP is infected (or NATting for a computer that is infected) with the Cutwail Spambot. In other words, it's participating in a botnet.


Cutwail is a complex infection and requires a number of steps to ensure that it's eradicated.

First, Cutwail spams out very high volumes, and is one of the the largest vectors of malware on the Internet, and almost every cutwail infection also has a copy of the Pushdo (DDOS by web transaction) malware and/or the Zeus botnet. The Zeus botnet controls the Cutwail/Pushdo pair as well as does information stealing/keyboard logging. Hence, this is a very severe threat - not just to the owner of the infected computer, the other members of your internal network (if you have one) but the rest of the Internet too.

Second, there are two methods for detecting cutwail. One of the methods is by detecting the spams that cutwail sends. The other method does not work that way. This means that even if you block outbound port 25 from non-mail-servers on your local network, you can still detect a cutwail infection on your local network. This means that if you implement port 25 restrictions, you should implement logging so that you can detect what internal machines are being blocked by it and are thereby probably cutwail infections.

TO READ THE REST OF THIS ARTICLE, go to:

http://cbl.abuseat.org/lookup.cgi?ip=213.144.13.74

As well Listed at SORBS:
  • http://www.au.sorbs.net/lookup.shtml

Listed at SPAMRATS:
  • http://www.spamrats.com/lookup.php?ip=213.144.13.74

A small report on this IP can be seen by clicking the .txt. Icon:

Document hosting: UploadEdit.com

3/15/2014

Category MALICIOUS IP: Cutwail Spambot on IP 194.176.111.154 (Kyrgyzstan)
Pushdo Malware and Zeus Botnet - Dictionary Attacker


The IP Address 194.176.111.154 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-03-15 04:00 GMT (+/- 30 minutes), approximately 5 hours ago.

This IP is infected (or NATting for a computer that is infected) with the Cutwail Spambot. In other words, it's participating in a botnet.


Cutwail is a complex infection and requires a number of steps to ensure that it's eradicated.

First, Cutwail spams out very high volumes, and is one of the the largest vectors of malware on the Internet, and almost every cutwail infection also has a copy of the Pushdo (DDOS by web transaction) malware and/or the Zeus botnet. The Zeus botnet controls the Cutwail/Pushdo pair as well as does information stealing/keyboard logging. Hence, this is a very severe threat - not just to the owner of the infected computer, the other members of your internal network (if you have one) but the rest of the Internet too.

Second, there are two methods for detecting cutwail. One of the methods is by detecting the spams that cutwail sends. The other method does not work that way. This means that even if you block outbound port 25 from non-mail-servers on your local network, you can still detect a cutwail infection on your local network. This means that if you implement port 25 restrictions, you should implement logging so that you can detect what internal machines are being blocked by it and are thereby probably cutwail infections.

TO READ THE REST OF THIS ARTICLE, go to:

http://cbl.abuseat.org/lookup.cgi?ip=194.176.111.154

A small report on this IP can be seen by clicking the .txt. Icon:

Document hosting: UploadEdit.com

3/14/2014

Category MALICIOUS IP: 91.200.13.57 (UKRAINE)
Comment Spammer
Spamhaus Listed SBL190623

Ukranian Flag in Colours


CATEGORY MALICIOUS IP: 91.200.13.57 
(COMMENT SPAMMER, UKRAINE)

IP:
http://91.200.13.57/
  • https://www.virustotal.com/de/url/8dc15e28c1ef4acadca8a839d4ce140fcf76180fef657d7fbc6a1ed65d5d0b36/analysis/1394809243/
  • https://www.virustotal.com/de/ip-address/91.200.13.57/information/

THE IP IS LISTED AT SPAMHAUS (SBL): BOTNET SPAMMER
  • http://www.spamcop.net/w3m?action=checkblock&ip=91.200.13.57

E-MAIL REPUTATION: POOR

WEB REPUTATION: POOR
  • http://www.senderbase.org/lookup/?search_string=91.200.13.57
13.480 Web Post Submissions
  • https://www.projecthoneypot.org/ip_91.200.13.57
http://glubina.com.ua/
  • https://www.virustotal.com/de/url/0307b0678d32d537e08147614d05e160f27ac4f83777bc06c4083fa2997867b1/analysis/1394811245/

3/11/2014

Category MALICIOUS IP: 177.55.96.212 (BRAZIL)
Listed at SPAMHAUS (CBL)
Linux, FreeBSD or some other form of UNIX

The IP Address 177.55.96.212 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-03-04 14:00 GMT (+/- 30 minutes), approximately 6 days, 21 hours ago.

CBL has detected that this IP is infected with (or NATting for) a spambot that attempts to break into other systems using stolen or compromised credentials and sends VERY VERY large volumes of spam. The infected machine is probably Linux, FreeBSD or some other form of UNIX, but sometimes Windows machines are infected. CBL has zero tolerance for reinfections.

Of late some of these infections are facilitiated by a SSH Rootkit. See this link for more details.



In most cases, this IP address would be that of a shared hosting environment. If you are a customer of this environment, you will almost certainly not be able to do anything about it, only the administrators of the hosting environment itself can. Please contact your administrators, and refer them to this page.

If the administrators are reluctant to do anything please try to convince them, because there is nothing you can do to fix this problem.

One way of finding the user that is infected and spewing spam is to use the "lsof" (list open files) utility. "lsof" is available for most versions of UNIX-like systems such as Linux as part of the official distribution, but may not be installed by default. So first, make sure you have it installed. On many systems such as Ubuntu, you can install it by:

TO READ THE REST OF THIS ARTICLE, go to:

http://cbl.abuseat.org/lookup.cgi?ip=177.55.96.212

An example of a Malicious Domain hosted in this IP is for example:
http://jatrol.com.br/
To see the full Report of this Domain, click the .txt Icon:

Document hosting: UploadEdit.com

1/11/2014

Category MALICIOUS DOMAIN & IP: www.erubylifeland.com - 91.244.218.10 - POLAND (Maazben Spambot)


Sie sind herzlich eingeladen, den Palast zu besuchen - Ruby Palace, um genau zu sein.

Steuern Sie jetzt den Ruby Palace zum Spielen an und wir werden Sie mit einem Willkommensangebot ehren, das eines Königs würdig ist: einem ziemlich mächtigen 200% Bonus auf Ihre Einzahlung.

Nutzen Sie dieses Angebot, um Ihre Einzahlung zu verdreifachen und Sie könnten in kürzester Zeit über einen riesigen Kontostand herrschen.

Mit freundlichen Grüssen
 

Ihr Erubylifeland Team

  • Please notice that most of all those Mails that include "Ruby" (Example), are connected to Gambling Sites who want to "steal" your hard earned money in many different ways. You will ALWAYS lose. Consider going to a "real" Casino, instead of gambling online, although the chance losing more money than gaining it is potentially low as well. "Ruby"-Mails are not only SPAM but as well Scam, Phishing, and downloads of Malware (Riskware). These domains rarely last more than a month and they change the name again. Ignore & delete those Mails and the included links. Otherwise you will be set onto a potential Risk, damaging your PC.

Mail von Erubylifeland
  • Bitte beachten sie dass sogut wie alle E-Mails die im URL den Namen "Ruby" (Beispiel) enthalten und die im SPAM-Ordner liegen (oder auch nicht), in Verbindung stehen mit (zum Teil illegalem) Glücksspiel (Online-Casinos), die nur darauf bedacht sind ihr hart erworbenes Geld aus der Tasche zu ziehen. Wenn Sie aber unbedingt "zocken" möchten, wäre es ratsamer ein echtes Casino zu besuchen. Obwohl man dort im Normalfall auch, eher ärmer als reicher dieses verlässt. "Ruby-Mails" stehen nicht nur mit SPAM im Zusammenhang, sondern auch mit SCAM, Phishing und schädliche Downloads von schädlicher Software (ganz oft werden diese schädlichen Downloads ohne Wissen des Besuchers) auf den PC heruntergeladen. Am besten ist man meidet diese Sites, ansonsten könnte ihr PC beschädigt werden.


MALICIOUS DOMAIN:

www.erubylifeland.com
  • https://www.virustotal.com/de/url/461d5ed2b1d86155c33e98e87b5bb3533bb190e7c6e82457e3cc48c36e93b452/analysis/1389460924/
  • https://www.mywot.com/en/scorecard/erubylifeland.com
  • http://www.urlvoid.com/scan/erubylifeland.com/
  • http://zulu.zscaler.com/submission/show/e35a53031a4236e5f8b7f322288f38e4-1389461000
 unsubscribe.erubylifeclub.com
  • https://www.virustotal.com/de/url/4c904ba17f77b20a4c778e464663ea4c2f5afc6e9ae6503105829141f4f916a3/analysis/1389461056/
  • http://www.urlvoid.com/scan/unsubscribe.erubylifeclub.com/
  • http://zulu.zscaler.com/submission/show/5b7833d704bb569c4b177b02dc576d59-1389461258

The IP Address 91.244.218.10 (IP Location: POLAND) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. This IP is infected (or NATting for a computer that is infected) with the Maazben Spambot. In other words, it's participating in a botnet.
 

IP address: 91.244.218.10 (Originating from that E-Mail)
  • https://www.virustotal.com/de/url/9914108464941e650189d7b09e26313dd5942a6c12814b298fe2840d56ebe73c/analysis/1389461915/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=91.244.218.10
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=91.244.218.10
LISTED AT Reputationauthority:
  • http://www.reputationauthority.org/lookup.php?ip=91.244.218.10
Email Reputation: Poor
Spam Level: Critical & Very High

  • http://www.senderbase.org/senderbase_queries/detailip?search_string=91.244.218.10

For Additional INFORMATION on the Maazben Spambot check these links:

Related Post:

Category MALICIOUS IP: Maazben Spambot - 91.244.218.10 - POLAND - (PHISHING, SCAM, SPAM, MALWARE)


The IP Address 91.244.218.10 (IP Location: POLAND) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. This IP is infected (or NATting for a computer that is infected) with the Maazben Spambot. In other words, it's participating in a botnet.


Originating from this SPAM-Mail
IP address: 91.244.218.10
  • https://www.virustotal.com/de/url/9914108464941e650189d7b09e26313dd5942a6c12814b298fe2840d56ebe73c/analysis/1389461915/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=91.244.218.10
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=91.244.218.10
LISTED AT Reputationauthority:
  • http://www.reputationauthority.org/lookup.php?ip=91.244.218.10
Email Reputation: Poor
Spam Level: Critical & Very High

  • http://www.senderbase.org/senderbase_queries/detailip?search_string=91.244.218.10


RELATED MALICIOUS DOMAINS:
www.erubylifeland.com
  • https://www.virustotal.com/de/url/461d5ed2b1d86155c33e98e87b5bb3533bb190e7c6e82457e3cc48c36e93b452/analysis/1389460924/
  • https://www.mywot.com/en/scorecard/erubylifeland.com
  • http://www.urlvoid.com/scan/erubylifeland.com/
  • http://zulu.zscaler.com/submission/show/e35a53031a4236e5f8b7f322288f38e4-1389461000
 unsubscribe.erubylifeclub.com
  • https://www.virustotal.com/de/url/4c904ba17f77b20a4c778e464663ea4c2f5afc6e9ae6503105829141f4f916a3/analysis/1389461056/
  • http://www.urlvoid.com/scan/unsubscribe.erubylifeclub.com/
  • http://zulu.zscaler.com/submission/show/5b7833d704bb569c4b177b02dc576d59-1389461258
For Additional INFORMATION on the Maazben Spambot check these links:

1/07/2014

Category MALICIOUS DOMAIN & IP: www.7secretsearch.com - Referrer-Bot - Spam-Bot - (IP: 192.157.253.9 - United States)

Potentially Malicious Spam (PHISHING, REFERRER) Domain:


 SECRET SPAM 

 

How To Control Visits From Referring Bots Such as Vampirestat, 7secretsearch and Adsensewatchdog ?


Have you ever been annoyed by these sites which increases your visits in your blog and no visits appear in Google Analytics? Or the infamous Whos.amung.us toolbar ? The anonymous robot visits from Vampirestat or Adsensewatchdog and www.7secretsearch.com. Neither Adsensewatchdog nor any other of these Bots have anything whatsoever to do with Google or Google AdSense and are simply spam sites that use automated traffic to blogs to attract clicks to their own sites from blog owners such as you.

Stay away. Traffic from these sites won't affect your standing with the real Adsense, so just ignore them.

Follow the next steps to get these bots under contol and to reduce their traffic:
  • Never click on the referred Domain links in your Blog or Webmaster Satistics, or visit their site.
  • Instead make a post (like this one) on your blog, with a negative review. On the long run their reputation will fall down to negative. Reputation is all that makes them lose.
  • Go to Virus Total (you can stay there anonymous), scan the URL of that Malware Domain, and give em a red flag. If you register you can also post your meaning giving a review. On my blog, if you look through deeply enough, there are enough referring Lookup-Domains for getting information (good or bad) upon a suspicious link or Domain.
  • Additionally, you also can submit a SPAM report to Google (Webmastertools) here.
Vampirestat whois info can be found here:


DOMAIN:
www.7secretsearch.com
  • https://www.virustotal.com/de/url/739a8261db4d68ae323ed83cfbc607b660a24b795f8303556f69a16ff8401d3d/analysis/1389109170/
  • https://www.mywot.com/en/scorecard/7secretsearch.com

www.7secretsearch.com also LINKS TO THESE MALICIOUS DOMAINS (either directly or indirectly):
widgets.amung.us
  • https://www.virustotal.com/de/url/7d7680eeb36197872a2ece324606e7743b74fd3a8e9630c6c368a3e1e21750b3/analysis/1389106363/
  • https://www.mywot.com/en/scorecard/widgets.amung.us
ad.yieldmanager.com
  • https://www.virustotal.com/de/url/e0a975001a88f4f74a9d2b665d51f2926c2419314d71064df9154651e39cf4a3/analysis/1389106564/
  • https://www.mywot.com/en/scorecard/ad.yieldmanager.com
content.yieldmanager.edgesuite.net
  • https://www.virustotal.com/de/url/e6800829b1dc059b832b190918b88a3bf2a9e3abec2ec851fd97f1ef0cae3d5f/analysis/1389106685/
  • https://www.mywot.com/en/scorecard/content.yieldmanager.edgesuite.net
i.imgur.com
  • https://www.virustotal.com/de/url/342cf1310c26da63f694aa634371ad46b4eca8e3a872cf6fa57580da670b3f18/analysis/1389110141/ 
  • http://www.urlvoid.com/scan/i.imgur.com/
  • https://www.mywot.com/en/scorecard/i.imgur.com
ads1.qadabra.com
  • https://www.virustotal.com/de/url/12a7166afab22285b29fbb66a049ff087a12cc15de8946c14c8f854a32753030/analysis/1389110286/
  • https://www.mywot.com/en/scorecard/ads1.qadabra.com
******************************************
IP:
www.7secretsearch.com = 192.157.253.9
  • https://www.virustotal.com/de/url/53855973d65537bd71949729a1f4d4d0e8cb9abb1a4cf483e3cbabaa00b3b0ed/analysis/1389106168/
  • https://www.virustotal.com/de/ip-address/192.157.253.9/information/
Fwd/Rev DNS Match: No
  • http://www.senderbase.org/lookup/?search_string=192.157.253.9
RELATED POSTS: 

Category MALICIOUS DOMAIN & IP: www.vampirestat.com - Referrer-Bot - Spam-Bot - (IP: 192.157.253.9 - United States)

Potentially Malicious Spam (PHISHING, REFERRER) Domain:


 

How To Control Visits From Referring Bots Such as Vampirestat and Adsensewatchdog ?


Have you ever been annoyed by these sites which increases your visits in your blog and no visits appear in Google Analytics? Or the infamous Whos.amung.us toobbar ? The anonymous robot visits from Vampirestat or Adsensewatchdog. Neither Adsensewatchdog nor any other of these Bots have anything whatsoever to do with Google or Google AdSense and are simply spam sites that use automated traffic to blogs to attract clicks to their own sites from blog owners such as you.

Stay away. Traffic from these sites won't affect your standing with the real Adsense, so just ignore them.

Follow the next steps to get these bots under contol and to reduce their traffic:
  • Never click on the referred Domain links in your Blog or Webmaster Satistics, or visit their site.
  • Instead make a post (like this one) on your blog, with a negative review. On the long run their reputation will fall down to hell. Reputation is all that makes them lose.
  • Go to Virus Total (you can stay there anonymous), scan the URL of that Malware Domain, and give em a red flag. If you register you can also post your meaning giving a review. On my blog, if you look through deeply enough, there are enough referring Lookup-Domains for getting information (good or bad) upon a suspicious link or Domain.
  • Additionally, you also can submit a SPAM report to Google (Webmastertools) here.
Vampirestat whois info can be found here:


DOMAIN:
www.vampirestat.com
  • https://www.virustotal.com/de/url/351a5e04578dbede25165617ca14aa393ee229efdc533bae6a1f0960af976edf/analysis/1389105156/
  • https://www.mywot.com/en/scorecard/vampirestat.com
  • http://www.urlvoid.com/scan/vampirestat.com/
www.vampirestat.com also LINKS TO THESE MALICIOUS DOMAINS (either directly or indirectly):
widgets.amung.us
  • https://www.virustotal.com/de/url/7d7680eeb36197872a2ece324606e7743b74fd3a8e9630c6c368a3e1e21750b3/analysis/1389106363/
  • https://www.mywot.com/en/scorecard/widgets.amung.us
ad.yieldmanager.com
  • https://www.virustotal.com/de/url/e0a975001a88f4f74a9d2b665d51f2926c2419314d71064df9154651e39cf4a3/analysis/1389106564/
  • https://www.mywot.com/en/scorecard/ad.yieldmanager.com
content.yieldmanager.edgesuite.net
  • https://www.virustotal.com/de/url/e6800829b1dc059b832b190918b88a3bf2a9e3abec2ec851fd97f1ef0cae3d5f/analysis/1389106685/
  • https://www.mywot.com/en/scorecard/content.yieldmanager.edgesuite.net
******************************************
IP:
www.vampirestat.com = 192.157.253.9
  • https://www.virustotal.com/de/url/53855973d65537bd71949729a1f4d4d0e8cb9abb1a4cf483e3cbabaa00b3b0ed/analysis/1389106168/
  • https://www.virustotal.com/de/ip-address/192.157.253.9/information/
Fwd/Rev DNS Match: No
  • http://www.senderbase.org/lookup/?search_string=192.157.253.9
RELATED POST: 

Category MALICIOUS DOMAIN & IP: www.adsensewatchdog.com - Referrer-Bot - Spam-Bot - (IP: 62.116.143.21 - GERMANY)

Potentially Malicious Spam (PHISHING, REFERRER) Domain:


 

How To Control Visits From Referring Bots Such as Vampirestat and Adsensewatchdog ?

Have you ever been annoyed by these sites which increases your visits in your blog and no visits appear in Google Analytics? Or the infamous Whos.amung.us toolbar ? The anonymous robot visits from Vampirestat or Adsensewatchdog. Neither Adsensewatchdog nor any other of these Bots have anything whatsoever to do with Google or Google AdSense and are simply spam sites that use automated traffic to blogs to attract clicks to their own sites from blog owners such as you.

Stay away. Traffic from these sites won't affect your standing with the real Adsense, so just ignore them.

Follow the next steps to get these bots under contol and to reduce their traffic:
  • Never click on the referred Domain links in your Blog or Webmaster Satistics, or visit their site.
  • Instead make a post (like this one) on your blog, with a negative review. On the long run their reputation will fall down to negative. Reputation is all that makes them lose.
  • Go to Virus Total (you can stay there anonymous), scan the URL of that Malware Domain, and give em a red flag. If you register you can also post your meaning giving a review. On my blog, if you look through deeply enough, there are enough referring Lookup-Domains for getting information (good or bad) upon a suspicious link or Domain.
  • Additionally, you also can submit a SPAM report to Google (Webmastertools) here.
Adsense Watchdog whois info can be found here:


DOMAIN:
www.adsensewatchdog.com
  • https://www.virustotal.com/de/url/921112e01ece904b7e24283c7ec7ef528e7a3dc1ac245b8f587e6433436ce107/analysis/1389090321/
  • http://zulu.zscaler.com/submission/show/fe117411f30d42cb7739f297064075f2-1389090365
  • https://www.mywot.com/en/scorecard/adsensewatchdog.com
  • http://www.urlvoid.com/scan/adsensewatchdog.com/
adsensewatchdog also LINKS TO MALICIOUS DOMAIN:
g.ateway.net/scripts/js3caf.js
  • https://www.virustotal.com/de/url/0b99952398ba93d977c9cc1e2643ceafe173bfabe3457b2ab3e625458dbc983e/analysis/1389090678/
*************************************
IP:
www.adsensewatchdog.com = 62.116.143.21
  • https://www.virustotal.com/de/url/39f28e85728fbfeaa15bee84c353657140821d8e8b77585f1e57bbd8628ebf60/analysis/1389091150/
  • http://www.urlvoid.com/ip/62.116.143.21
Web Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=62.116.143.21
  • https://www.virustotal.com/de/ip-address/62.116.143.21/information/
 
RELATED POST: