Translate

Posts mit dem Label Spamhaus Listed (SBL) werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Spamhaus Listed (SBL) werden angezeigt. Alle Posts anzeigen

5/04/2014

PHISHING SCAM !
Subject: The hottest sex positions in the world from:
wonder-save.de (IP: 46.137.116.197)



SPAM - SCAM - PHISHING DOMAIN
(MAIL THROUGH sexpositions@load-next.com)

http://www.wonder-save.de/
  • https://www.virustotal.com/de/url/4cbee3944f626152a7b0e565989dfcdfa97128d9e1661e8b2f881544bdcf38a7/analysis/1399057180/
HTML=LOOOOOOOLLL (Rattenscharfe Amateute am laufenden Band)
  • https://www.virustotal.com/de/file/d079714ab2586e4eb1d64bdea7ea0904160f2c848b0cb84b1c4040e82f79e501/analysis/1399057765/


BitDefender DOMAIN information: "This URL domain/host was seen to host badware at some point in time"


DOMAIN BLACKLISTED AT:
1) WOT
  • https://www.mywot.com/en/scorecard/wonder-save.de
2) SURBL
  • http://www.surbl.org/lists
3) JoeWein
  • http://www.joewein.net/
ADDITIONAL LINK:
http://www.wonder-save.de/o/e181067801c9b41237c8ca23126a2754c00befbb41d019e0470c71483874f92d
  • https://www.virustotal.com/de/url/2a9d116e843f5d5ca49d2b1e8fecb2be80998c6d79b9fccfeacd62a13a0f4ee3/analysis/1399063964/
HTMLSRC
  • https://www.virustotal.com/de/file/b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b/analysis/1398895856/
REDIRECTION TO --->
http://www.medusa.mx/open/e181067801c9b41237c8ca23126a2754c00befbb41d019e0470c71483874f92d
  • https://www.virustotal.com/de/url/d8053385191d602cccc3bde8afc22a3f99814f27d239f74787787b55b110a46f/analysis/
HTMLSRC
  • https://www.virustotal.com/de/file/b1442e85b03bdcaf66dc58c7abb98745dd2687d86350be9a298a1d9382ac849b/analysis/1398895856/
DOMAIN:
http://www.medusa.mx/
  • https://www.virustotal.com/de/url/a451ede892082c712db5d49ed9152ed9bb0dd59aad190acb4be3d4d1320b8bfc/analysis/1399064361/
IP:
http://176.34.253.56/
  • https://www.virustotal.com/de/url/d4999bea2206837dff08b433a4c099eb794b7f1e3c5aafb7cad21895a2382f86/analysis/1399065373/
  • https://www.virustotal.com/de/ip-address/176.34.253.56/information/
REDIRECTS TO --->
http://newsletterabo.com/
  • https://www.virustotal.com/de/url/53fb33f8aea6cfadcd5fcaea7cf34509d2e95721acefa4058490a024d37eb9bd/analysis/1399064949/
IP:
http://62.129.143.124/
  • https://www.virustotal.com/de/url/753211dc1d21447d75875e36d3dd36c195078e99d32c3039c3dbee0232c96cd6/analysis/1399066574/
  • https://www.virustotal.com/de/ip-address/62.129.143.124/information/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=62.129.143.124
Some 5000 SPAMVERTIZED DOMAINS ARE hosted HERE:
  • http://www.spamhaus.org/sbl/query/SBL112409
WEB-REP: POOR
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=62.129.143.124
HTMLSRC
  • https://www.virustotal.com/de/file/ed3d4bf96a6e2c0c0f9ac7b27701b8dbab3fbfeb8078a3b4a847c1a797d8cd6d/analysis/1399064611/
SEE AS WELL:
  • http://sitecheck.sucuri.net/results/www.medusa.mx
  • http://sitecheck.sucuri.net/results/newsletterabo.com
-----------------------

MAIL SENT THROUGH:
http://load-next.com/
  • https://www.virustotal.com/de/url/7ac028fb0869d91755fb1a260da32b7189872856761e98b271bbf7c54283b670/analysis/1399061768/
  • https://www.virustotal.com/de/file/989e7a7c0680624b684c78468a1a1909c98a96dbce68c3a6d9a7d9122314aceb/analysis/1399061565/
  • https://www.virustotal.com/de/file/4ee70fe07827224c29f73047c71569c8fe740b370506cdd8b13e203a0ea5244d/analysis/1399061582/
IP:
http://95.130.125.232/ (AUSTRIA)
  • https://www.virustotal.com/de/url/e75688860b8f4224a5c62a7bfdb9c424a7a1e97e237eb40730d991c7d7e2ea42/analysis/1399063376/
  • https://www.virustotal.com/de/ip-address/95.130.125.232/information/
Fwd/Rev DNS Match: NO
  • http://www.senderbase.org/lookup/?search_string=95.130.125.232
-----------------------

IP:
http://46.137.116.197/
  • https://www.virustotal.com/de/url/1475cbe1f128f13cfbc44a6ef054af0e4edbfe87b1a881fcf912045eb62ab857/analysis/1399059664/
  • https://www.virustotal.com/de/ip-address/46.137.116.197/information/

4/26/2014

PHISHING: Re: Bestellbestätigung.
"ACHTUNG ! Sondernewsletter !"
FROM:
Snowshoe Spammer mawamalai.com (IPs: 79.124.56.67 - 79.124.56.70)
PUA.JS.Xored

BULGARIA



ACHTUNG! Sondernewsletter!

Sie haben keine Bestellung bei uns getätigt. Sie werden es aber wie 97.2% der Leser tun, wenn Sie diese Mail gelesen haben!
Rührende Geschichte bringt Moderatorin von "Raus aus den Schulden" zu weinen!

Arbeitslos und mit über 130.000 Euro verschuldet!
Dieser Mann änderte sein Leben und verdient mit diesem System bis zu 263,69 Euro am Tag!
Bald von hohen Schulden zum Reichtum? RTL2 testete Live im TV!

Die Moderatoren waren verblüfft! Sie können es auch! Uns zwar absolut KOSTENLOS!
Doch es gibt einen Haken! Dieses Patent wird ist leider stark begrenzt.
Denn der Patentbesitzer hat dieses System an eine US Bank verkauft!

Nur Diejenigen, die sich noch rechtzeitig registrieren, dürfen das System lebenslänglich kostenfrei nutzen!

Schauen Sie sich schnell das Video an, das Ihr Leben verändern wird!


HIER GEHT ES ZUM VIDEO

Sollte der Link nicht funktionieren, dann kopieren Sie bitte die Domain in den Browser: http://b-unitd.com/9uy

Click here to unsubscribe


Mail Screenshot

PHISHING SPAM-DOMAIN: 
FROM BULGARIA
http://mawamalai.com/
  • https://www.virustotal.com/de/url/6896cabd8597b88bada31b7daa824a29a707f6ab3078291cc0fc256bdbdbdf12/analysis/1398514506/
HTML:
  • https://www.virustotal.com/de/file/dbb6e6caba47b4688bd5a128e57eb8d26620942b13d5b07a0fa51d75fde63d2a/analysis/1398514432/

*********************************************************************************************************************

ANALYSIS IP: 79.124.56.67
http://79.124.56.67/
  • https://www.virustotal.com/de/url/ef621203c8c566900d8a693072d085991dd8111f907a5a97aa828560f19ede02/analysis/1398517859/
Invalid HTML data
  • https://www.virustotal.com/de/file/b7bd64ddcc323a81ffc9806c613c863132802289e9bc57f62affcce235d996e9/analysis/1398517950/
  • https://www.virustotal.com/de/ip-address/79.124.56.67/information/
HOSTNAME:
http://news1.bowntymailer.com/
  • https://www.virustotal.com/de/url/73c6ee9f15bc9c283a3281fa27d6dc857f8a92ee572d3733bc96ebe6247f05d6/analysis/1398521012/
REDIRECTS TO:
http://79.124.56.67/cgi-sys/defaultwebpage.cgi
  • https://www.virustotal.com/de/url/aec08d798876325028714570d7ccaedfe9ac44e8c7001c4b7734aaa322657d64/analysis/1398519269/
IP 79.124.56.67 IS BLACKLISTED AT:

1)
SPAMHAUS (SBL): SNOWSHOE SPAMMER
  • http://www.spamhaus.org/query/bl?ip=79.124.56.67
  • http://www.spamhaus.org/sbl/query/SBL213606
  • http://www.spamhaus.org/sbl/listings/telehouse.bg
http://telehouse.bg/
  • https://www.virustotal.com/de/url/4a0a98bd45413718c532b3128cfc59a15f8b8ba7bc5195fab8c9042cab9d827b/analysis/
2)
WOT:
  • https://www.mywot.com/en/scorecard/79.124.56.67
3)
spam.abuse.ch:
  • http://dnsbl.abuse.ch/?ipaddress=79.124.56.67
4)
WEB-REP: POOR
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=79.124.56.67

*********************************************************************************************************************

Originating PHISHING-MAIL-IP Address: 79.124.56.70
http://79.124.56.70/
  • https://www.virustotal.com/de/url/94a3d7b252550f754c522cbee1ab45246f8c8ec7d5f69be7165d0f2289ffe12a/analysis/1398519845/
  • https://www.virustotal.com/de/ip-address/79.124.56.70/information/
Invalid HTML data
  • https://www.virustotal.com/de/file/b7bd64ddcc323a81ffc9806c613c863132802289e9bc57f62affcce235d996e9/analysis/1398517950/
  • https://www.virustotal.com/de/ip-address/79.124.56.70/information/
HOSTNAME:
http://news4.bowntymailer.com/
  • https://www.virustotal.com/de/url/07f76972f4be2bd08f85c65791eb977f9ae1eb70c410ca5a74dabe047c66ea2c/analysis/1398520764/
REDIRECTS TO:
http://79.124.56.70/cgi-sys/defaultwebpage.cgi
  • https://www.virustotal.com/de/url/1dff6d9729554c1422fd204c39c3c16d202a9ec6ac2822f2eeabfc6e921a7983/analysis/1398520085/
IP 79.124.56.70 IS BLACKLISTED AT:

1)
SPAMHAUS (SBL): SNOWSHOE SPAMMER
  • http://www.spamhaus.org/query/bl?ip=79.124.56.70
  • http://www.spamhaus.org/sbl/query/SBL213606
  • http://www.spamhaus.org/sbl/listings/telehouse.bg
http://telehouse.bg/
  • https://www.virustotal.com/de/url/4a0a98bd45413718c532b3128cfc59a15f8b8ba7bc5195fab8c9042cab9d827b/analysis/
2)
WOT:
  • https://www.mywot.com/en/scorecard/79.124.56.70
3)
spam.abuse.ch:
  • http://dnsbl.abuse.ch/?ipaddress=79.124.56.70
4)
WEB-REP: POOR
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=79.124.56.70

*********************************************************************************************************************

OTHER LINKS CONNECTED TO THE PHISHING MAIL:

1.0
http://mawamalai.com/link.php
  • https://www.virustotal.com/de/url/7db23e02d8d6153c472dc14a24fb6a995875b1bb2fb271bf57cd42f78a7196ba/analysis/1398514872/
  • https://www.virustotal.com/de/file/23d32b79f3e71e41c2eb3d8811f58f72a2b6b5eb04c0981f16f61ab009945054/analysis/1398434545/
1.1
http://mawamalai.com/open.php
  • https://www.virustotal.com/de/url/dab2df490d9409a591b7b634045eb4699e62a0e15409a21de06efc1b305d456d/analysis/1398514992/
  • https://www.virustotal.com/de/file/dd5bdccb831d1b19c505bd3e67553f6049cea2e20dba7eb231a02ed0103e521f/analysis/1398169420/
1.2
http://mawamalai.com/unsubscribe.php
  • https://www.virustotal.com/de/url/e46fa0421bfd53d4679c0d1fd2005a9b877cce218e9773c9302d4bacaa09cb1b/analysis/1398515065/
  • https://www.virustotal.com/de/file/baefeec3f91b70b39b03c556d29dd1ad4eff87fe7bb0ba91fc3b774e70089281/analysis/1397141557/
2.0 (AS YOU CAN SEE IN THE MAIL-SCREENSHOT)
http://b-unitd.com/9uy
  • https://www.virustotal.com/de/url/5509e6b6e3a8aea57a3d1f566f2823d2cfea8dc636069e390ac91a7de7985732/analysis/1398515235/
REDIRECTS TO:
http://tracker.regaloptions.com/9uy
  • https://www.virustotal.com/de/url/f264470eb6d29a18bd40c6451cf1a21ae7341a3db08bf4a34352c799c9cc7c95/analysis/1398515582/
REDIRECTS TO:
http://www.projekt95pro.com/?campaign=6739&ft=1&p=jsbfaeyJhIjoiMTAwODg4IiwiYyI6IjEzOTg1MTUyNjg2NzU0ODY5MDMifQ==
  • https://www.virustotal.com/de/url/9f7dbb1fb3caa99f8b80908ee4e17c5be0c176938a8953b5f58d66fbaf4c56a7/analysis/


HTML:
  • https://www.virustotal.com/de/file/876dfcc859ab841d81c38c7ae8195570475b176540797ace7223e0b2af998976/analysis/1398515488/

(FROM 2.0) OR TO !:
http://tracker.cedarfinance.com/
  • https://www.virustotal.com/de/url/b74481dafb943ce7417addb8795ca57b616850f4cb3b93950c215203b14f95ca/analysis/1398515998/
REDIRECTS TO:
https://www.cedarfinance.com/?ft=1
  • https://www.virustotal.com/de/url/89eb4f88e14c1c1b12a1ecdba00c72c4b360d70235b10b0db0a18437b79766ad/analysis/1398517210/

OTHER SUSPICIOUS LINK FROM mawamalai:
http://mawamalai.com/admin/includes/js/javascript.js
  • https://www.virustotal.com/de/url/f1d7cbde38ced99e4fc12d0265eeca61a5bdba41fd3aa60a8f04c36dc57b5e6c/analysis/1398516567/
PUA.JS.Xored
  • https://www.virustotal.com/de/file/40ea889122eaed21758c286ac2eb832a1f7263abc47e60f538e8360511c009be/analysis/
  • http://virusscan.jotti.org/de/scanresult/b14d12cc39c2a0ee18b3df555067046fdaa75169

4/24/2014

FRENCH CASINO PHISHING:

"Jeux sur Internet - Prenez Votre B0nus"

positionstatus.com (IP: 68.66.55.34)
Spamhaus Listed (Hamilton, CANADA)


Rien n’est comparable aux B0NUS offerts
par Euroking et en vous joignant a
ses membres vous en recevrez une
multitude.

Ces Primes vous permettront de vous
eclater dans un environnement
fantastique et sur des tables superbes
ainsi que d’en gagner les cagnottes qui
sont, de l’avis de tous, parmi les plus
genereuses du web.

Ne laissez pas passer cette
opportunite de gagner une fortune et
venez vite vous mettre au jeu.

Accédez au site en cliquant là >>>

A tout de suite...


SPAM & PHISHING DOMAIN:
http://positionstatus.com/
  • https://www.virustotal.com/de/url/ebc6a370b83be39f4d86787a6d757c76985d3be66809969090d2649e5c49bd32/analysis/1398322886/
LISTED AT SPAMHAUS:
  • http://www.spamhaus.org/query/domain/positionstatus.com
LISTED AT SURBL:
  • http://www.surbl.org/lists
  • https://www.mywot.com/en/scorecard/positionstatus.com
--------------------------
http://positionstatus.com/link.php
  • https://www.virustotal.com/de/url/f7fe5bafd2152c3bc8ec03a8c332ba4217f6a95796ad0f7607967928f0e9c8fc/analysis/1398322918/
http://positionstatus.com/unsubscribe.php
  • https://www.virustotal.com/de/url/9d19b31ca3fbcad91c6becab677c0ba46f6c94c8d70addba06875d96c4d3302d/analysis/1398322961/

ORIGINATING IP:
http://68.66.55.34/
  • https://www.virustotal.com/de/url/e5e675654f7df2e537064f8f11def3aa257d8ffc9fc59f67eb193890731531a2/analysis/1398322996/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=68.66.55.34
EMAIL-REP: POOR
WEB-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=68.66.55.34

4/16/2014

PHISHING MAIL from:
www.med-equip.com.tn (IP: 193.95.93.62)
HTML:Script-inf

(THAILAND & TUNESIA)
"!Keep It Simple In The Bed retread"
gaecaoro@totbb.net



PHISHING SPAM & MALWARE:
HTML:Script-inf
ROGUE MEDICATIONS (THAILAND & TUNESIA)

DOMAIN:
http://www.med-equip.com.tn/
  • https://www.virustotal.com/de/url/b9fb02cf988d929e6a2c86e2570c607bf20bce182b931092f2afdb72cc30a153/analysis/1397659999/
HTML
  • https://www.virustotal.com/de/file/c6b1a536e10e685f7eb2e7875e1385070f1381d3c7142d6bf35cdd99f464baea/analysis/1397660454/
E-MAIL LINK:
http://www.med-equip.com.tn/geriforte.html
  • https://www.virustotal.com/de/url/403d17cc13d16d4f05fde4699d1fbb319c5aad5af693f5526c82a0d4558455e8/analysis/1397659995/
HTML:Script-inf
  • https://www.virustotal.com/de/file/af51c501f333a7a1c81a7e64f09850d249a22283e6731df4482a58bd9134838d/analysis/1395389479/
SREENSHOT PHISHING MAIL
IP:
http://193.95.93.62/
  • https://www.virustotal.com/de/url/4842c7f2236d8e6fb467f709bf7833ffbd3907a913681c44dddb94a0ce54293b/analysis/1397662127/
  • https://www.virustotal.com/de/ip-address/193.95.93.62/information/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=193.95.93.62
  • http://www.spamhaus.org/sbl/query/SBL204400
WEB-REP: POOR
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=193.95.93.62
www.med-equip.com.tn/geriforte.html REDIRECTS TO:
http://triptabletspharmacy.ru/
  • https://www.virustotal.com/de/url/9a59b27ab7899a59763aed3092d887621a3a55c684227a7471fd05f2803da02d/analysis/1397661510/
IP triptabletspharmacy.ru:
http://107.182.164.141/
  • https://www.virustotal.com/de/url/ed96c08ef5482160f445fcd3665d2e8991ff0ba2a0f74d73c063227b5a59b89d/analysis/1397662386/
  • https://www.virustotal.com/de/ip-address/107.182.164.141/information/
  • http://www.senderbase.org/lookup/?search_string=107.182.164.141
SEE ALSO:
  • http://zulu.zscaler.com/submission/show/b6bc817a43647a0fa89d3e68a44e696b-1397660255
  • http://zulu.zscaler.com/submission/show/8d1a7645f4d5da4e722e8c11b95b4e9c-1397660264
  • https://urlquery.net/report.php?id=1397660035929
MAIL SENT "FROM":
http://totbb.net/
  • https://www.virustotal.com/de/url/dfc051bf8979828be83f9b5b0ffe9d372302dc7d88bb2aa8ebc289437bcd6a23/analysis/1397660871/
IP totbb.net:
http://203.113.9.20/
  • https://www.virustotal.com/de/url/c62bc82dab5ac1d2100e2fc5fc26972ca6bd86d8b55925645540eadeff8279f7/analysis/1397662629/
  • https://www.virustotal.com/de/ip-address/203.113.9.20/information/
ORIGINATING IP ADRESS FROM MAIL:
http://111.84.115.252/
  • https://www.virustotal.com/de/url/9b7ee547d226d4fc171a124b383f6528b8308ad493efb984a6d9a0dd7a637440/analysis/
  • https://www.virustotal.com/de/ip-address/111.84.115.252/information/
LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/query/bl?ip=111.84.115.252
EMAILREP: POOR
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=111.84.115.252

4/04/2014

"La Crise m'a frappe de plein fouet"
FRENCH SPAM of the Moment (March 2nd 2014):
globalmrkt.net (IPs: 14.3.2.2 & 66.111.202.245)
JAPAN & USA
SPAM, SCAM, PHISHING

La Crise m'a frappe de plein fouet, et pourtant cela
m'a rendu Riche tres rapidement.

En 2011, une catastrophe arrive au garage pour lequel
je travaillais. Le patron est tomber malade et nous
n'avons trouve personne pour reprendre cette petite
affaire sans grand interet...

Du coup nous les 5 employes, nous nous sommes retrouves
au chomage sans grand avenir devant nous surtout dans
notre région.

Cela a ete un coup terrible ...

Je n'avais nulle part ou aller, aucune idee de quoi
faire, avec un simple diplome de mecanicien obtenu
en travaillant dans ce meme garage...

Et pourtant, un amis tres aise a decide de me
prendre par la main et de m'expliquer comment
faire fortune avec un PC et une connexion internet.

Rendez-vous est pris chez lui, je n'en reviens pas
du luxe qui l'entoure, voiture, piscine, hifi,
le reve pour toute personne...

On s'installe devant son PC et il me fait voir
comment en quelques minutes il gagne 100€, c'est
tout simplement incroyable je n'en revenais pas.

Presser de rentrer a la maison pour me mettre
au travail j'en oublie presque de le remercier.

Bref fini les blablas...en quelques semaines j'ai
gagne plus d'argent quand 5 annee de travail au
garage c'est stupefiant et dur a croire.

Du coup comme je sais que beaucoup galere avec
cette crise mondiale, j'ai cree une page web
pour vous expliquer en details comment vous
aussi commencer a mettre en place ce systeme.

Pour vous y rendre cliquez simplement ici >>

Je suis content de pouvoir vous aider alors
n'hesitez pas a venir me parler sur MSN
si vous avez besoin de moi...

E-MAIL SCAM SCREENSHOT

MALICIOUS DOMAIN: SPAM, SCAM, PHISHING
http://globalmrkt.net/
  • https://www.virustotal.com/de/url/fc9354101dde316cc480db2faaa4a9cb4d67c1c83b442b437b271d798c3af9c3/analysis/1396623727/
http://globalmrkt.net/link.php
  • https://www.virustotal.com/de/url/f6ba43bb07d8bd0b29bd10e4c38a2ab65f5954d51bf4f297088d918ba2a76872/analysis/1396623762/
http://globalmrkt.net/open.php
  • https://www.virustotal.com/de/url/a0d3800e98aa335b3bd3e39ed0b0bc32fc3f46febeced00ebef054ceab3a4645/analysis/1396623856/
ORIGINATING IPs:
http://14.3.2.2/ (Asahi, JAPAN)
  • https://www.virustotal.com/de/url/452305e81bc2b995dadee0ad7a30c2a4071b6c5ad9d20d0aa7f3b049fa130c9f/analysis/1396623426/
  • http://www.senderbase.org/lookup/?search_string=14.3.2.2
MALICIOUS IP:
http://66.111.202.245/ (Santa Monica, USA)
  • https://www.virustotal.com/de/url/b4b642acac605882a2012b00bd46454690e5bcd475930800b2a21e95d517960e/analysis/1396624250/
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=66.111.202.245
  • http://www.spamhaus.org/sbl/listings/ARIN
Fwd/Rev DNS Match: NO
EMAIL-REP: POOR
WEB-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=66.111.202.245
SEE AS WELL:
  • https://www.mywot.com/en/scorecard/globalmrkt.net
LISTED AT SURBL:
  • http://www.surbl.org/surbl-analysis


3/14/2014

Category MALICIOUS IP: 91.200.13.57 (UKRAINE)
Comment Spammer
Spamhaus Listed SBL190623

Ukranian Flag in Colours


CATEGORY MALICIOUS IP: 91.200.13.57 
(COMMENT SPAMMER, UKRAINE)

IP:
http://91.200.13.57/
  • https://www.virustotal.com/de/url/8dc15e28c1ef4acadca8a839d4ce140fcf76180fef657d7fbc6a1ed65d5d0b36/analysis/1394809243/
  • https://www.virustotal.com/de/ip-address/91.200.13.57/information/

THE IP IS LISTED AT SPAMHAUS (SBL): BOTNET SPAMMER
  • http://www.spamcop.net/w3m?action=checkblock&ip=91.200.13.57

E-MAIL REPUTATION: POOR

WEB REPUTATION: POOR
  • http://www.senderbase.org/lookup/?search_string=91.200.13.57
13.480 Web Post Submissions
  • https://www.projecthoneypot.org/ip_91.200.13.57
http://glubina.com.ua/
  • https://www.virustotal.com/de/url/0307b0678d32d537e08147614d05e160f27ac4f83777bc06c4083fa2997867b1/analysis/1394811245/