Translate

Posts mit dem Label Tornevall Listed werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Tornevall Listed werden angezeigt. Alle Posts anzeigen

5/27/2014

POTENTIALLY DAMAGING IP: 198.50.178.90
COMMENT SPAMMER & MORE
Montréal, CANADA




POTENTIALLY DAMAGING IP:
http://198.50.178.90/
  • https://www.virustotal.com/de/url/49af94681d256ad8f31faa479b1a97d576e162c723c0f894e11a7fac21042a4d/analysis/1401210067/
XML
  • https://www.virustotal.com/de/file/0a43cb9ab42a7a08ac796fc0f90cb28bdf063a8f1a84096754950f46db83cdbe/analysis/1401210229/
COMMENT SPAMMER:
  • https://www.projecthoneypot.org/ip_198.50.178.90
LISTED AT TORNEVALL:
  • http://dnsbl.tornevall.org/
Heartbleed OpenSSL Result: Vulnerable
  • http://zulu.zscaler.com/submission/show/974aa036407238e24522b1aa10d27646-1401210072
BESIDES THAT: OUTDATED APACHE SERVER SOFTWARE: VULNERABLE
  • http://httpd.apache.org/security/vulnerabilities_24.html
-------->
DOMAIN:
http://exe.moneyrobot.com/
  • https://www.virustotal.com/de/url/13158ea50cdf2e66bce90bd6845f2a496012338f90047900bf21e11cf29de56e/analysis/1401210907/
PUA MoneyRobot.exe (The digital signature of the object did not verify)
  • https://www.virustotal.com/de/file/c974e9923097b2bec307212a12b0165c263f03b3156bd7f735d5c628edb57611/analysis/
  • https://www.virustotal.com/de/file/4a5e038bc0bbd3e1e0ba7d4489eda42df6a6b4237aff1c489b4d6d2c760c5367/analysis/
  • https://www.virustotal.com/de/file/75976b46e7a286d49e9ac74a1f6090c95226495c655ac83d601b2f79a6cfe52e/analysis/
http://exe.moneyrobot.com/Data/bcdc096817213b207777e843e90e7767
  • https://www.virustotal.com/de/url/8e8a714041ac640b848c6157bfff80edc9b8f5366d34982efe15104ca2f63aba/analysis/1401210501/
BESIDES THAT: OUTDATED APACHE SERVER SOFTWARE: VULNERABLE
  • http://httpd.apache.org/security/vulnerabilities_24.html
IP:
http://67.205.81.45/
  • https://www.virustotal.com/de/url/ec13ba31f3a882856e43d75c7a15dc972e227201d8947815b532c5aa54c0ab5f/analysis/1401211771/
  • https://www.virustotal.com/de/file/752c03b6b7c5b46c8b2e2a0715b9847a3d9be43b1b1d5ba1484ef88d729d0464/analysis/1401211825/
  • https://www.virustotal.com/de/ip-address/67.205.81.45/information/
  • http://zulu.zscaler.com/submission/show/e729c788a7cca9552811c1ea8b13c430-1401212249
BESIDES THAT: OUTDATED APACHE SERVER SOFTWARE: VULNERABLE
  • http://httpd.apache.org/security/vulnerabilities_24.html
SPAM SERVER, BAD WEB HOST (18):
  • https://www.projecthoneypot.org/ip_67.205.81.45

5/14/2014

Category MALICIOUS IP: 74.91.17.228
Comment Spammer & RULE BREAKER
(LISTED AT TornevallNET)
Kansas City, MISSOURI, United States

MALICIOUS IP: COMMENT SPAMMER & RULE BREAKER
http://74.91.17.228/ (Kansas City, MISSOURI)
  • https://www.virustotal.com/de/url/fbcd5088b580dd9c07b2de9601c20618756c1e90c68bc42f974d0e3747a11f5f/analysis/1400100618/

LISTED AT TornevallNET
  • http://dnsbl.tornevall.org/
  • http://www.ipvoid.com/scan/74.91.17.228/
Form Posts: 2771

RULE BREAKS: 3 web page navigation rules broken by this IP
  • https://www.projecthoneypot.org/ip_74.91.17.228
Network Owner:
http://www.datashack.net/
  • https://www.virustotal.com/de/url/613dddb1e1ba69a8a8808dafe1b1e237bf5b5ca6d56c04260eb7279e12b35c09/analysis/
IP DATAShack:
http://108.162.203.173/
  • https://www.virustotal.com/de/url/bfa1f2179b4602f74892918accbb1fdd6147a1046e98f1a7554cbd49be015485/analysis/1400102035/

4/28/2014

186.94.81.128
Category MALICIOUS IP
Palos Grandes, VENEZUELA
Spamhaus listed (PBL)



IP:
http://186.94.81.128/
  • https://www.virustotal.com/de/url/347ec8b05932a64cc5e39ad8df105c962ea48fa2bb24660cff0570b815c3b04b/analysis/1398683475/
LISTED AT SPAMHAUS (PBL 915113):
  • http://www.spamhaus.org/query/bl?ip=186.94.81.128
  • http://www.spamhaus.org/pbl/query/PBL915113
LISTED AT TONEVALL:
  • http://dnsbl.tornevall.org  
See as well:
  • http://www.stopforumspam.com/ipcheck/186.94.81.128
E-MAIL REP: POOR
  • http://www.senderbase.org/lookup/?search_string=186.94.81.128 


4/14/2014

CATEGORY MALICIOUS IP:
118.249.108.152 = COMMENT SPAMMER

from Changsha, CHINA


CATEGORY MALICIOUS IP FROM 
Changsha, CHINA:

COMMENT SPAMMER - LISTED AT SPAMHAUS (PBL)
FOUND ON A CnC BOTSERVER (EXPLOIT) ROUNDUP LIST
http://118.249.108.152/
  • https://www.virustotal.com/de/url/6ed60ee1803bdf1832b1b82f44411076a2b118bcafcda2e48d4610d2a9baf2e8/analysis/1397506802/
PBL SPAMHAUS LISTED:
  • http://www.spamhaus.org/query/bl?ip=118.249.108.152

LISTED AT Tornevall:
  • http://www.ipvoid.com/scan/118.249.108.152/
EMAIL-REP: POOR
  • http://www.senderbase.org/lookup/?search_string=118.249.108.152
ROUNDUP:
  • https://www.projecthoneypot.org/ip_118.249.108.152

4/08/2014

Category MALICIOUS IP:
5.135.188.193 (kimsufi.com)

COMMENT SPAMMER from (Roubaix, FRANCE)



CATEGORY MALICIOUS IP: 
COMMENT SPAMMER
LISTED AT TORNEVALL

FOUND ON EXPLOIT KIT STATISTIC ROUNDUP:
Host - Pages - Hits - Bandwidth - Last visit date - [Start date of last visit] - [Last page of last visit] 5.135.188.193 - 16 - 16 - 5839847 20140115134221


HOST:
http://5.135.188.193/  (Roubaix, FRANCE)
  • https://www.virustotal.com/de/url/ad6cf5b5cc0ac88abe48f641f12ebb0bad4d7bf1d40e15af5f0383471eede4de/analysis/1396905319/
HOSTNAME: (Registered February 15th 2001)
http://ks3294570.kimsufi.com/
  • https://www.virustotal.com/de/url/9e0bfb2602bc25eb416989ffd0cb78bb0e35108f06b6dd5fe4acc5604718cf3e/analysis/1396907424/

WEPAWET: NON-EXISTING DOMAIN
  • http://wepawet.iseclab.org/view.php?hash=fb0cdf5e77cfec395b4db8bf802df86d&t=1396905343&type=js

DOMAIN: (IP: CANADA)
http://kimsufi.com/
  • https://www.virustotal.com/de/url/b2957ee6fe072c26c66415b45c22062fa9319dcd11a935ccc6808ddf8d88c4f1/analysis/
IP: 213.186.33.80  (FRANCE)
  • https://www.virustotal.com/de/url/bf71c3ee663f088661ee99420e310491c614b03b26557c771d040669e9cfe8e8/analysis/
  • https://www.virustotal.com/de/ip-address/213.186.33.80/information/
  • http://toolbar.netcraft.com/site_report?url=213.186.33.80
REDIRECTS TO:
http://www.kimsufi.com/
  • https://www.virustotal.com/de/url/70a198d280f8e42e13903be64df4dbebf292ed8f3ff5d58360ee0af9f1ea9ae3/analysis/1396908942/
IP (CHANGE): 198.27.92.3  (Montréal, CANADA)
  • https://www.virustotal.com/de/url/9e2487ef003597430ea9b8bf016675f1fb4501d516ab468212099b57ad707c87/analysis/1396909634/
REDIRECTS TO:
http://www.kimsufi.com/fr/index.xml
  • https://www.virustotal.com/de/url/69f5933404d7b76ef3e0d002add1516e622d015ddacf4cfeda5803f73673424d/analysis/1396909006/
REDIRECTS TO:
http://www.kimsufi.com/fr/
  • https://www.virustotal.com/de/url/30f30cae7dc114a98734d84bf5eb806a0932e6767c17e05b5f767ef4a5e3cbb3/analysis/1396909110/
  • https://www.virustotal.com/de/file/11114b722dd11cc71086f1d47fcb36ca7b2b5fce27413ecb8d3da00a70fc336d/analysis/1396909603/
  • https://www.virustotal.com/de/url/9e2487ef003597430ea9b8bf016675f1fb4501d516ab468212099b57ad707c87/analysis/1396909634/
--------------------------------------------------------------------------------------------------------------------------------------------
LISTED AT TORNEVALL:
  • http://dnsbl.tornevall.org/  (http://www.ipvoid.com/scan/5.135.188.193)

User-Agents: 30
Web post submissions: 52
  • https://www.projecthoneypot.org/ip_5.135.188.193

Netcraft Risk Rating: 9/10
  • http://toolbar.netcraft.com/site_report?url=5.135.188.193
ALSO:
  • http://www.stopforumspam.com/ipcheck/5.135.188.193