Translate

2/13/2014

Just another Spam from: www.ratgeberplatz.com:
„Herzlichen Glückwunsch“ („Congratulations“)
from Germany

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM SCREENSHOT from ratgeberplatz.com...


Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.

Verwandte Artikel:

19066.saeke.com:
MALICIOUS VISITOR OF THE WEEK (A BOTNET) & New Malicious Code
Trojan-Downloader.HTML.IFrame.aip, aiq, air
(CHINA, POLAND & RUSSIA)


MALICIOUS VISITOR OF THE WEEK (A BOTNET)








MALICIOUS (CHINA, POLAND & RUSSIA): Trojan-Downloader.HTML.IFrame.air
Reply Sinkhole - sinkhole.cert.pl 148.81.111.111 (Shadowserver Reported CnC Server IP group 3)
CVE-2008-2463 & CVE-2008-0015
http://19066.saeke.com/
https://www.virustotal.com/de/url/0768ee5a780f2d235f9b17e6789cd62fb2f9f2d08683d0351bd941ce0ea8c968/analysis/1392145114/
Exploit-IFrame.gen.ah
https://www.virustotal.com/de/file/d6c86c0aea173bb04a179812520b77e32b1f6f72b1f1d5f939898f3515cb92a0/analysis/1392205682/
Reply Sinkhole - http://sinkhole.cert.pl (148.81.111.111)
https://urlquery.net/report.php?id=9394745
https://urlquery.net/report.php?id=9394753
https://urlquery.net/report.php?id=9394749
https://urlquery.net/report.php?id=9394736
SCRIPT CODE: http://jsunpack.jeek.org/?report=6597a99bfac1a8733e9db2282b26a50e06efddc8
--->
http://19066.saeke.com/tj.js
https://www.virustotal.com/de/url/da19987591c4bfcceb3ff19582b77057402b4147172dbf9e5c9d2a1b496f8df3/analysis/1392217975/
https://www.virustotal.com/de/file/c17accf46049ffc28b33e8dfb56990ca0b035cc974dfc825952a7d94bc8e130e/analysis/1392217978/
--->
http://count45.51yes.com/click.aspx?id=450998701&logo=12
https://www.virustotal.com/de/url/34f490099e4c9785ddfba9018f2ee803943ad70736004f6bfd67d653ee4e6b26/analysis/1392218499/
https://www.virustotal.com/de/file/a9c13f407dd2befae9e13015941831b1c0a4433381700fd2210da2f4e4858cec/analysis/1392218278/
--->
http://count45.51yes.com/sa.htm?id=450998701
https://www.virustotal.com/de/url/f036a01fd81657fe43ac7724fd8bfef9279c67a13ff3823a763806a6edae7744/analysis/
--->
http://19066.saeke.com/gg.js
https://www.virustotal.com/de/url/be691723ba9286a06b1c95dc1855eb2fbff83c3b61f2774ab0d97fa38afcfe69/analysis/1392217936/
https://www.virustotal.com/de/file/2bde577fdaf14ced5c83ddc3e80c2ce78f5d06657aaf93aaeed628841597d7bf/analysis/1392217940/
--->
----------------------------
1st) http://www.0002555.com/
http://jsunpack.jeek.org/?report=b2b887ac1cc0b97c383d4d77550fa60c762d951b
https://www.virustotal.com/de/url/9f40196ff30f7143de35faba39e57193b52e11899b83e363f549254990f56033/analysis/1392212926/
JS:Decode-AHP [Trj] & JS/Exploit
https://www.virustotal.com/de/file/f2b87dd97c96d86679cc9db8050930e3c80d53fe86ee1f300a9c30ae2197dde7/analysis/1392213008/
JS/Exploit
https://www.virustotal.com/de/url/9f40196ff30f7143de35faba39e57193b52e11899b83e363f549254990f56033/analysis/1392212926/
--->
2nd) http://www.0002555.com/
http://jsunpack.jeek.org/?report=357f1217863b57f4544b34c7c90e26ace423885c
https://www.virustotal.com/de/url/9f40196ff30f7143de35faba39e57193b52e11899b83e363f549254990f56033/analysis/1392219336/
JS:Decode-AHP [Trj]
https://www.virustotal.com/de/file/da097870d62b19b49bd849e42d28536d05dbe4f3dc51f9c72c821d5bae746f4b/analysis/1392219103/
JS/Exploit
https://www.virustotal.com/de/file/37754a8ad7e8976ac0784fb7a6914854bcbcfea04cc4ac18506ba43a53672893/analysis/1392219542/
--->
http://www.0002555.com/?jdfwkey=ltxhx2
https://www.virustotal.com/de/url/e98cc7adf2b66b409f9c3f1a204bf92e07095e113f3507c155604d1a1963f343/analysis/1392220534/
Trojan.Url.IframeB.rrxhg
https://www.virustotal.com/de/file/ec46a7ddc9363450c29f79bec511b6d2910434744fd58b35c86efcda4f925d70/analysis/1392219094/
--->
http://count41.51yes.com/click.aspx?id=418575533&logo=11
https://www.virustotal.com/de/url/3ecfeb8d9385e5ce340628caf9bc5d54be6831df820b41bf5822d2bddf16350e/analysis/1392219731/
Trojan.Url.IframeB.rrxhg
https://www.virustotal.com/de/file/4b15dfa57083bb09ce49282b65290351ad27897ba9170aa00075fde2d7d21d86/analysis/1392219053/
https://www.virustotal.com/de/file/c2878b0fe3502325b658e57346d8c8bd78125a5b3cdfe6023a051724b66a5bf3/analysis/1392219061/
--->
http://count41.51yes.com/sa.htm?id=418575533
https://www.virustotal.com/de/url/29a17f881cb94afee5b57ae6d484a9dedc383b48352516fca1e73c2f06d11e66/analysis/1392220106/
--->
http://count30.51yes.com/click.aspx?id=308228346&logo=2
https://www.virustotal.com/de/url/8a02b1b560f3abf37ca36d1d57464716da3f03e9b56cb37628cd727808889991/analysis/1392220198/
https://www.virustotal.com/de/file/e879df4e1a5d975ca1418d14eb50f35a5330fcaadb4d198ed6a2fb4853b572e1/analysis/
--->
http://count30.51yes.com/sa.htm?id=308228346
https://www.virustotal.com/de/url/ec51f98a5309cc55f56af2ff7c9e9d50a06208b3526da6c5b329301a85e8913c/analysis/1392220375/
--->
http://player.youku.com/player.php/sid/XNjYwNDI1MTI4/v.swf
https://www.virustotal.com/de/url/992fad2fcdcc6b663dfbb25ca14a15a8c02656de0b2a7312fc749bee10ee558e/analysis/
https://www.virustotal.com/de/file/906fe6e47fe95ee6638b1e05195a5b3759a4a68f2967d6646d456b75acb71271/analysis/1392187035/
--->
http://static.youku.com/v1.0.0400/v/swf/loader.swf?VideoIDS=XNjYwNDI1MTI4
https://www.virustotal.com/de/url/357f07d6e7d50783a04222552b115c0e9826fc3c49a3ebe465e94bdc68130dc3/analysis/1392221033/
--->
http://player.youku.com/player.php/sid/XNDI4ODQxOTMy/v.swf
https://www.virustotal.com/de/url/51aac3efbee0778f03b8a6446e4cc3e3be69c8e0a009b1b578be6ac3af5cb4fb/analysis/1392221205/
--->
http://static.youku.com/v1.0.0400/v/swf/loader.swf?VideoIDS=XNDI4ODQxOTMy
https://www.virustotal.com/de/url/8cb172325549ac5a74c8208a58230f6699cd22a83618d53915ab6f47672af44e/analysis/1392221286/
--->
http://player.youku.com/player.php/sid/XNjU4ODk3MzU2/v.swf
https://www.virustotal.com/de/url/8e9692d910802f217669a3d4203d72e9499a25c6e5859394393cb4290872e070/analysis/1392221347/
--->
http://static.youku.com/v1.0.0400/v/swf/loader.swf?VideoIDS=XNjU4ODk3MzU2
https://www.virustotal.com/de/url/5f8a0f3dfb857fb4be2327fa72038115853e40274b309d9d240a724e47f0ad7d/analysis/1392221402/
--->
http://player.youku.com/player.php/sid/XNjY4MjQ4MzE2/v.swf
https://www.virustotal.com/de/url/68fb9fec46f372784f8193172829c26479024d3609687f75912cd77e30186f17/analysis/1392221486/
--->
http://static.youku.com/v1.0.0400/v/swf/loader.swf?VideoIDS=XNjY4MjQ4MzE2
https://www.virustotal.com/de/url/879301b1d169129c1b391d1eb68e411853a5a9ac63592112d8c30b187b07c4bc/analysis/1392221591/
--->
http://player.youku.com/player.php/sid/XNjY2MzQzODg4/v.swf
https://www.virustotal.com/de/url/7a85c31c8dd22d05e9d20297fd343d0b7f94faee7a1017832c2eb88b4c8b8236/analysis/1392221648/
--->
http://static.youku.com/v1.0.0400/v/swf/loader.swf?VideoIDS=XNjY2MzQzODg4
https://www.virustotal.com/de/url/ee1ef43787634c68ddc8b20b90baf8856b45758162fdefd7acf64764bbf40cb3/analysis/1392221724/
---->
CVE-2008-2463
Office Snapshot Viewer    The Microsoft Office Snapshot Viewer ActiveX control allows remote attackers to download arbitrary files to a client machine
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2463
CVE-2008-0015
MsVidCtl Overflow    Overflow in Microsoft Video ActiveX Control via specially-crafted data parameter
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0015
http://www.Brenz.pl/
https://www.virustotal.com/de/url/31ce243b2ef5dd3790be577eeb9d68df7afdda26be2131de243cb06b3d742efc/analysis/1392222143/
https://urlquery.net/report.php?id=9412380
http://www.Brenz.pl/rc/
https://www.virustotal.com/de/url/4df2dbeb23a75f5631c006b880092a8843ffb8451dd2acbec429878b5bc44e8a/analysis/1392221816/
Shadowserver Reported CnC Server IP group 3
https://urlquery.net/report.php?id=9412383
http://wepawet.iseclab.org/view.php?type=js&hash=12962b1916a95d5314edc824efbff88b&t=1270649249
---> FINAL ARRIVE
http://sinkhole.cert.pl/
https://www.virustotal.com/de/url/ef6aa460ada5cc7d5f8dd784ae083eb0f2f3654bfb6559444d2eff704aed4bb6/analysis/1392217250/
https://urlquery.net/report.php?id=9411000
--->
http://148.81.111.111/
https://www.virustotal.com/de/url/986707e69ef388d44bdee6824a6cf10819c16ded7874a3c0d5ea3ad880030489/analysis/1392217321/
https://urlquery.net/report.php?id=9411000
------------------------------------------
SEE ALSO:
http://wepawet.iseclab.org/view.php?hash=2a24c85462e9dc30ca3776286f99886a&t=1392145172&type=js
http://wepawet.iseclab.org/view.php?hash=7382f78798d46535438780e5eb9cabd2&t=1392219910&type=js
http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=19066.saeke.com
http://zulu.zscaler.com/submission/show/40ce5691550607bbeab209159d154ad0-1392145179
http://app.webinspector.com/public/reports/20032993
http://www.urlvoid.com/scan/19066.saeke.com/

THE SAME SCHEME APPLIES AS WELL FOR THE FOLLOWING DOMAIN(S):
1) http://shenxingdubo.wuhou.ru/
https://www.virustotal.com/de/url/4b2a06f4a7e233b1cb50a0700997a697ac1acfe7c2524e0116a55f5777a7a8e2/analysis/1392222909/
Exploit-IFrame.gen.ah
https://www.virustotal.com/de/file/c2e1c253bd05372138c7da63f89152f5408923b2d7fac8147d4b5a10aebd0183/analysis/1392223274/
https://urlquery.net/report.php?id=9412757
http://jsunpack.jeek.org/?report=ac909241b96c177472a11c6d43f84b2ad74ac73a
2) http://bocaitonghaoxiangbo.se966.com/
https://www.virustotal.com/de/url/1d21050badc72f3864b75b0bf68e2856e2af881ba8a7dd9688665cd1571e1de1/analysis/1392223637/
3) http://kaihucaijinyulecheng.qkkyy.com/
https://www.virustotal.com/de/url/aab847e63610663609a5d62188cdf3971c3234b056ac619b97dbddf7ef608d6b/analysis/1392224039/
https://www.virustotal.com/de/file/a392b918860b282a2a1d8848060811228da928fd67ec8c9e487c8001f723fc6e/analysis/1392224103/
https://urlquery.net/report.php?id=9413126
ETC.
* http://aomenpujingyulechang.tpctr.com/
* http://songtiyanjin.cqchildren.cn/
* http://aomenyulecheng.aacpu.com/
* http://xinpujingyulecheng.ddy77.com/
* http://dota2bocaiba.130p.com/
* http://liuhehecaiwangzhi.mm532.com/
* http://zhangxinyouguanfangweibo.qkkyy.com/
* http://yulechengyouhui.sdhutao.com/
* http://wushengdongfangmingzhu.ddy77.com/
* http://bogoubodog.ningxi.net/
* http://dadongfangyulecheng.se966.com/
http://yulechengzaiwangshangzenmezhuce.jobflats.com/
http://007huangjiaduchangqvod.aacpu.com/
http://ribenzuqiubaobeishipin.ddy77.com/
http://guangdongtiyupindaoluxiang.bd84.com/
http://shengshiguoji.aacpu.com/
http://shuangseqiutouzhujiqiao27zhaofa.zhuolingxiu.com/
http://gaokejidubogongju.qkkyy.com/
http://F1wenzizhibo.hf025.com/
FOR MORE SEE & GO ON SCANNING WITH ZULU (ITs SIMPLY A BOTNET) :D:
http://zulu.zscaler.com/submission/show/fdbedf19d7cf1179c64c21c7f109c2df-1392224551
http://zulu.zscaler.com/submission/show/b7c15629a0ef5f92de4fcccf5d94164f-1392224591
http://zulu.zscaler.com/submission/show/80fbe6e5dd86bc2a8fbf68b2aaacc785-1392224731
http://zulu.zscaler.com/submission/show/f3d259b3bdb26c7f3c7f0253a9a6b1f0-1392225180
AND SO ON....

2/11/2014

Action required ! THE DAY WE FIGHT BACK !

On Anniversary of Aaron Swartz's Tragic Passing, Leading Internet Groups and Online Platforms Announce Day of Activism Against NSA Surveillance



Mobilization, dubbed "The Day We Fight Back" to Honor Swartz & Celebrate Anniversary of SOPA Blackout

Washington, DC – A broad coalition of activist groups, companies, and online platforms will hold a worldwide day of activism in opposition to the NSA's mass spying regime on February 11th. Dubbed "The Day We Fight Back", the day of activism was announced on the eve of the anniversary of the tragic passing of activist and technologist Aaron Swartz. The protest is both in his honor and in celebration of the victory over the Stop Online Piracy Act two years ago this month, which he helped spur.

Participants including Access, Demand Progress, the Electronic Frontier Foundation, Fight for the Future, Free Press, BoingBoing, Reddit, Mozilla, ThoughtWorks, and more to come, will join potentially millions of Internet users to pressure lawmakers to end mass surveillance -- of both Americans and the citizens of the whole world.

On January 11, 2013, Aaron Swartz took his own life. Aaron had a brilliant, inquisitive mind that he employed towards the ends of technology, writing, research, art, and so much more. Near the end of his life, his focus was political activism, in support of civil liberties, democracy, and economic justice.

Aaron sparked and helped guide the movement that would eventually defeat the Stop Online Piracy Act in January 2012. That bill would have destroyed the Internet as we know it, by blocking access to sites that allowed for user-generated content -- the very thing that makes the Internet so dynamic.



David Segal, executive director of Demand Progress, which he co-founded with Swartz, said: "Today the greatest threat to a free Internet, and broader free society, is the National Security Agency's mass spying regime. If Aaron were alive he'd be on the front lines, fighting back against these practices that undermine our ability to engage with each other as genuinely free human beings." According to Roy Singham, Chairman of the global technology company ThoughtWorks, where Aaron was working up until the time of his passing:

"Aaron showed us that being a technologist in the 21st century means taking action to prevent technology from being turned against the public interest. The time is now for the global tribe of technologists to rise up together and defeat mass surveillance."

According to Josh Levy of Free Press:

"Since the first revelations last summer, hundreds of thousands of Internet users have come together online and offline to protest the NSA’s unconstitutional surveillance programs. These programs attack our basic rights to connect and communicate in private, and strike at the foundations of democracy itself. Only a broad movement of activists, organizations and companies can convince Washington to restore these rights.”

Brett Solomon, Executive Director, Access, added:

"Aaron thought in systems. He knew that a free and open internet is a critical prerequisite to preserving our free and open societies. His spirit lives in our belief that where there are threats to this freedom, we will rise to overcome them. On February 11th, we'll rise against mass surveillance."

On the day of action, the coalition and the activists it represents make calls and drive emails to lawmakers. Owners of websites will install banners to encourage their visitors to fight back against surveillance, and employees of technology companies will demand that their organizations do the same. Internet users are being asked to develop memes and change their social media avatars to reflect their demands.

Websites and Internet users who want to talk part can visit TheDayWeFightBack.org to sign up for email updates and to register websites to participate. Regular updates will be posted to the site between now and the February 11th day of action.

WHO: Access, Demand Progress, Electronic Frontier Foundation, Fight for the Future, Free Press, The Other 98%, BoingBoing, Mozilla, Reddit, ThoughtWorks -- and many more to come

WHAT: Day of Action in Opposition to Mass Spying, Honoring Aaron Swartz and SOPA Blackout Anniversary

WHEN: February 11, 2014

HOW INTERNET USERS CAN HELP:

  •     Sign up to indicate that you'll participate and receive updates.
  •     Sign up to install widgets on websites encouraging its visitors to fight back  against surveillance. (These are being finalized in coming days.)
  •     Use the social media tools on the site to announce your participation.
  •     Develop memes, tools, websites, and do whatever else you can to participate -- and encourage others to do the same.

NEW MALWARE CODE: Trojan-Downloader.JS.Iframe.dfm
INFECTED DOMAIN castelgiorgio.com
(ITALY - AUSTRALIA - UNITED STATES)


2/10/2014

Potentially MALICIOUS IP-VISITOR TO THIS BLOG:
5.228.175.88 (RUSSIAN FEDERATION)
Listed at SPAMHAUS (PBL)







POTENTIALLY MALICIOUS IP: (RUSSIAN FEDERATION)
5.228.175.88
  • https://www.virustotal.com/de/url/9a5637c8f5e9e879f58b3cfe1543d4e99d2887e934d6c212e93437feac0b22e6/analysis/1392062781/

LISTED AT SPAMHAUS (PBL):
  • http://www.spamhaus.org/query/bl?ip=5.228.175.88

Email Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=5.228.175.88

HOSTNAME:
broadband-5-228-175-88.nationalcablenetworks.ru
  • https://www.virustotal.com/de/url/a8681b9778da0b6e81f869a1a481143702f0d420c80c3263ead51a3127b03a4b/analysis/1392063552/

DOMAIN:
nationalcablenetworks.ru
  • https://www.virustotal.com/de/url/8e8530d88e624479f71553153beb0a55797a2ceb259233b198c47104eb7ce2bd/analysis/1392063734/

NETWORK OWNER:
www.rostelecom.ru
  • https://www.virustotal.com/de/url/a1de2b65a0f6c052d2fab4d62d1bd8dc96fbeec821c1d2e94642c5478d353fc5/analysis/1392064034/
  • http://www.senderbase.org/lookup/org/?search_string=OJSC%20Rostelecom
rostelecom.ru links either directly or indirectly to the following Domains: 
widgets.twimg.com
  • https://www.virustotal.com/de/url/fc8fb130582f32fba6ff856d59a615af1ea1214aeb4283b366d3a1061d5c2a80/analysis/1392064674/
qsoft.ru
  • https://www.virustotal.com/de/url/145246976aef9e4f1975b45cbf76fc0aa77660197d2740949a8e670ddf803d8d/analysis/1392064722/


NEWLY DETECTED:
ricaworld.altervista.org
HEUR:Trojan.Script.Generic (GERMANY)



NEWLY DETECTED MALWARE: HIDDEN IFRAME (HEUR:Trojan.Script.Generic)
ricaworld.altervista.org
  • https://www.virustotal.com/de/url/75c19d584b99aa082712e4ff096bc54f5edc683048b8729344b9f854b2608fe7/analysis/1392036074/

INFECTION:
Trojan.JS.QXJ
  • https://www.virustotal.com/de/file/e42c571c0963b0d0d7a7344f9582c6252bcf12614a6c8e368559502d643d48c0/analysis/1392036385/
--->
ricaworld.altervista.org/Scripts/AC_RunActiveContent.js
  • https://www.virustotal.com/de/url/fb38eb2a93366fdd5276b20f708db788dfcad2f2e6662ff916779246be29b3bf/analysis/1392036955/

INFECTION:
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/b5b1d54315c2a2e9d9486452b6e0b27be42cbe78a31f28d3f49051c30663897a/analysis/1392036765/
  • https://www.virustotal.com/de/file/481cdfa5cb56926629612634970abf7679b43261dc92ad5040eba08a513f82fd/analysis/1392036780/
 


--->
chcipenize.wz.cz/mailcheck.php
  • https://www.virustotal.com/de/url/de21862addb9217bd2c8085868153c321b2fa58ef42248920d2ad2c819cb269e/analysis/1392037277/
  • https://www.virustotal.com/de/file/a406668064e43de3c55fb9293777d8f9651ace466dc1f51bf53fcf9a0402a7d2/analysis/1375077498/
  • https://www.virustotal.com/de/file/ac21eb5fb9ff8ad43bf2826385b0019225ed43bbc3098e6ce65542ce8f9b6e12/analysis/1392037253/
--->
www.iws-leipzig.de/contacts.php
  • https://www.virustotal.com/de/url/d0b7f370689cad91470fe8264879beeca58ae2600215d5b899d084bde6a25559/analysis/1392037470/

NEW:
yansalamandra.ru
HEUR:Trojan.Script.Generic
Russian Federation




NEWLY DETECTED: MALICIOUS IFRAME (RBN 365)
yansalamandra.ru
  • https://www.virustotal.com/de/url/67921025f91c62ba5e76eda2f819051ee0ad0d25d2aa551bdb8b7f215979ce12/analysis/1391972916/

INFECTION: 
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/4d878e5f2db1d468d80a1d15ab6a5bef205b4834e85e5226f8ba9cae406e4b64/analysis/1391974022/
  • https://urlquery.net/report.php?id=9327064
  • http://jsunpack.jeek.org/?report=5c2537adab93e2e9a6fa9108f149dc6d9138b788
--->
advomn.pp.ua
  • https://www.virustotal.com/de/url/93856bf13af0b2df401a4080f6b72274156db06cc73e05499e0d3cffe0cf7e86/analysis/1391975226/
  • https://urlquery.net/report.php?id=9327399
advomn.pp.ua/38c190227eaddbe1e920ad1a993701980a6d4d8e516d3011c2fc023a042b7d4b171a7f801a278e4630354f01a9232a6a3a2ec980002e92716c9ce0dc480c29447345c6dee2d30344b6b
  • https://www.virustotal.com/de/url/df4bd15c09f7e998375234b0ec08a26dce90f07c9cd2da9dde32f54ca1336bb2/analysis/1391975200/
--->
changeip.changeip.name/rsize.js
  • https://www.virustotal.com/de/url/41c106f4f24956e8e6d031bc20861b77b7b9674f8ad231ef4e51fff8892e90a3/analysis/1391974447/
  • https://urlquery.net/report.php?id=9327265
  • https://urlquery.net/report.php?id=9327273
------------------------------------------

OTHER MALICIOUS LINK:

yansalamandra.ru/administrator/help/en-GB/chinchin.js
  • https://www.virustotal.com/de/url/286c044eac09bac2fe39efa3e21ab1e60bbee92349e1499c02e7efe4e02d7eec/analysis/1391975320/

INFECTION:
Troj/JSRedir-MN
  • https://www.virustotal.com/de/file/c3755028d1adf4d41fd5d0ffd1bdabffc9a093be438025b491fca6901c74cc06/analysis/1391975322/
  • http://jsunpack.jeek.org/?report=009476f8e2cc5e8c96b8a51b339bcd41b26c9851

2/08/2014

ILLINOIS Online Child Predators 2011:
“funson999” aka Michael Wayne Bailey
sentenced to 97 Months in Prison

US District Attorney S.R. Wiggington
On March 12th, 2012, Michael Wayne Bailey, 35, of Granite City, Illinois, was sentenced to a total of 97 months imprisonment charging him with possession of child pornography (count one) and receipt of child pornography (count two), the United States Attorney for the Southern District of Illinois, Stephen R. Wigginton, announced. The sentence consists of 97 months’ imprisonment on counts one and two, to run concurrently.

Michael Wayne Bailey
Bailey was also ordered to serve 20 years’ of supervised release on counts one and two, to run concurrently; fined 300 USD on each count, for a total fine of 600 USD; and ordered to pay an additional 200 USD special assessment. Bailey pled guilty to the two-count indictment on September 23rd, 2011 and has been detained since his arraignment on July 26th, 2011.

The violation referenced in count one of the indictment occurred on March 17th, 2011, when officers were executing a state search warrant and seized eight PCs with numerous other media devices from the residence which Bailey shared with other individuals. While profiling the data on the computers, officers located a screen name, “funson999,” which contained numerous chats, discussing the molestation of children and trading images of minors. Officers were able to track the funson999 account to Michael Bailey.


Bailey then admitted creating the funson999 account, stating that he would save images of minors engaged in sexually explicit conduct to his hard drive and then delete them. Bailey also stated he received approximately 10 images of minors engaged in sexually explicit conduct via the Web. Additionally he also admitted engaging in the chats recovered from his computer. Finally, Bailey stated that he deleted e-mails and other information associated to the funson999 account after the initial search warrant was executed.

The violation referenced in count two of the indictment occurred on October 2, 2009, when Bailey downloaded an image of a minor engaged in sexually explicit conduct. The case was investigated by the Madison County Sheriff’s Department and the Federal Bureau of Investigation’s Metro East Cyber Crimes and Analysis Task Force. The case itself was assigned to Assistant United States Attorney Angela Scott.

MALICIOUS VISITOR TO THIS BLOG: www.bema.it INFECTED: Trojan-Downloader.JS.Iframe.czo & HEUR:Trojan.Script.Generic (ITALY)



MALICIOUS SITE: EXPLOIT BLACKHOLE (MALICIOUS INJECTION) Trojan-Downloader.JS.Iframe.czo



DOMAIN:
www.bema.it
  • https://www.virustotal.com/de/url/9c313118270d7060f6a88b8d02315e60f6fa366d1e640d01b0154f43f721ab7c/analysis/1391876292/
HTML
  • https://www.virustotal.com/de/file/c48575a72b511e9fc0a7e9e601b33507d08296eadb6efebb18655dc1177de4c1/analysis/

SPECIFIC MALWARE (VISITING) LINK: 
www.bema.it/paesaggigeologici.htm
  • https://www.virustotal.com/de/url/1a3e767c25cb71944b44bf81943c6d839273fdec1f176966f963d0875215e959/analysis/1391876591/

INFECTION:  
Trojan-Downloader.JS.Iframe.czo
  • https://www.virustotal.com/de/file/483e183fedd9db8a7fd74fd979c235c2d0565933534898c55abbfa3e7801b5e7/analysis/1391875774/
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/0e3b1abbec7f3d81910ab10ba644d5ba64a1075db3b9a85a7833642913871582/analysis/1391875789/
  • http://jsunpack.jeek.org/?report=8ace5573ffdaf77d5ed6faf5dd6aface337b0387
  • http://wepawet.iseclab.org/view.php?hash=a4bbe339803250d0b1a917575df82c92&t=1391875552&type=js
  • https://urlquery.net/report.php?id=9316907

---> REMOTE
miamiheattickets.com/http.php
  • https://www.virustotal.com/de/url/0bbe620806942d74fb1ede783f53c0f29151485340a3687deec3bdb8689900d8/analysis/1391877039/
--->
www.bema.it/bema_internet.css
  • https://www.virustotal.com/de/url/28a06f8a729f620fc4fb8c3b3aa47c3f2a66b5b9e7fba3578075c5f187218d58/analysis/1391877125/
  • https://www.virustotal.com/de/file/805730a9867637233a0e88034a7160ceebb1232bec363db7d057455dc4e8243c/analysis/1352190357/


OTHER MALWARE LINKS FROM THIS DOMAIN:
1) www.bema.it/opere/pg_1.htm
  • https://www.virustotal.com/de/url/52200c7f623b60c44c2256c70bc3041a0f7efbf825c1e0067565fd8dfd3dfd37/analysis/1391877987/
INFECTION: 
HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/a4e9035cacdfbfcb1b28cfb2ebedccc0901dbc4c82173a388648d43a7d82b88f/analysis/1391877891/
--->
moreclosings.com
  • https://www.virustotal.com/de/url/cb65fb78eb9f34870ab0c33b3fd7b48e9163f72d6d9b29ee9320e97dcb6d69f4/analysis/1391878110/
moreclosings.com/showthread.php?sid=193854
  • https://www.virustotal.com/de/url/97d8c820291908356fa32a0b17c1d0eb4bc54e40e4ef64c9a2e72dfd8469a30b/analysis/
  • https://urlquery.net/report.php?id=9317125
2) www.bema.it/artigrafiche.htm
  • https://www.virustotal.com/de/url/d2fba275794bdef2a814e05cf08b9439daa40293e332fa100bde91327b470231/analysis/1391878663/
INFECTION:  
Trojan-Downloader.JS.Iframe.czo
  • https://www.virustotal.com/de/file/3fa71c9f13947e2c60e52843932f59dddcc8e2d424a6f106717f5632e4533dcd/analysis/1391878603/
  • https://urlquery.net/report.php?id=9317122
3) www.bema.it/impianti.htm
  • https://www.virustotal.com/de/url/17a7d8f57f4c1f929637dea43d3cf7332442a484bb2f89ecca2afb9bf4a9dd1c/analysis/
INFECTION:  
Trojan-Downloader.JS.Iframe.czo
  • https://www.virustotal.com/de/file/fc694a8433ca74015e3badf6ecd4d00b18f93ddfaa30121a21b6405658a97928/analysis/1391878854/
  • https://urlquery.net/report.php?id=9317119


Category MALICIOUS IP: 217.74.66.183 (komsta.biz)
Infected with a spam or malware forwarding link - Botnet
(POLAND) Also: mecsohesti.strefa.pl & berlokava.strefa.pl


The IP address 217.74.66.183 (listed in the CBL (Composite Blocking List)) corresponds to a web site that is infected with a spam or malware forwarding link. The website's host name is "komsta.biz", and this link is an example of the redirect: "http://komsta.biz/xmlrpc/r1.php". In other words the website "komsta.biz" has been hacked. Usually, the redirect takes the user's browser to a spam or malware site. It's usually fake russian pills or pornography.




Most probably, the infection is a Cpanel, Plesk, Joomla or Wordpress CMS install, that has become infected either through a vulnerability (meaning the CMS software is out of date and needs patching), or the owner of "komsta.biz" has had their account information (userids/passwords) compromised. Then malicious software/files are being uploaded by ftp or ssl.

In many cases, particularly with older compromises, the criminals that hacked this site will have uploaded a wide variety of spamming and other compromise tools. Therefore, the account corresponding to "komsta.biz" needs to be examined very carefully for signs of tampering. Further, the criminals will even modify existing web pages (particularly http://komsta.biz itself) to have hidden references to pill/drug/porn sites.

It is believed that the malicious redirects are done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors.


REFERENCES:
217.74.66.183
  • https://www.virustotal.com/de/url/0a6cbec1348cf0d336786144d8ac8b3392a06044ea45210c1ff7164b935138d3/analysis/1391867416/
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=217.74.66.183
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=217.74.66.183 
----------------------------------------------------------
komsta.biz
  • https://www.virustotal.com/de/url/d075ee0a046bf5b9061d6516f74a2a8a896f6d645b500b82b8e5621cdd347af3/analysis/1391868630/
komsta.biz/xmlrpc/r1.php
  • https://www.virustotal.com/de/url/13fe2e198d34cfb1180de459f3cdc711cd35315653a442f5ea4cfae49d771803/analysis/ 
---------------------------------------------------------

Other Malicious Domains connected to this IP:
mecsohesti.strefa.pl
  • https://www.virustotal.com/de/url/7b8461c8134626cc15ae094d9ae3c6fa82c82a417cc6936693dbaac78829481e/analysis/1391866196/
mecsohesti.strefa.pl/908juare3rm.js
  • https://www.virustotal.com/de/url/e953124d50e1310dd2812e263931848b00d462470c676a634e4cb399cfa6b92a/analysis/1391866188/
  • https://www.virustotal.com/de/file/b16b4bdb5699e781801c38303ff0843681d622683b1edfaefe7d9255da7cdc36/analysis/1391865764/
  • http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=mecsohesti.strefa.pl
---------------------------------------------------------
berlokava.strefa.pl
  • https://www.virustotal.com/de/url/3ade4568cc4b8450928f22fdc2ef3961f253073f5854b1cecc26274ddce8afc6/analysis/1391865399/

INFECTED WITH: HTML:Script-inf
  • https://www.virustotal.com/de/file/1b9c71d4ede9b1b74f6a228fd391b1532e2dbe90c78ef3bbb77effbebac9693c/analysis/1391865730/
  • http://wepawet.iseclab.org/view.php?hash=f54d99392772ab74cc133e0920e5a658&t=1391865424&type=js
  • http://zulu.zscaler.com/submission/show/4f05692eb30713ac8402cef9ce93cb06-1391865434


SPAM:
"Pures Verwöhnprogramm" emv-info.hotelreservierung.de
(FRANCE)




MALICIOUS DOMAIN: SPAM & PHISHING SCAM (FRANCE)

ORIGINATING IP ADRESS:
2.1.14.110
  • https://www.virustotal.com/de/url/5daa82f054d1922a3ee933df19c8e85c6798db2f94bd03335d629588349fe817/analysis/1391807477/
LISTED AT SPAMHAUS:
  • http://www.spamhaus.org/query/bl?ip=2.1.14.110
Email Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=2.1.14.110

emv-info.hotelreservierung.de
  • https://www.virustotal.com/de/url/68cf71f26c2b4e5ef62d3fc27600ed4dc7c1086101b89194092ae84a3fd93340/analysis/1391806480/
  • http://www.UnmaskParasites.com/security-report/?page=www.hotelreservierung.de

CONNECTED SPAM DOMAINS:
ads.unister-gmbh.de
  • https://www.virustotal.com/de/url/f046bd900cae54568f25063533aeddb8f685ce58b24066f37357fba10e1a2e23/analysis/1391806371/
  • https://www.mywot.com/en/scorecard/ads.unister-gmbh.de
crm.hotelreservierung.de
  • https://www.virustotal.com/de/url/e82ecd62ab91a3b4792554b117d55deaabc5820d89bdfc8aef7dcf3a4a87aeb7/analysis/1391806614/
www.ab-in-den-urlaub.de
  • https://www.virustotal.com/de/url/a368e6a05fd18af9554b616f32e8fab1797d8baab9f67c2585b6f9d72f3ff254/analysis/1391806780/

2/07/2014

MALWARE:
Trojan-Downloader.JS.Agent.gtu & HEUR:Trojan.Script.Generic
INFECTED SITE(s):
bretthersley.com & pvhetiozstg.findhere.org


MALICIOUS URL(s): 
(Trojan-Downloader.JS.Agent.gtu) 
MAL. Iframe Injection 
(RBN 275) 
Likely leading to EXPLOIT KIT



DOMAIN:
bretthersley.com
  • https://www.virustotal.com/de/url/385d06231a7226fa3998b97e62c5c10195485b57556cd52f3d3a0f4874e602d5/analysis/1391776537/

SPECIFIC LINK:
bretthersley.com/wp-content/themes/01_Super_Slick_VCard_-_Wordpress_Version/images/loader.gif
  • https://www.virustotal.com/de/url/225a220dd922c4e73a01ec0f40f5d9686c4d5960f28295dd720abce0cbffce41/analysis/1391775974/

FORMERLY:
Trojan-Downloader.JS.Agent.gtu
  • https://www.virustotal.com/de/file/3851fd1f908ad8e7a2c8f3b8fd7a5e73182fa8d99761903a743c12db24d90028/analysis/1375177800/

NOW:
Trojan-Downloader.JS.Agent.gtu
  • https://www.virustotal.com/de/file/7fb2f58d2fcc4d48f596e23c122441e8bc0f62cfda923868f1fe1731fe06d8dc/analysis/1391776994/

ALSO: HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/828d91af1ebe3f81d909b1e836629bd73d759f72804b3094ecf8a4a690888b00/analysis/1391777096/

REFERENCE:
  • http://jsunpack.jeek.org/?report=21aee5b48f214c4f99c87831e7d0ef38bcf6a694
Detected a Dynamic DNS URL
Detected malicious iframe injection
Detected a TDS URL pattern
  • https://urlquery.net/report.php?id=9276908
---> REMOTE
pvhetiozstg.findhere.org/vc.php?go=2
  • https://www.virustotal.com/de/url/026e9c1d6e32a50a62b715d7f58a057a1e3c68e3df6af13882c745ce2944a6d3/analysis/1391777504/
  • https://www.virustotal.com/de/file/214c3b683099a23da1e8ea88093f2c0ce6234f55f36943f810e031628cb7c93e/analysis/1369498120/
Detected a Dynamic DNS URL
Detected a TDS URL pattern
  • https://urlquery.net/report.php?id=9277385
--------------------------

ALSO:

WORDPRESS VERSION OUTDATED: RISK BEING VULNERABLE

2/06/2014

aromavietnam.com
Malicious Domain Infected with:
HEUR:Trojan.Script.Generic & Trojan.JS.Iframe.aeq
(EXPLOIT from VIETNAM)


MALWARE: EXPLOIT


DOMAIN:
aromavietnam.com
  • https://www.virustotal.com/de/url/ec13cdcd880da204742fbbb17ebb754f78fa9e9916c5d900393e779c09d017bf/analysis/1391695139/

Infected with: HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/000ab3f5794c646ded51dd9b66d10749834dce17193ee9da1c28520fd23c52c1/analysis/1391697040/

EXPLOIT-KIT embedded iframe redirection - possible exploit kit indicator
  • https://urlquery.net/report.php?id=9256862
  • https://urlquery.net/report.php?id=9258051
  • https://urlquery.net/report.php?id=9258064

--->
173.237.187.203/post.php?id=704732
  • https://www.virustotal.com/de/url/aa23c1e60447fa417c7bf7cd25fdf3257e0b354fb1a37a143b8334b7bd96c1f5/analysis/1391698495/
  • https://urlquery.net/report.php?id=9258108

OTHER MALICIOUS LINK(s):
aromavietnam.com/stmenu.js
  • https://www.virustotal.com/de/url/e30a7f2e0271567938041e58cbccb2b2273e217c83110083ec79c4b747bef41c/analysis/1391694780/

Infected with: Trojan.JS.Iframe.aeq
  • https://www.virustotal.com/de/file/864d33b798d3c718263cb7ed78bea4a007133af53c704f45a54f0ca5e832aaa0/analysis/1391695003/

--->
37.59.120.98/704732.js
  • https://www.virustotal.com/de/url/eef9a6a86ae865da21b27b35623e5756f3569ceacb11a0a0fc444de13c413c0c/analysis/1391696634/
REF.: http://jsunpack.jeek.org/?report=05a453d8b0c4094c355d0f93ec02fe7f9619f4a2


arifizgidizayn.com (MALICIOUS DOMAIN)
Infected with: HEUR:Trojan.Script.Generic
(EXPLOIT KIT, TURKEY)



MALICIOUS DOMAIN: EXPLOIT (KIT)

arifizgidizayn.com
  • https://www.virustotal.com/de/url/6d6c58ba2c1ccebe07cdae728992b6ecb9ada7c603b89df47fc4fda6dd80a703/analysis/1391683685/

SPECIFIC LINK:

arifizgidizayn.com/swfnoborder.js
  • https://www.virustotal.com/de/url/0505699678769fee5f460fc5d4d1eb04c24ad093d348504cfd2dd82860e595a4/analysis/1391683043/


https://www.virustotal.com/de/file/24a0434d89dfd70c0b84e3caa8adb9231512568bf2caf24d2bb9a6d7404952bb/analysis/1391683046/


Malware Network Compromised Redirect
  • https://urlquery.net/report.php?id=9252311
  • http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=arifizgidizayn.com
---> PATH


DOMAIN:
habibtour.com.au
  • https://www.virustotal.com/de/url/1ab36c262cf6533186fbe3a53be55e00d781a106bbffce7bea5fdbff8feab24a/analysis/1391683497/

SPECIFIC REDIRECTION LINK(s) (SUSPENDED):
habibtour.com.au/language/t.php
  • https://www.virustotal.com/de/url/7506f10411b494a3fdd3e39a6485ff45534f0ea20342a400ffdf22ae4c6238e8/analysis/1391683482/
  • https://www.virustotal.com/de/file/07f99e34de6b4f4707f502d1cfcf2957b330c5ff713cf377d1eb82b85f975539/analysis/1391414551/
habibtour.com.au/cgi-sys/suspendedpage.cgi
  • https://www.virustotal.com/de/url/be266fdc5e1bb28d85a41c7de7af5c0fce9c078aa3bcab1d83530e56c0fe52ca/analysis/1391683618/

2/05/2014

Snowshoe Spammers - MALICIOUS DOMAIN & IP:
b2bdigitalapps.com & 193.180.115.48
"Les 5 astuces pour faire encore mieux l'amour"
(PHISHING-SCAM, AUSTRIA, SWEDEN)


Bonjour,

Tu trouves que tes relations sexuelles deviennent monotones ? Tu n'est
pas seul. Comme toi, je me suis rendu compte que ma femme et moi, on ne
faisait plus l'amour aussi souvent qu'avant.  Et quand ça nous arrive,
c'est toujours les mêmes vieilles recettes.

En fait, j'avais perdu l'enthousiasme et, ça m'ennuie de le dire, il
m'est même arrivé d'éviter de faire l'amour plusieurs fois. Ce n'était
plus comme avant et je savais qu'il fallait faire quelque chose avant
que ca n'aille trop loin.

Alors je suis allé sur le net pour trouver des idées et j'ai trouvé un
livre qui s'appelle  “500 Astuces Amoureuses” En fait, c'est drôle.
Pendant que je lisais le livre, ma femme est venue voir ce que je
faisais. Quand elle a su de quoi il s'agissait elle m'a viré de
l'ordinateur pour lire elle-même.

Alors finalement, il a marché, ce livre ?

Je te laisse juger : la nuit même, elle a apporté des fraises et du
coulis de chocolat à grignoter devant la télé (évidemment inspiré du
livre).

Ca m'a complètement surpris. Je n'aurais jamais pensé qu'une chose
simple comme manger des fruits et du chocolat pendant les préliminaires
pouvait être aussi excitant.

Je n'irai pas dans les “détails” de la suite … :D… mais je dois dire que
je suis devenu fan de ce livre !
Et notre sexualité est extraordinaire maintenant. Nous ne sommes jamais à
court d'idées pour rendre les choses excitantes. Et si on a besoin
d'une idée, il nous suffit d'ouvrir le livre. C'est top !

Si tu penses que ta sexualité est devenue un peu ordinaire, ou si tu veux
simplement l'améliorer un peu, regardes ce livre

en cliquant ici>>

A bientôt

MALICIOUS PHISHING-SCAM DOMAIN: (SNOWSHOE SPAMMERS)
b2bdigitalapps.com
  • https://www.virustotal.com/de/url/c7c6daf58332d34d90b1234b1bdd40c922f4a3bed5174f9b2d561bff8d66a706/analysis/1391621955/
b2bdigitalapps.com/link.php
  • https://www.virustotal.com/de/url/7e06bfb6d9730edbbacc4189f36681e84aaa585dd580e2e53543c4aa10d14d0e/analysis/
  • https://www.virustotal.com/de/file/22fc373d3b3ab36009613adfd7bb60f7135a4f510aa31808856e721dd5799d0c/analysis/
b2bdigitalapps.com/open.php
  • https://www.virustotal.com/de/url/21e996363e94694017a766295f26702b7d6fe9c605a57d30965b3c6be6f9027a/analysis/1391622030/
  • https://www.virustotal.com/de/file/dd5bdccb831d1b19c505bd3e67553f6049cea2e20dba7eb231a02ed0103e521f/analysis/1390580473/
b2bdigitalapps.com/unsubscribe.php
  • https://www.virustotal.com/de/url/c7f6d051298f7b524bcf37fa3bc9ac2cab53cfff8081d9cf78d2f095f85e8e19/analysis/1391622053/
  • https://www.virustotal.com/de/file/fb18ec2dc45858efd8a69d17873eb1a92801a4af8e6b6a44b03e9e7a69d11ffd/analysis/


Snowshoe Spam (Screenshot)

ORIGIN IP:
193.180.115.48
  • https://www.virustotal.com/de/url/9c8a9262baa8df9d848573706b4bcf2eeb9c8d23404f1951accff6b123ff9e64/analysis/1391620870/
  • https://www.virustotal.com/de/file/18f256b9f1807fe04ee416b47643bae7ed150f37cf79e24c4e2b9646cf3cf908/analysis/1391622765/
 
LISTED AT SPAMHAUS (SBL):
  • http://www.spamhaus.org/query/bl?ip=193.180.115.48
 
Email Reputation: Poor
Web Reputation: Poor
  • http://www.senderbase.org/lookup/?search_string=193.180.115.48