Translate

4/01/2014

PHISHING from www.heavenjav.com (IP: 89.248.168.164)
Netherlands
PUA.Phishing.Bank


HeavenJAV Screenshot

Phishing SITE:
DOMAIN:
http://www.heavenjav.com/
  • https://www.virustotal.com/de/url/7ba4abf24940faa50c30bdea1e3788d98f79c5d38bbaf6a60934ec10951f8c02/analysis/1396342103/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/e0862f4de5204feea0c3d8e365db0082d9b66743873bd1622248b392dfdc63ef/analysis/1396342533/
  • http://virusscan.jotti.org/de/scanresult/0882e3fab80e1c4561884fb123e103298c89153a
http://www.heavenjav.com/2013/02/24/front-magazine-uk-no-178-2013/
  • https://www.virustotal.com/de/url/07f6c70e33553e5b4da02f94af3c4b3ecca2003cf1610505e437a106ae85cbf9/analysis/1396342096/
PUA.Phishing.Bank
  • https://www.virustotal.com/de/file/90d8f789b5499a6d10b89b31cb75ed7474481e20996e125c676da78b8d599c9c/analysis/1396342153/
  • http://virusscan.jotti.org/de/scanresult/d8067f7e7a665777aeaeb064eb3fb32664db9e1a
http://89.248.168.164/
  • https://www.virustotal.com/de/url/3b8ce797c88762fece7858c4024261fb686117e4c6d68a9f0ef3d0f154a9ac71/analysis/1396350748/

Real Comment Number 3 on COMMENT SPAM (with Malicious Link) !

ANONYMOUS WROTE:
"Whɑt's up, after reading this awesome paragraph..."
KEY COMMENT: "Stop by my website..."

scp.uma.pt/images/....... Portugal, Poland, Germany

This Post is (and will be & stay) to demonstrate what SPAM IN BLOGS (Comment SPAM) IS about and how you should difference it ! From this part it is surveilled, and followed. IP-Data and Domains who are involved are being recorded, to monitor the frequency and analyzing the connections given to it. In case suspicious Connections (related to Phishing, Spambots (what they already are), and other fraudulent activities and/or behaviour) will (not only) be recorded and transfered to the appropriate agencies (i.e. IC3) what however is done anyway. Special observations from outside can be adressed to me through IC3. 

Reminder: However, every SPAM-Post is delivered to the appropriate Adress. Keep following.
-------------------------------------------------------------------------------------------------------------------------------------------

NUMBER 3:

Whɑt's up, after reading this awesome paragraph i am as well happy to share my experience here with mates. Stop by my website http://scp.uma.pt/images/1.php/what-is-biaxin-used-to-treat-ogqd.php
SPAM COMMENT MADE ON FOLLOWING POST:

http://stayaway2.blogspot.com/2014/01/category-malicious-domain_13.html
 
SCREENSHOT OF ANONYMUS COMMENT SPAMMER
 
 
MW URL: PHISHING - ROGUE MEDS - TDS SUTRA
http://scp.uma.pt/images/1.php/what-is-biaxin-used-to-treat-ogqd.php
  • https://www.virustotal.com/de/url/b4ddfb4f5d1d6de3d7ac09bc3f9b86cf1e1152c431989be9ba128ebadcc902ed/analysis/1396334546/
TDS Sutra - redirect received
TDS Sutra - request in.cgi
  • https://urlquery.net/report.php?id=1396334666046
--->
http://getmarketschoice.com/in.cgi?12&parameter=what+is+biaxin+used+to+treat
  • https://www.virustotal.com/de/url/15b9552bdaaef5306203130d8ec521adc2ec02836e244a6c288660a77af1de9f/analysis/1396334968/
TDS Sutra - redirect received
  • https://urlquery.net/report.php?id=1396335061174
---->
http://okpillsbest.com/catalog/Antibiotics/Biaxin.htm
  • https://www.virustotal.com/de/url/817a3dad94af46f7e84cf077bf34f54888b21bf8df5e2b7aa8c58a00dc3437e4/analysis/
  • https://urlquery.net/report.php?id=1396335569086
IPs:
http://193.136.232.84/
  • https://www.virustotal.com/de/url/6e4f5bd49883788be5d2d08199a76341d1b5a44a5e1054a20bbb2999170950aa/analysis/1396335823/
http://91.230.205.65/
  • https://www.virustotal.com/de/url/cd4912b45256be4f214fd289ed20c225c7d68e236e44c78895ffe3fb862f847d/analysis/1396335909/
  • https://www.virustotal.com/de/ip-address/91.230.205.65/information/
http://176.9.192.16/
  • https://www.virustotal.com/de/url/4c8e99a657d39784c9bd79d726db6b96677fbb9e575d28bc2eb704caa08c7257/analysis/1396336061/
  • https://www.virustotal.com/de/ip-address/176.9.192.16/information/
  • http://95.169.190.160/
  • https://www.virustotal.com/de/url/00dfaf1d27128c8f8f00b91a82a1f3a259e51042b504b784c7fa970efaaa2424/analysis/1396336268/
  • https://www.virustotal.com/de/ip-address/95.169.190.160/information/
Spider Sightings: 14
  • https://www.projecthoneypot.org/ip_95.169.190.160

SCAM OF THE DAY from:
"WIR BIETEN DARLEHEN" ("We Offer Credits")
With Greetings from Coquitlam (CANADA), Australia &...& ratgeberplatz.com

IHR SEID IN ALLE FINANZNÖTE ODER BENÖTIGEN SIE MITTEL ZU STARTEN IHR EIGENES GESCHÄFT? BRAUCHEN SIE DARLEHEN FÜR IHRE SCHULD ZU BEGLEICHEN ODER ZAHLEN SIE IHRE RECHNUNGEN?
Wir geben Kredite im Bereich von 7000 US-Dollar (sieben Tausend Dollar) bis zu 50.000.000 US-Dollar (50 Millionen Dollar) mit 3 % Zinssatz.



Füllen Sie das nachstehende Formular (ist kein Formular, nur Text im Mail) für die Anwendung von Darlehen durch:



Persönliche e-Mail-Adresse:

Name: Adresse:

Land:

Telefonnummer:

Menge, die benötigt werden:

Darlehen-Dauer:

Monatliches Einkommen:

Alter:

Geschlecht:



Sie sind Beratung senden Ihre Daten an diese e-Mail-Adresse ein: scoth_smitt@ymail.com



Alles Gute
Herr Rev Scoth Smitt (Blöder gehts wohl nicht!)
Screenshot of HOCHwürden.....

MALICIOUS: HIDDEN IfRAMES ALL OVER THE PLACE & INVOLVED IN PHISHING SCAM
http://sd43.bc.ca/
  • https://www.virustotal.com/de/url/8290fd493074a03e4b9c2e28e27d880175519bba5ec36b12f16aae864214fe44/analysis/1396302819/
http://sd43.bc.ca/Pages/default.aspx
  • https://www.virustotal.com/de/url/3430aa5e2fcb1a7be76346576a55c9179acb649e9ab39d83843e692dbf2eca0e/analysis/1396302945/
HTML: 
W32.HfsIframe.420f (WHATEVER IT MEANS REFERS TO A HIDDEN IFRAME)
  • https://www.virustotal.com/de/file/701247cb9f12329ce5558b3ceff20ab16a4f4880606b86cfe7fe474480f7299b/analysis/1396302682/
ORIGINATING IP(s) (ratgeberplatz.com again involved): Coquitlam (CANADA)
http://142.35.6.131/
  • https://www.virustotal.com/de/url/0878044af1696c27903ac4978f8113c96b1222f5461fbc8f2e9db3191934f1f1/analysis/1396304403/
http://14.2.27.4/   (Adelaide, Australia)
  • https://www.virustotal.com/de/url/3bdc4ddd451c4313001e49b924ff7ff7022ee6cec34bf8ec7b614487b5de2bf8/analysis/1396304621/

3/31/2014

St. Louis & San Diego:
Jonathan Cowden sentenced to 15 Months Prison on Hacking Charges

A man formerly from St. Louis now living in San Diego was behind the series of online attacks against an Israeli organization.

Jonathan Cowden, 27, used hacking tools to attack Nefesh B’Nefesh, an Israeli organization that assists immigrants to that country, between November 2011 and January 17th, 2012 . Cowden stole data, damaged computers and boasted about his exploits on Twitter as “_AnonymouSTL_” and elsewhere.


Cowden was indicted on January 9th 2012 on a charge of accessing a protected computer without authorization, but the indictment was sealed until Cowden’s arrest January 18th 2012 in San Diego, where he moved to in the summer of 2011. There he pleaded not guilty in the U.S. District Court in San Diego.

In court documents, Cowden told court officials that he earns 4.000 USD a month working for a company that advertises its ability to keep companies’ online data safe. In at least one online profile, he billed himself as a “White Hat” hacker, someone who helps organizations identify security vulnerabilities.

According to a cyber attack timeline on Hackmageddon.com, the Nefesh incident was part of a series of attacks against Israeli targets. The total cost of the breach was estimated at 180.000 USDollar, and Nefesh had 594 names, addresses and encrypted passwords stolen, the site notes.

On March 27th 2014 Jonathan Cowden was sentenced to 15 months of imprisonment resulting from his conviction for hacking a website associated with an Israeli-based business. Cowden was also ordered to pay restitution to the victims of his hacking crimes.

NEW MEXICO:

Albuquerque Police Website HACKED by ANONYMOUS seems to come
as "revenge" to a recent Albuquerque Police Shooting
that left a homeless man dead

The Albuquerque police website is back online after authorities say a cyberattack took it down for hours.

APD Website: http://www.cabq.gov/police/

The department has not been reached for comment on Sunday evening, but announced earlier in the day that the site was breached. It was visible late Sunday afternoon after going down in the early afternoon. Police spokesman Simon Drobik said that the Server downtime was due to a cyberattac.



The attack comes days after a YouTube video emerged threatening retaliation for a recent police shooting that left a homeless man dead. The video that bore the logo of the computer hacking collective Anonymous warned of a cyberattack on city websites and called for a protest march.

Hundreds of protesters were marching Sunday to protest recent police shootings.

SEE THE VIDEO HERE:



A department spokesperson said the attack happened around 11 oclock Sunday morning. As part of the attack, the personal information of high-ranking police officials was released.

On Twitter, a group called "Anonymous" took credit for crashing the site. The group released a video last week that said APD murdered James Boyd in cold blood.

The group tweeted the home addresses of several police officials.

APD said Sunday's cyber threat has not affected public safety communications, so response services are OK. The police department's Facebook and Twitter accounts are also down. APD disabled them in anticipation of a cyber-attack.

Anonymous is also taking credit for crashing the city of Albuquerque's website. A city spokesperson said the website was down for about five minutes.

Source: AP

3/30/2014

FACEBOOK PHISHING & HACKING:
pirateruncomptefacebookfrance.blogspot.com

What safely could be translated into: "HowtoHijack(Pirate)aFaceBookAccount(in)France.blogspot.com


MALICIOUS BLOGSPOT: 
PHISHING FOR FB DATA (HOW TO HIJACK (HACK) A FB ACCOUNT ETC.
http://pirateruncomptefacebookfrance.blogspot.com/
  • https://www.virustotal.com/de/url/586b5098f327ff98a61c8a2a6a0aab975a50d1df315230588de967d26d30a3ad/analysis/
THIS (FOLLOWING) LINK IS PROVIDED ON THE PAGE (TRY FOR FREE)
http://goo.gl/dKwO8n
  • https://www.virustotal.com/de/url/299ad80bc881f312479170902dadea87917189d04df4e4fb91c8cce28767fa6d/analysis/1396211990/
  • http://sitecheck3.sucuri.net/results/goo.gl/dkwo8n
  • http://www.phishtank.com/phish_detail.php?phish_id=2332672
---> REDIRECTS TO:
http://cheatlord.net/facebookcheat/
  • https://www.virustotal.com/de/url/2874549c53c37bb47427b4888d4003ef56a9eb9769d551381638e37a6dd799ff/analysis/
  • http://wepawet.iseclab.org/view.php?hash=31faf50ec251a7f34f1a65abfeff7658&t=1396211280&type=js

FACEBOOK PHISHING & HACKING:

hackeruncomptefacebook.com
piraterfacebookcompte.com
advertising-pl.com


WITH Greetings from Tulsa, Oklahoma



MALICIOUS DOMAIN(s): FACEBOOK CREDENTIALS PHISHING & HACKING
http://hackeruncomptefacebook.com/
  • https://www.virustotal.com/de/url/cfac8fa2254451995f4d2a6f8de40c8f02436f81228d9b4b8b31ea88ae073e2e/analysis/1396201707/
SEE RESULTS FROM LAST YEAR:
  • http://wepawet.iseclab.org/view.php?hash=68dc48fe9f199d1c877a5445079dd407&t=1382978731&type=js
  • http://wepawet.iseclab.org/view.php?type=js&hash=12d7e2d3b011064d4fd4c5bb016e131c&t=1380889976
IP(s):
http://108.174.194.226/    (TULSA, OKLAHOMA)
  • https://www.virustotal.com/de/url/ca9613975145454f057431a2b9c3116aedfc9a4a97e013b6f95804db13897c02/analysis/1396204128/
  • https://www.virustotal.com/de/ip-address/108.174.194.226/information/
MailRep: POOR
  • http://www.senderbase.org/lookup/?search_string=108.174.194.226
FOR THE FULL REPORT SEE .txt ICON:

Document hosting: UploadEdit.com

Real Comment Number 2 on COMMENT SPAM !

ANONYMOUS WROTE:
"It's really a great and useful piece of information."
KEY COMMENT: "Here is my blog post: pirater un compte Facebook"


My Site: www.facebook-recherche.com

This Post is (and will be & stay) to demonstrate what SPAM IN BLOGS (Comment SPAM) IS about and how you should difference it ! From this part it is surveilled, and followed. IP-Data and Domains who are involved are being recorded, to monitor the frequency and analyzing the connections given to it. In case suspicious Connections (related to Phishing, Spambots (what they already are), and other fraudulent activities and/or behaviour) will (not only) be recorded and transfered to the appropriate agencies (i.e. IC3) what however is done anyway. Special observations from outside can be adressed to me through IC3. 

Reminder: However, every SPAM-Post is delivered to the appropriate Adress. Keep following.
-------------------------------------------------------------------------------------------------------------------------------------------

NUMBER 2:
It's really a great and useful piece of information. I'm glad that you simply shared this helpful information with us. Please keep us up to date like this. Thank you for sharing. Here is my blog post pirater un compte Facebook www.facebook-recherche.com
SPAM COMMENT MADE ON FOLLOWING POST:

http://stayaway2.blogspot.com/2014/01/international-online-child-predators.html

SCREENSHOT OF ANONYMUS COMMENT SPAMMER




PHISHING & MALICIOUS DOMAIN: FACEBOOK ACCOUNT HIJACK (HACK) & PHISHING FOR FB CREDENTIALS AS WELL A BLOG COMMENT SPAMMER (LISTED AT SPAMHAUS)
http://www.facebook-recherche.com/
  • https://www.virustotal.com/de/url/86eba7512f57e84d6864a943230e74e9767a568755dd2240690ddba9572a1910/analysis/1396193684/
HTML
  • https://www.virustotal.com/de/file/4d92a05b9a4c097d28c09784947fd4af204e1238b13df695bc477f5f74666e67/analysis/
LISTED AT SPAMHAUS (DBL):
  • http://www.spamhaus.org/query/domain/facebook-recherche.com
-------------------------
IP: NETHERLANDS
http://37.46.125.166/
  • https://www.virustotal.com/de/url/a9a0fd6a7a201e4675d3179bd408efbf0f602f492c649f450d92fb56c1d140cf/analysis/1396195483/
  • https://www.virustotal.com/de/ip-address/37.46.125.166/information/

A Reminder of Delawares ONLINE CHILD PREDATORS:

David Osborn, 40, from New Castle, Delaware
James Powell, 49, of Bridgeville, Delaware

THE POWELL CASE:
James Powell, 49, of Bridgeville, Delaware, was sentenced on October 1st, 2013, to 10 years in prison on federal charges of traveling interstate to engage in illicit sexual conduct with a minor and possession of child pornography.


Judge Reggie B. Walton
Powell pled guilty to the charges in April 2013 in the U.S. District Court for the District of Columbia. He was sentenced by the Honorable Reggie B. Walton. Powell was convicted in Prince George’s County, Maryland in 1997 of third-degree sexual abuse in a case that involved a child and was therefore subject to a 10-year mandatory minimum sentence. Following completion of his prison term, Powell will be placed on 20 years of supervised release. He also will be required to register as a sex offender for 25 years after his prison term.

According to the government’s evidence, on September 10th, 2012, Powell contacted an undercover officer with the FBI’s Child Exploitation Task Force, who had entered a social network site frequented by individuals with a sexual interest in children. Over the next few days, Powell engaged in online e-mail, instant message, and text message conversations with the undercover officer, whom Powell believed was the father of an underaged girl. During this period of time, Powell arranged with the undercover officer to meet for the purpose of engaging in sexual acts with the child. During the course of their communications, Powell also sent the undercover officers two images of child pornography.

On September 12th, 2012, Powell traveled from Delaware to a prearranged meeting place in Washington, D.C. When he arrived at the meeting place, he was arrested. He has been in custody ever since. (Well done, off the streets)
THE OSBORN CASE
David Osborn, 40, pleaded guilty before U.S. District Judge Richard G. Andrews in the District of Delaware.

Judge Richard G. Andrews
According to statements made at the hearing and documents filed in court, Osborn was identified by the FBI through reports of child pornography trafficking provided by AOL LLC to the National Center for Missing and Exploited Children (NCMEC). Under federal law, Internet service providers, such as AOL, are required to report suspected child pornography being transmitted over their servers to NCMEC, which then directs these “cybertips” to the appropriate law enforcement agency. AOL reported that a particular online username, later linked to Osborn, had been used to trade images of child pornography with another computer user in South Florida.



On May 26th, 2011, federal agents executed a search warrant at Osborn’s New Castle residence and arrested Osborn after finding more than 700 images of child pornography on his computer equipment. Law enforcement agents also searched Osborn’s e-mail account, which was found to contain numerous images of child pornography. Osborn’s child pornography collection included images of girls, ranging from prepubescence to mid-teenage, engaged in various sexual acts or posing lasciviously. Forensic data found on the equipment indicated that Osborn had been receiving and distributing images of child pornography for a number of years. Also found on Osborn’s computer equipment were more than 500 Internet chat logs between Osborn and others regarding child sexual exploitation.

According to information provided at court hearings, in the past, Osborn worked as a school bus driver, substitute teacher, and with the Newport, Delaware chapter of Job’s Daughters, a youth organization for girls.

At sentencing, Osborn faces a mandatory minimum sentence of five years in prison and a maximum sentence of 20 years in prison. Osborn also faces a term of supervised release following his prison sentence of five years to life, and will be required to register as a sex offender in any jurisdiction in which he lives, works, or attends school. Osborn has been detained since his May 26th, 2011 arrest. 

INTERNATIONAL Online Child Predator(s):
Greek Citizen Georgios Sgouros, 43
and 5 other (U.S. Citizens) from Colorado
sentenced between 78 and 120 months in PRISON

Greek Man Sentenced for Traveling in Interstate Commerce with Intent to Engage in Illicit Sexual Act with Minor

Georgios Sgouros, 43, of Athens, Greece, was sentenced in March 2012 by Chief U.S. District Court Judge Wiley Y. Daniel to 10 years in federal prison for traveling with the intent to engage in illicit sexual conduct. Following his prison sentence, Chief Judge Daniel ordered Sgouros to serve 10 years on supervised release, although the defendant is a citizen and national of Greece and therefore will likely before face deportation.

Sgouros was charged by criminal complaint on June 16th, 2010. He was indicted by a federal grand jury in Denver on July 12th, 2010. He pled guilty to travel with the intent to engage in sexual conduct charge on December 1st, 2011.

According to court documents, on January 28th, 2010, a United States Immigration and Customs Enforcement (ICE) special agent posed in an undercover sting Operation as a single Mom with two girls, age 5 respectively 7.

While in an undercover capacity, the Agent engaged in an Internet chat with Sgouros, who expressed interest in traveling to Colorado in having sex with the two childrengirls. During the chats, Sgouros and the undercover agent also discussed the logistics of where he would stay during his visit, and how they would meet up at the International airport in Denver.

During the next several months, Sgouros and the undercover agent exchanged e-mails as well as private chats on the Internet regarding Sgouros’ intention to engage in sexual activity with the children.

On June 13th and 14th, 2010, the man, IDd as Georgios Sgouros, e-mailed the undercover agent his travel itinerary from Athens, Greece to Denver. As on June 15th, 2010, Sgouros was admitted into the United States by U.S. Customs and Border Protection (CBP) at Philadelphia International Airport. He arrived in the U.S. aboard a flight from Amsterdam. He then flew from Philadelphia to Denver, where he was met by ICE special agents and taken into custody.

Other Project Safe Childhood Sentencings
Michael Bilotta

Michael Bilotta of Garfield County, Colorado, was sentenced by U.S. District Court Judge John L. Kane to serve 100 months in federal prison, followed by a life term of supervised release for possession of child pornography. On three separate occasions, the defendant was discovered sharing hundreds of gigabytes online, which constituted tens of thousands of images and videos of child pornography, including images of children as you as 10 years old. In total, Bilotta possessed over 100.000 images of child pornography.

Sean Scott

Sean Scott of Pueblo, Colorado, was sentenced by U.S. District Court Judge John L. Kane to serve 120 months in federal prison, followed by a life term of supervised release for possession of child pornography. On two separate occasions, the defendant possessed hundreds of images and videos of child pornography. He shared his collection of over 185 videos of child pornography online, and some of the videos depicted the sounds of the children’s abuse.

Daniel Petura

Daniel Petura of Arapahoe County, Colorado, was sentenced by U.S. District Court Judge Philip A. Brimmer to serve 78 months in federal prison, followed by 10 years of supervised release, for possession of child pornography. The defendant bought a subscription to a website that provided child pornography and accessed the website approximately 4.000 times. Petura was found in possession of over 1.500 images of child pornography, some depicting infants, and some of which he had obtained from the subscription website.

Stephen Mark Erway

Stephen Mark Erway of Denver, Colorado, was sentenced to 120 months in federal prison by Senior U.S. District Court Judge Lewis T. Babcock for violating the terms of his probation for possession of child pornography. Erway was convicted in 1988 with crimes related to the sexual exploitation of minors, including child pornography. He served a prison sentence and was released on probation. While on probation, he violated the terms of his probation by improperly using computers and by engaging in online relationships with minors.

James Matthew Allen

James Matthew Allen of Denver, Colorado, was sentenced by U.S. District Court Judge William J. Martinez to serve 120 months in federal prison, followed by 12 years of supervised release, for possession of child pornography. Allen was a registered sex offender at the time he was discovered trading images of child pornography online. He was found in possession of just under 150 images of child pornography.

Real Comment Number 1 on COMMENT SPAM !
Michael Burning: "My homepage :: Mike Burns......
KEY COMMENT: "is a enormous source of facts"

This Post is (and will be & stay) to demonstrate what SPAM IN BLOGS (Comment SPAM) IS about and how you should difference it ! From this part it is surveilled, and followed. IP-Data and Domains who are involved are being recorded, to monitor the frequency and analyzing the connections given to it. In case suspicious Connections (related to Phishing, Spambots (what they already are), and other fraudulent activities and/or behaviour) will (not only) be recorded and transfered to the appropriate agencies (i.e. IC3) what however is done anyway. Special observations from outside can be adressed to me through IC3. 

Reminder: However, every SPAM-Post is delivered to the appropriate Adress. Keep following.
-------------------------------------------------------------------------------------------------------------------------------------------

STARTER IS (Number One):

Hi there, its pleasant article concerning media print, we all be familiar with media is a enormous source of facts.

My homepage :: Mike Burns
SPAM COMMENT MADE ON FOLLOWING POST:

http://stayaway2.blogspot.com/2013/12/malicious-site-romhcorguk-blackhat-seo.html

Screenshot Michael Burning

PERSONAL OPINION BEHALF MYSIDE:
Is Michael Burning with Cola ? Or with a Cool Aid ?


Malicious Blogspotvisitor snapchatpasswordgenerator.blogspot.com

(To this Blog, and probably to many others who
highlight the Snapchat Data-breach a while ago):

PHISHING FOR MOBILE PHONE NUMBERS
Pretending you will win some IPhone, or some other Malware Crap...




PHISHING BLOG: THE bit.ly LINK HAS BEEN FOUND ON THE FOLLOWING BLOGSPOT:
MALICIOUS COMMENT SPAMMER: (SPAMMED MY OWN BLOG)


COMMENT WAS GIVEN ON THIS POST:
stayaway2.blogspot.com/2014/01/hacked-skype-and-snapchat-compromised.html
http://snapchatpasswordgenerator.blogspot.com/
  • https://www.virustotal.com/de/url/d99d7a09c4fdd8b2bf19eae284261183d0884644de04b4e28dfc35a661cceca0/analysis/1396125921/

SUSPICIOUS ActiveX behaviour:
  • http://wepawet.iseclab.org/view.php?hash=a9a04c5facd1c77a6a57444abdb478d2&t=1396123149&type=js

THE OWNER OF THIS BLOG IS (should be) Saad Hashmi (SOUNDS LIKE HASH ME) AND HAS VIDs CALLED: How to Hack Twitter ETC. WHERE SEVERAL VIDs HAVE BEEN REMOVED OR NEVER EXISTED:
https://plus.google.com/101817228413013975367/posts
  • https://www.virustotal.com/de/url/1315983a69f47b3e7a91c6d4dc1148f7eb8ebd773ac7846caf907cd711affbed/analysis/1396127927/

PHISHING FOR MOBILE NUMBERS (SUPPOSING TO WIN SOMETHING) BEFORE DOWNLOADING (DOMAIN):
http://bit.ly/1h4aQgx
  • https://www.virustotal.com/de/url/775bedbd10540c804cd6045beaad4728754a8a35c3a673d9d4df0afaddfe1179/analysis/1396128854/

AT PHISH TANK:
  • http://sitecheck3.sucuri.net/results/bit.ly/1h4aqgx
  • http://www.phishtank.com/phish_detail.php?phish_id=2348877

REDIRECTS TO: --->
http://cleanfiles.net/?stj2nPC
  • https://www.virustotal.com/de/url/025997ab9b0805abdd4d83e9997a54085e2dfbc5ebc39893b1e5c76d27d87916/analysis/1396129645/
  • https://www.virustotal.com/de/file/ef8567646f6f7b246704a8550da770a2beb5f628b154bca2b89bc733a756c1a2/analysis/1396128932/

REDIRECTS TO: --->
http://jlyse.net/?stj2nPC
  • https://www.virustotal.com/de/url/a9e5e6fd72161667774a27f2ecaca3cd16d65a473ac4af8553ea41dea4dac749/analysis/1396129771/

---->
http://cleanfiles.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/4d26dd55eb21671c4b451ba271d1a4264d27c783e8bbda93608f8cdaf11c3a7c/analysis/1396129874/
FILE:
  • https://www.virustotal.com/de/file/bafc06f1e99e8ceb57dda20a1f97bc1ca1b347890d3ea8d057e6592306a896cb/analysis/1396130019/

----->
http://jlyse.net/includes/public/log_visitor.php
  • https://www.virustotal.com/de/url/18a2a109263c3ba20011e59974ef4bd5e49b44d7aeb0f4e7745dc7bb65106550/analysis/1396130315/

------>
http://jlyse.net/includes/offers/bootstrapWindow.php?file=143026
  • https://www.virustotal.com/de/url/38c9384d1eef60edb4173b22cd71a98361e104fa2ca2e71d2b942fc93506884c/analysis/1396130553/

------->
http://jlyse.net/js/jquery-1.7.2.min.js
  • https://www.virustotal.com/de/url/e340b2c1a3e48ff193de46aaf0a5e60ebf3632fce7bd315f9b446d861c4429c0/analysis/1396130639/
  • https://www.virustotal.com/de/file/7cc16f897286710dfbb1e44ff8793113990ec3c9cac4df8aebefd95c7e11f35c/analysis/1394224032/

-------->
http://jlyse.net/bootstrap/assets/css/bootstrap.css
  • https://www.virustotal.com/de/url/6fd04f3ba5075a1dc73400b5f604307f4d3a613c76492870004ca216c64d6645/analysis/1396130730/
  • https://www.virustotal.com/de/file/03db46511bdaf1e131c2c9954c7b0cbd8f3c593aa4498b7f89ac3067511a5d60/analysis/1374039732/

--------->
http://cleanfiles.net/js/dwn8.js?v=17
  • https://www.virustotal.com/de/url/74ea97392f9c77ac88c303e9be63a528c9c36d26a3ba5baa7d3b5623c548b6f3/analysis/1396130811/
FILE:
  • https://www.virustotal.com/de/file/ff8b96ace5c518b297cb290bc797b9e26e794cd8d5cc2fdd05ed422eaa0e0a50/analysis/1396131053/

---------->
http://js-agent.newrelic.com/nr-361.min.js
  • https://www.virustotal.com/de/url/c593c58403de499701b64c2af0823e7f7d119ea39bb921ae6819c07057c52a88/analysis/1396131852/
  • https://www.virustotal.com/de/file/fce342d034fb770700ba7ac8421e05cd19d08bdc06ee0636f30fcdb3cd5db5fd/analysis/1396131856/

http://wepawet.iseclab.org/view.php?hash=d6973fc5d3786821ffb747ac7e431874&t=1396128982&type=js

3/29/2014

Just another Spam, from...
www.ratgeberplatz.com:
„Ihre Bewerbung. Ihr Gehalt: bis zu 300 Euro täglich!
(Da müsste ich doch längst Millionär sein bei all diesen Bewerbungen...)“
(„Your application for employment“)

from Australia & Germany (IP: 14.2.24.1)

English:


www.ratgeberplatz.com is a Spamdomain. Just delete those mails. Do not click "unsuscribe Newsletter". If you do so, they only will register that you have read the Mail, and Spamming will become worse ! See Screenshot.

Related Posts:

Just another SPAM-Screenshot from....ratgeberplatz.com

Guten Tag,
Sie wurden ausgewählt! Wir stellen Ihnen jetzt exklusiv Wissen zur Verfügung für Ihren neuen Nebenjob. Ihr Gehalt: bis zu 300 Euro täglich!

Nach Ihrer kostenlosen Anmeldung erhalten Sie sofort gratis Wissen und können starten.

Hier klicken:
http://mailings.ratgeberplatz.com/tracker.php

Für Deutschsprachige Leser:


www.ratgeberplatz.com ist eine eindeutige Spamdomain. Diese Mails sollte man getrost löschen. Bloss nicht auf "Newsletter abbestellen" klicken. Das einzige was anschliessend geschieht, ist dass sie von dieser Domain noch mehr Spam geschickt bekommen, da sie sich durch ihren Klick preisgegeben haben, und die Domain ratgeberplatz.com nun weiss, dass sie die E-Mail gelesen haben! Siehe Screenshot.


IN THIS CASE THE ORIGINATING IP ADRESS IS:
14.2.24.1   (Australia)
  • https://www.virustotal.com/de/url/6671096f3f434b58d889520e044498210faf3944dae80d8a5a084fd47ee0e3a6/analysis/1396003406/
  • http://www.senderbase.org/senderbase_queries/detailip?search_string=14.02.24.01
Second IP:
83.136.83.241   (Germany)
  • https://www.virustotal.com/de/url/248549c14fcab8bb31ebba0e20bc506f52d4070c0eb6fe42fbb7a48ab258dca9/analysis/1396118848/
THAT IS ALSO THE REASON WHY THIS POST (DOMAIN www.ereatvipgame.la) IS CONNECTED TO ratgeberplatz.com, as they use the same SPAM Server:

http://stayaway2.blogspot.com/2014/03/phishing-spam-from-wwwereatvipgamela-in.html

DIES IST DER GRUND WIESO ratgeberplatz.com mit involviert ist im folgenden POST (Casino-Phishing www.ereatvipgame.la) da sie beide die gleiche SPAMSERVER-IP-Adresse nutzen:

http://stayaway2.blogspot.com/2014/03/phishing-spam-from-wwwereatvipgamela-in.html

RECENTLY (RE-)DETECTED:
afristyle.com infected with HEUR:Trojan.Script.Iframer
IP: 160.124.112.100 - SOUTH AFRICA



MALWARE: HEUR:Trojan.Script.Iframer
DOMAIN:
http://afristyle.com/
  • https://www.virustotal.com/de/url/94e4f0d5dec56125cc4ac81ecd1aea5438e8ee9191f9a1ddee5729b370a5ee3f/analysis/1396113676/
HEUR:Trojan.Script.Iframer (PUA, document write)
  • https://www.virustotal.com/de/file/61b5f2266af649aeb40b3c12cb9b437da4c9b09492cff6aaf2fe4c33f46401e0/analysis/1396113489/
IP:
http://160.124.112.100/
  • https://www.virustotal.com/de/url/34dfd6f154e8f0f124b31235af491ff951386a432cf009980d5abed411171b24/analysis/1396114396/
  • https://www.virustotal.com/de/ip-address/160.124.112.100/information/
--->
http://find.uk.to/dns.htm
  • https://www.virustotal.com/de/url/9882d00fcdca159baba47dd3f0b38cb7277532978e54e483d51da98599153adf/analysis/1396114311/
  • https://urlquery.net/report.php?id=1396113767846

3/28/2014

Stop ! This Website Is Not Safe !
Psssst...i am OUTING myself....so, beware...
Not only since Yesterday (This Blog) is stamped as a PHISHING Site (by BD (BitDefender)....This POST (Threat)) will be kept updated.
Sooner or later. And Fortinet jumped into it (Today. The NET).
Riddle: Find out why...it started...! STAY TUNED !

STOP ! THIS WEBSITE is NOT Safe 
  • http://trafficlight.bitdefender.com/info?url=http://stayaway2.blogspot.com
THE BEGINNING: (AS I SAID, SOME (delicate) INFO WILL BE UPDATED). BitDefender is a GERMAN/ROMANIAn "Fusion?"itis.

The more Hacking, the more will publish. The Circle of Life makes not halt in Front of...BD...who is working EAST(Ward)s !!!


The end of defending Bits (or bytes)



Happy Eastern to ALL (and to myself, i almost forgot): But Never Forget: Kaspersky is the RULE !! Is someone heading EAST ? Or WEST ?? Hitchhike.....

And https://www.virustotal.com/de/user/BMonday/

:D