Author Topic: hs.3-150.zlkon.lv -(94.247.3.150)  (Read 25088 times)

0 Members and 1 Guest are viewing this topic.

April 05, 2009, 07:45:15 pm
Read 25088 times

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
redirect to exploits
Code: [Select]
namebuyline.cn/in.cgi?income
filmtypemedia.cn/in.cgi?income
yourfilmmovie.cn/in.cgi?income
homenameregistration.cn/in.cgi?income
nameashop.cn/in.cgi?income
mainnameshop.cn/in.cgi?income
namesupermart.cn/in.cgi?income
namebrandmart.cn/in.cgi?income
namebuypicture.cn/in.cgi?income31
Ruining the bad guy's day

April 06, 2009, 04:35:59 pm
Reply #1

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
All Redirect to exploit stated below:
Code: [Select]
lotante.cn/in.cgi?income
japanhostnet.com/in.cgi?income
lotbetworld.cn/in.cgi?income
namestorefilmlife.cn/in.cgi?income
internetnamestore.cn/in.cgi?income
coolnameshop.cn/in.cgi?income
dotcomnameshop.cn/in.cgi?income
playbetwager.cn/in.cgi?income
thelotbet.cn/in.cgi?income


wepawet couldnt analyze this exploit and stated that the index.php response is empty(http://wepawet.iseclab.org/view.php?hash=0427b7627c9938608b886b095702247a&t=1239032970&type=js)
was able to d/l the pdf and sent it only.
anyway it download a trojan in the end in the same domain:
Code: [Select]
litehitscar.cn/index.phphttp://wepawet.iseclab.org/view.php?hash=4ad4419f482403c543365cad5e60269a&type=js

btw the domain with the trojan resolves 94.247.3.151 for me...
Mal-Aware

April 06, 2009, 07:09:06 pm
Reply #2

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
did all the domains with the redirections resolved  as 94.247.3.151 for you?(as stated on MDL )

because for me they are all  94.247.3.150 ,also checked on centralops,etc...
Mal-Aware

April 06, 2009, 07:37:17 pm
Reply #3

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
did all the domains with the redirections resolved  as 94.247.3.151 for you?(as stated on MDL )

because for me they are all  94.247.3.150 ,also checked on centralops,etc...

My mistake. Is is another disadvantage of adding urls manually. One mistake and then copy and paste.
Fixed.
Ruining the bad guy's day

April 07, 2009, 03:41:30 pm
Reply #4

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
another redirector to litehitscar.cn
Code: [Select]
superbetfair.cn/in.cgi?income43
Ruining the bad guy's day

April 08, 2009, 12:32:39 pm
Reply #5

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
redirects to hyperliteautoservices.cn
Code: [Select]
cheapslotplay.cn/in.cgi?income48
mixante.cn/in.cgi?income52
Ruining the bad guy's day

April 10, 2009, 12:07:07 pm
Reply #6

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
There is a panel at those sites at /user/panel.

for example
Code: [Select]
www.mediahomenamemartvideo.cn/user/panel
Ruining the bad guy's day

April 17, 2009, 09:21:59 am
Reply #7

Malware-Web-Threats

  • Special Members
  • Hero Member

  • Offline
  • *

  • 354
    • MalwareURL
two others on this IP

redirects to liteautogreatest[.]cn

Code: [Select]
hxxp://cutlot.cn/in.cgi?income
hxxp://lotmachinesguide.cn/in.cgi?income

Wepawet
Wepawet

April 21, 2009, 05:53:33 pm
Reply #8

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

April 25, 2009, 05:45:39 am
Reply #9

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Ruining the bad guy's day

April 27, 2009, 06:58:42 pm
Reply #10

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Code: [Select]
superlitecarbest.cn/in.cgi?income74redirects to exploits at litevehiclemall[.]cn 94.247.3.151
Ruining the bad guy's day