Author Topic: Mr Clean's dirt  (Read 162253 times)

0 Members and 1 Guest are viewing this topic.

April 01, 2009, 06:20:18 am
Reply #15

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Code: [Select]
somefilesportalnow.com/viewtubesoftware.40019.exe
freeportalsoftwarenow.com/viewtubesoftware.40019.exe
sim-softportal.com/viewtubesoftware.40019.exe
dnk-softwares.com/viewtubesoftware.40019.exe
get-softwares.com/viewtubesoftware.40019.exe
glk-softportal.com/viewtubesoftware.40019.exe
glock-softwares.com/viewtubesoftware.40019.exe
Ruining the bad guy's day

April 01, 2009, 11:21:55 am
Reply #16

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
contr-softportal.com/viewtubesoftware.40019.exe

April 01, 2009, 06:28:54 pm
Reply #17

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
http://zaq-softwares.com/viewtubesoftware.40016.exe




April 02, 2009, 04:05:08 pm
Reply #21

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331

April 02, 2009, 05:58:40 pm
Reply #22

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Code: [Select]
hxxp://sendspace-usa.net/sur4you.exe

http://www.virustotal.com/analisis/66933d74a2ca3ffca1742cbcd5c1c08c
http://www.threatexpert.com/report.aspx?md5=295e55e662d21f42596972924a74db37


Doesn't resolve here. Can you give me the ip ? I'm experiencing dns problems at the moment when I try to resolve .net domains.
Ruining the bad guy's day

April 02, 2009, 06:12:09 pm
Reply #23

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
IP was 196.2.198.241 - it's not resolving atm

/edit

Others on the same IP;

Code: [Select]
egns.vg
www.egns.vg
ns1.egns.vg
bankofoscotland.co.uk
thelegion74.com
love-true.com
thronofodin.com
throbilskirnir.com
good1soft.com
great2008x.com
ustechservic.com.cn
vse4you.info
wwwfbcdn.net
cd-soft.net
thefreecompany.net
googgle.su
yanndex.su
sendspace.com.bz
yourbestpartners.biz

Though Domain Tools says there's 65 on there (and the guy that owns sendspace-usa.net apparently owns 63 domains - and I'm betting they're likely on the same IP)

/edit

http://hosts-file.net/misc/hpObserver_-_egns.vg.html

There's also 196.2.198.240, 196.2.198.242, 196.2.198.243 and 196.2.198.252

http://hosts-file.net/?s=196.2.198.242

Related to;

http://www.bobbear.co.uk/delivery-solutions-inc.html
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net


April 03, 2009, 09:56:21 pm
Reply #25

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331

April 04, 2009, 04:50:21 am
Reply #26

sowhat-x

  • Guest
Code: [Select]
hxxp://find-365.com/pages/make-pictures
hxxp://best-tube-home.com/200073/scan/
hxxp://files.ms-loads-av.com/exe/setup_200073_1_1.exe
hxxp://files.ms-loads-av.com/ -> spawns exe...
hxxp://files.ms-loads-av.com/exe/setup_200073_2_1.exe
hxxp://files.ms-loads-av.com/exe/setup_1_2_1.exe

find-365.com is the most interesting (to me at least),as it's hosted in more than one ip addresses...
http://www.bfk.de/bfk_dnslogger.html?query=find-365.com#result

Code: [Select]
hxxp://mycigarworld.info/in.cgi?16
hxxp://greatvirusscan.com/index.php?affid=10700
hxxp://greatvirusscan.com/download.php?affid=10700  -> spawns exe...

Code: [Select]
hxxp://tds.ibestadult.info/in?4
hxxp://mega-antiviral-ms.com/200073/scan/
hxxp://files.ms-loads-av.com/exe/setup_200073_1_1.exe

Code: [Select]
hxxp://webprotectionscan.com/download.php?affid=00000
hxxp://zoosexvideo.net/movie352.exe

April 04, 2009, 11:43:40 am
Reply #27

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
find-365.com is the most interesting (to me at least),as it's hosted in more than one ip addresses...
http://www.bfk.de/bfk_dnslogger.html?query=find-365.com#result

I agree, quite interesting.

61.235.117.88   #       SHENZHEN        CHINA
72.167.121.94   #       LOS ANGELES     UNITED STATES
88.214.200.60   #       -       UNITED KINGDOM
92.62.101.47    #       TALLINN ESTONIA

2 of these IP's have already been reported

http://www.malwaredomainlist.com/mdl.php?search=72.167.121.94&colsearch=All&quantity=50
http://www.malwaredomainlist.com/mdl.php?search=88.214.200.60&colsearch=All&quantity=50

April 04, 2009, 05:43:09 pm
Reply #28

sowhat-x

  • Guest
Quote
hxxp://ourbestsearch.info/in.cgi?4
hxxp://adult-tube-downloads.net/promo3/?aid=330
hxxp://adult-tube-downloads.net/promo3/get.php?aid=330&vname=protect
http://www.virustotal.com/analisis/5a58f3c0fc68a1a71ced42ac568936e8

April 06, 2009, 05:37:12 am
Reply #29

sowhat-x

  • Guest
Quote
hxxp://bestguideinc.net/search.php?qq=    ---> the .js redirector...
hxxp://www.spywareisolator2008.com/landing/?wmid=mirex    ---> spawns fake av exe...

Quote
hxxp://antivirus-av-ms-checker.com/200073/scan/
hxxp://files.download-av-ms.com/exe/setup_200073_1_1.exe