Author Topic: daily something......  (Read 858065 times)

0 Members and 1 Guest are viewing this topic.

June 10, 2009, 08:51:36 pm
Reply #450

sursmurf

  • Special Access
  • Full Member

  • Offline
  • *

  • 68

June 11, 2009, 05:24:08 am
Reply #451

promised

  • Jr. Member

  • Offline
  • **

  • 21
banker
Quote
hxxp://71.174.51.86/images/logout.jpg

June 11, 2009, 05:43:25 am
Reply #452

Malware-Web-Threats

  • Special Members
  • Hero Member

  • Offline
  • *

  • 354
    • MalwareURL
Code: [Select]
jenesaisrien.com:8080/load.php
vds659.sivit.org:8080/load.php
shopmoviefestival.cn:8080/load.php
s72-38-121-90.static.comm.cgocable.net:8080/load.php
static-86-94.is.net.pl:8080/load.php
s15238535.onlinehome-server.info:8080/load.php
tweetwitter.com:8080/load.php
gianttopdiscover.cn:8080/load.php
247orders.com:8080/load.php
4-job.com:8080/load.php
server.edwinbuckley.co.uk:8080/load.php
infostore.ca:8080/load.php
roleski.pl:8080/load.php
wtssurvey.com:8080/load.php
findabigrig.cn:8080/load.php
shopmovieproduction.cn:8080/load.php
fancystarlight.com:8080/load.php
lomianki.com:8080/load.php
thegeekdude.com:8080/load.php
theadsensekid.com:8080/load.php
thehomename.cn:8080/load.php
eszafiry.com:8080/load.php
mlodapara.com:8080/load.php
obraczki.com:8080/load.php
readymixbet.cn:8080/load.php
namemartfilmlife.cn:8080/index.php
xbuzzer.com:8080/load.php
spigotinch.com:8080/load.php
smsconnectnow.com:8080/load.php
numberingcite.com:8080/load.php
typicalprecedent.com:8080/load.php
findyourbigidea.cn:8080/load.php
findbigthinkers.cn:8080/load.php
bigskytopguide.cn:8080/load.php
michaelsbestway2findalawyer.cn:8080/load.php
hugetopseek.cn:8080/load.php

VirusTotal
ThreatExpert
Quote
hxxp://78.109.29.116/new/controller.php?action=bot&entity_list=&uid=1&first=1&guid=13441600&rnd=981633

June 11, 2009, 09:12:40 am
Reply #453

Malware-Web-Threats

  • Special Members
  • Hero Member

  • Offline
  • *

  • 354
    • MalwareURL
redirects by telemedia.m77s[.]cn:
Wepawet

exploits:
Code: [Select]
f97q.cn/images/index.php
Wepawet

pdf:
Code: [Select]
f97q.cn/images/spl/pdf.pdf
Wepawet

trojan:
Code: [Select]
f97q.cn/images/exe.php
VirusTotal - 6/40 (15.00%)
Anubis

Quote
From ANUBIS:1032 to 78.109.25.217:80 - [r99u.cn] 
Request: GET /myl/464664.php?id=470261258&v=101&tm=33&b=9671316727 
Response: 200 "OK" 
Request: GET /myl/exe/loader.exe 
Response: 200 "OK"
 

June 11, 2009, 03:27:25 pm
Reply #454

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Mal-Aware

June 12, 2009, 09:42:03 pm
Reply #455

Malware-Web-Threats

  • Special Members
  • Hero Member

  • Offline
  • *

  • 354
    • MalwareURL
redirects:
Code: [Select]
thelotmachine.cn:8080/in.cgi
thenetnameshop.cn:8080/in.cgi
compoundcapitolgroup.cn:8080/in.cgi
mixlotworld.cn:8080/in.cgi
superlottry.cn:8080/in.cgi
webnamemart.cn:8080/in.cgi

payloads:
Code: [Select]
adsl.141.255.0.72.maskatel.ca:8080/load.php
bunchguide.cn:8080/load.php
bigtopfindsite.cn:8080/load.php
bigtopfindsite.cn:8080/cache/readme.pdf
bigtopfindsite.cn:8080/cache/flash.swf
filmlifeimages.cn:8080/load.php
filmlifeimages.cn:8080/cache/readme.pdf
filmlifeimages.cn:8080/cache/flash.swf
findbigshots.cn:8080/load.php
findbigshots.cn:8080/cache/readme.pdf
findbigshots.cn:8080/cache/flash.swf
giantpremium.cn:8080/load.php
giantpremium.cn:8080/cache/readme.pdf
giantpremium.cn:8080/cache/flash.swf
gianttopnano.cn:8080/load.php
gianttopnano.cn:8080/cache/readme.pdf
gianttopnano.cn:8080/cache/flash.swf
mediahomenameshopmovie.cn:8080/load.php
mediahomenameshopmovie.cn:8080/cache/readme.pdf
mediahomenameshopmovie.cn:8080/cache/flash.swf
nameshopinternational.cn:8080/load.php
nameshopinternational.cn:8080/cache/readme.pdf
nameshopinternational.cn:8080/cache/flash.swf
newnetnameshop.cn:8080/load.php
newnetnameshop.cn:8080/cache/readme.pdf
newnetnameshop.cn:8080/cache/flash.swf
shopmovielife.cn:8080/load.php
shopmovielife.cn:8080/cache/readme.pdf
shopmovielife.cn:8080/cache/flash.swf
yournameshop.cn:8080/load.php
yournameshop.cn:8080/cache/readme.pdf
yournameshop.cn:8080/cache/flash.swf

exe:
http://www.virustotal.com/analisis/25db455ed35b759dc3a6924359bd72c37f9cc3b13edac98a96894e344d45078d-1244797876
http://anubis.iseclab.org/?action=result&task_id=1c7642f4324780a04014ee1900012c257

pdf:
http://wepawet.iseclab.org/view.php?hash=d21d612330db155dcbd75191a9b7c021&t=1244801268&type=js

flash:
http://wepawet.iseclab.org/view.php?hash=3e05fc4fd1c7a49f8478da9c76c7c435&type=swf
http://www.virustotal.com/analisis/8fa7088e7dae6ff5f9c4f5eaff14de22e2198b28946472486a5045e44d0d5b5d-1244133184

http://www.threatexpert.com/report.aspx?md5=7264e961f25beaa201906e4086caa1ce

June 14, 2009, 08:02:43 pm
Reply #456

bobby

  • Special Members
  • Hero Member

  • Offline
  • *

  • 322
    • Malzilla
Code: [Select]
http://nyfilmlife.cn:8080/index.phpleads to:
Code: [Select]
http://gianttoplocate.cn:8080/load.php?id=0
http://gianttoplocate.cn:8080/load.php?id=1
http://nyfilmlife.cn:8080/cache/readme.pdf
http://nyfilmlife.cn:8080/cache/flash.swf
http://gianttoplocate.cn:8080/landig.php?id=4

June 15, 2009, 06:28:40 am
Reply #457

CM_MWR

  • Special Members
  • Hero Member

  • Offline
  • *

  • 319

June 15, 2009, 07:16:21 am
Reply #458

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Mal-Aware

June 15, 2009, 03:56:03 pm
Reply #459

sparsha

  • Special Members
  • Hero Member

  • Offline
  • *

  • 305
New Rogue sites
Code: [Select]

protectionsystem.org
protectionsystemlab.com/psystem.exe

Core-guard-antivirus.com
fullguardlab.com
fullprotect.org

http://gosoonscan.com/?uid=13002
http://planscan4.info/download/install.php

http://ina4id.com/download/InternetAntivirusPro.exe
http://ina4id.com/download/file.exe


June 15, 2009, 04:35:48 pm
Reply #460

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Mal-Aware

June 16, 2009, 12:37:14 am
Reply #461

Malware-Web-Threats

  • Special Members
  • Hero Member

  • Offline
  • *

  • 354
    • MalwareURL
redirects:
Code: [Select]
globalmixgroup.cn:8080/in.cgi

payloads:
Code: [Select]
bigbestlite.cn:8080/load.php
bigbestlite.cn:8080/cache/readme.pdf
bigbestlite.cn:8080/cache/flash.swf

bigtopfestival.cn:8080/load.php
bigtopfestival.cn:8080/cache/readme.pdf
bigtopfestival.cn:8080/cache/flash.swf

mixbetonline.cn:8080/load.php
mixbetonline.cn:8080/cache/readme.pdf
mixbetonline.cn:8080/cache/flash.pdf

themixbet.cn:8080/load.php
themixbet.cn:8080/cache/readme.pdf
themixbet.cn:8080/cache/flash.swf

VirusTotal: 1/40
ThreatExpert

June 16, 2009, 05:30:37 am
Reply #462

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Trojans:
Code: [Select]
almasto.net/ins.exe
biggerz.net/ins.exe
Camposceola.com/ins.exe
http://www.virustotal.com/analisis/33c3518f7555aa7b407570e8174133563621629ff2ff8e3c468ffca8da703f3b-1245123021
Code: [Select]
almasto.net/sdfsdf.exehttp://www.virustotal.com/analisis/3e9314888ad11497839781d9a4c9325e36caf86d59bc1ac7ece987e9c56a777b-1245122926
Code: [Select]
friendslinks.com/0/new.exehttp://www.virustotal.com/analisis/68fbe09bcbe4464d9644a57444d9e94f43fd04a2fe42a35ab0f0274cbf14f9ce-1245121971
Code: [Select]
xz.ub9.net/winres.exehttp://www.virustotal.com/analisis/396abb55f933c0df23e78582f5b13738bb799d260618959998f0245c058704f3-1245123148
Code: [Select]
heyjoy.cn/612.exehttp://www.virustotal.com/analisis/652c1cff90096824647b2377b4850fb47f4b6f6abe470eb0114f51d9de86a2a6-1245123263

Exploits:
Code: [Select]
almasto.net/lnk.php?embedded=falsehttp://wepawet.cs.ucsb.edu/view.php?hash=27262e8c3f678960412e6ecd940ccd3f&t=1245109604&type=js

Fake AV downloader:
Code: [Select]
friendslinks.com/0/loyalbox.exehttp://www.virustotal.com/analisis/776c883badde97f0577d6b11eb759ea9f85302a96d79f4446d3eb4e4399051a0-1245122144
Code: [Select]
porno-tube-xxx.us/loader/index.php?userid=id_0079http://www.virustotal.com/analisis/26e35006830b010d1d7c97541f1cf960e3b9e8d4d611e5b991132c1634fe92c2-1245122608

Fake AV:
Code: [Select]
you-adult-tube.co.cc/setup.exehttp://www.virustotal.com/analisis/f2dd78517405edeeacc4b06eab567a54e54b9306d18f02ed620a55cb45abbcbd-1245122729

gives koobface related malware links:
Code: [Select]
upr15may.com/ld/gen.php
Mal-Aware

June 17, 2009, 12:58:15 pm
Reply #463

CM_MWR

  • Special Members
  • Hero Member

  • Offline
  • *

  • 319

June 18, 2009, 02:47:14 am
Reply #464

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Mal-Aware