IP Location: Netherlands - Nxs Internet BV
IP 217.115.197.59
[php5.cluster2.nxs.nl]
AS16237
hxxp://werkenbijdlapiper.nl/apache.jpg
hxxp://werkenbijdlapiper.nl/apachev2.jpg
md5sum ===> bbde3bab4a97ed75736b761169a80491
SHA256 ===> d8fb95049fb0335d9780b26fad9e73cfc8e6f64ebd33a2074433b4c19e6aab79
dropzone (already listed):
hxxp://pteradaktel.net/webstate/webstat.php
IP Location: Singapore - QALA Singapore Pte Ltd - QALA-SG-AP M1 Connect Pte Ltd
IP 210.193.49.130
[svr10.focushub.com]
Registrant/Registrant Email: Bryan Wong/SIDEWALK10@ZERO.AD.JP
AS17547
hxxp://praisemytee.com/apache.jpg
hxxp://praisemytee.com/apachev2.jpg
md5sum ===> bbde3bab4a97ed75736b761169a80491
SHA256 ===> d8fb95049fb0335d9780b26fad9e73cfc8e6f64ebd33a2074433b4c19e6aab79
dropzone (already listed):
hxxp://pteradaktel.net/webstate/webstat.php
related (Fake AV):
hxxp://wiki.joymineralcosmetics.com/main.php?h=praisemytee.com&i=J8moj9sbrP6sihj7U8VDy5sXog==&e=4
IP Location: France - Ovh Sas
IP 213.186.33.87
[cluster014.ovh.net]
AS16276
hxxp://marathon-demenagement.fr/alogo.jpg
md5sum ===> db0601b2aadb6ea03b0828203b365c84
SHA256 ===> 1749b809f111f27f4fe666969bafbd50e655bf2b6448918805dab63c3a9b0f74
dropzone (already listed):
hxxp://www.blogjo.biz/webstate/webstat.php
IP Location: Malaysia - Exa Bytes Network Sdn.Bhd - EXABYTES-AS-AP Exa Bytes Network Sdn.Bhd
IP 110.4.45.98
AS46015
hxxp://solartif.com.my/alogo.jpg
md5sum ===> db0601b2aadb6ea03b0828203b365c84
SHA256 ===> 1749b809f111f27f4fe666969bafbd50e655bf2b6448918805dab63c3a9b0f74
dropzone (already listed):
hxxp://www.blogjo.biz/webstate/webstat.php
related (Fake AV):
hxxp://ns1.joymineralcosmetics.com/main.php?h=solartif.com.my&i=JcSvj9Qarf+mihj7U8VDw5kXog==&e=4
IP Location: Malaysia - Exa Bytes Network Sdn.Bhd - EXABYTES-AS-AP Exa Bytes Network Sdn.Bhd
IP 110.4.45.111
[bramble.mschosting.com]
AS46015
hxxp://wic.com.my/alogo.jpg
md5sum ===> db0601b2aadb6ea03b0828203b365c84
SHA256 ===> 1749b809f111f27f4fe666969bafbd50e655bf2b6448918805dab63c3a9b0f74
dropzone (already listed):
hxxp://www.blogjo.biz/webstate/webstat.php
related (Fake AV):
hxxp://blog.onlyyoulifestyle.com/main.php?h=wic.com.my&i=JcSvj9Qarf+njRj7U8VCw5IXog==&e=4
related:
hxxp://tviwvo.pohuy.ws/t/t?
IP Location: Netherlands - LEASEWEB - LeaseWeb AS
IP 85.17.3.199
AS16265
hxxp://markec.by/alogo.jpg
md5sum ===> db0601b2aadb6ea03b0828203b365c84
SHA256 ===> 1749b809f111f27f4fe666969bafbd50e655bf2b6448918805dab63c3a9b0f74
dropzone (already listed):
hxxp://www.blogjo.biz/webstate/webstat.php
Fake AV for supradem.fr
hxxp://wwww.causeof.org/main.php?h=supradem.fr&i=J8mjj9QYr/mhgRj7U8tHz5kXog==&e=4
hxxp://wwww.causeof.org/main.php?i=J8mjj9QYr/mhgRj7U8tHz5kXog==&e=3
IP Location: Russian Federation - Bank Moscowskiy Kapital Ltd
AS42953
hxxp://91.194.0.20/beemstofadm.bin
md5sum ===> 70002aa44905bb6fdacac4d951fdc759
SHA256 ===> 4d830e91fe7a64a760a92abd6aebe01f605a21747da5a5e056798cf653341490
other malwaretrojan dropper agent
hxxp://hostshack.net/files/328997512/UltimateCodes.exe
md5sum ===> 8c3f8827614de3692cb3cc7ef73c5ff0
SHA256 ===> e4a4f62ed8f562fdf03ab1a4e49beb2818f97bfe41af76770eb0cc76cb00953e
http://www.virustotal.com/es/analisis/e4a4f62ed8f562fdf03ab1a4e49beb2818f97bfe41af76770eb0cc76cb00953e-1277480863VT
2/41 (4.88%)
IP Location: China - China Telecom Guangxi province - CHINA-TELECOM
IP 222.217.221.27
AS4134
hxxp://ip.yihaha.org/gorun.exe
md5sum ===> 1398a666565e0b0e0266abcaf19e57ba
SHA256 ===> 493f577832ab229332b2919a0c93d2169b1fd32e3c0972d8450ba32036114c3f
http://www.virustotal.com/es/analisis/493f577832ab229332b2919a0c93d2169b1fd32e3c0972d8450ba32036114c3f-1277481037VT
14/40 (35%)
hxxp://ip.yihaha.org/click.exe
md5sum ===> 31802c1c776687f837eb0f5877da1798
SHA256 ===> bab6f1cc6ad9c9d7b101ac6bf7f8722cc03c033070f95c229feec61cf99215b7
http://www.virustotal.com/es/analisis/bab6f1cc6ad9c9d7b101ac6bf7f8722cc03c033070f95c229feec61cf99215b7-1277481507VT
15/40 (37.5%)