Sunday, April 20, 2014

Mule/ID Theft "Drop" Email Addresses: 3/18/2014 - 3/31/2014

Address
wnunion210@yahoo.in
moffice18@yahoo.co.uk
mamudadiallo1@gmail.com
felixmoore01@globomail.com
cbb36343@gmail.com
realpost024@hotmail.com
billfranklin01@yahoo.com
jose.adamu007@yahoo.com
service@greeniscoindustrial-ltd.com

Network Scanners, Web Bots, and Affiliated Spammers: 1.182.118.184 - 93.180.5.26

IP Address PTR Record Country Activity Detected
1.182.118.184 no PTR record China Network Scanner
1.182.118.186 no PTR record China Network Scanner
112.123.169.45 no PTR record China Network Scanner
113.17.173.11 no PTR record China Network Scanner
113.17.173.12 no PTR record China Network Scanner
114.34.214.120 114-34-214-120.HINET-IP.hinet.net Taiwan Network Scanner
116.10.191.180 no PTR record China Network Scanner
116.10.191.181 no PTR record China Network Scanner
116.10.191.182 no PTR record China Network Scanner
116.10.191.184 no PTR record China Network Scanner
120.50.35.234 234.35.50.120.static.idc.qala.com.sg Singapore Network Scanner
124.128.82.104 no PTR record China Network Scanner
142.4.110.119 no PTR record United States Network Scanner
171.88.164.72 no PTR record China Network Scanner
180.76.4.175 no PTR record China Network Scanner
184.105.139.77 scan-03b.shadowserver.org United States Network Scanner
184.105.139.98 scan-04g.shadowserver.org United States Network Scanner
186.119.129.38 no PTR record Colombia Web Bot 
190.109.176.170 no PTR record Colombia Network Scanner
191.238.59.121 no PTR record Brazil Network Scanner
192.200.105.131 192-200-105-131.static.gorillaservers.com United States Network Scanner
192.81.76.84 mail.digitalhathi.com United States Network Scanner
198.50.186.211 no PTR record Canada Network Scanner
199.203.117.86 dns.rtssoftware.co.il United States Network Scanner
201.239.33.40 pc-40-33-239-201.cm.vtr.net Chile Network Scanner
208.57.237.98 lgb-static-208.57.237.98.mpowercom.net United States Network Scanner
210.152.157.43 s210-152-157-43.z-cloud.jp Japan Web Bot 
216.200.114.114 cu037.cub.ngptools.com United States Web Bot 
216.99.145.190 unassigned.psychz.net United States Network Scanner
217.73.88.145 user-88.145.infomir.com.ua Ukraine Network Scanner
218.237.66.140 no PTR record Republic of Korea Network Scanner
220.130.174.227 220-130-174-227.HINET-IP.hinet.net Taiwan Web Bot 
220.177.198.31 no PTR record China Network Scanner
222.186.34.224 no PTR record China Network Scanner
222.186.52.106 no PTR record China Network Scanner
23.228.245.166 no PTR record United States Web Bot 
23.229.16.250 scoood.com United States Network Scanner
24.38.88.10 1826580a.cst.lightpath.net United States Network Scanner
58.19.244.201 58.19.arpa.hb.cnc.cn China Network Scanner
58.218.200.113 no PTR record China Network Scanner
60.28.24.218 no-data China Network Scanner
74.143.5.106 74-143-5-106.static.insightbb.com United States Network Scanner
74.82.47.25 no PTR record United States Network Scanner
74.82.47.29 no PTR record United States Network Scanner
93.180.5.26 no PTR record Russian Federation Network Scanner

Suspicious Hosts/URLs: 103.254.137.18 - 95.84.156.43

Spamvertised URL IP Address Country Activity Detected
http://www.australian4wd.com.au...serivce_3d-secure-verification… 103.254.137.18 Australia Phishing
http://longerharder.ru/ 115.137.129.227 Republic of Korea Rogue Pharmacy
http://featheredge.net/book 192.31.186.3 United States Pornography
http://tabdrugpharmacy.ru 192.69.90.43 United States Rogue Pharmacy
http://camconnectonline.com 209.200.10.133 United States Pornography
http://rusexylxx.ru 46.165.232.250 Germany Pornography
http://mightyskills.net/book 75.98.13.98 United States Pornography
http://www.cpdconnect.co.uk/logs/Yahoo.html 91.186.30.102 United Kingdom Phishing
http://gniqlr.turnerlevitrapills.ru 95.84.156.43 Russian Federation Rogue Pharmacy
http://enzgil.newhealthcarepill.ru 95.84.156.43 Russian Federation Rogue Pharmacy

Spambots, Proxies, and Mail Servers: 1.54.57.251 - 98.138.229.30

IP Address  PTR Record Country Activity Detected
1.54.57.251 no PTR Record Vietnam Pornography
101.236.19.70 no PTR Record China Pornography
101.236.6.149 no PTR Record China Pornography
106.10.151.155 omp1009.mail.sg3.yahoo.com Singapore Mule/ID Theft
106.10.166.122 tm11.bullet.mail.sg3.yahoo.com Singapore Mule/ID Theft
115.241.236.28 no PTR Record India Mule/ID Theft
116.171.77.201 no PTR Record China Pornography
116.171.94.240 no PTR Record China Pornography
116.172.23.210 no PTR Record China Pornography
116.173.109.139 no PTR Record China Pornography
116.203.57.140 no PTR Record India Mule/ID Theft
122.16.122.200 p3200-ipbf1804marunouchi.tokyo.ocn.ne.jp Japan Mule/ID Theft
122.178.65.85 no PTR Record India Rogue Pharmacy
149.174.113.101 webmail-va027.sim.aol.com United States Mule/ID Theft
149.174.18.34 webmail-d144.sim.aol.com United States Mule/ID Theft
159.134.118.215 mail16.svc.cra.dublin.eircom.net Ireland Phishing
159.134.118.25 mail09.svc.cra.dublin.eircom.net Ireland Phishing
166.225.112.57 csn-166-225-112-57.uscc.net United States Rogue Pharmacy
178.81.236.40 no PTR Record Saudi Arabia Pornography
180.37.203.141 msgw006-02.ocn.ad.jp Japan Mule/ID Theft
185.3.33.154 no PTR Record Russian Federation Pornography
188.122.39.52 188-122-39-52.xdsl.5gdsl.com United Kingdom Mule/ID Theft
189.108.142.7 webmail.ilhasolteira.sp.gov.br Brazil Mule/ID Theft
195.138.83.32 akademiyah.tenet.odessa.ua Ukraine Mule/ID Theft
197.251.171.194 no PTR Record Ghana Mule/ID Theft
2.134.32.202 2.134.32.202.megaline.telecom.kz Kazakhstan Rogue Pharmacy
200.24.31.84 pijaos.udea.edu.co Colombia Mule/ID Theft
202.67.240.172 smtp6.hknet.com Hong Kong Mule/ID Theft
202.71.215.23 vp215023.static.uac1.hknet.com Hong Kong Mule/ID Theft
205.188.169.24 oms-dd04.mx.aol.com United States Mule/ID Theft
209.15.226.142 no PTR Record United States Phishing
209.85.216.176 mail-qc0-f176.google.com United States Mule/ID Theft
211.129.71.68 p16004-ipbffx02yosida.nagano.ocn.ne.jp Japan Mule/ID Theft
212.76.85.52 sl9.sahara.net.sa Saudi Arabia Mule/ID Theft
216.157.108.172 sbds009.sitevision.com United States Mule/ID Theft
41.138.103.155 no PTR Record Burkina Faso Mule/ID Theft
41.203.67.147 no PTR Record Nigeria Mule/ID Theft
41.206.11.91 41.206.11.91.vgccl.net Nigeria Mule/ID Theft
41.85.169.70 no PTR Record Benin Mule/ID Theft
42.1.143.44 no PTR Record China Pornography
42.1.159.21 no PTR Record China Pornography
42.1.239.91 no PTR Record China Pornography
46.39.245.200 no PTR Record Russian Federation Mule/ID Theft
64.12.81.145 oms-md01.mx.aol.com United States Mule/ID Theft
67.36.170.78 adsl-67-36-170-78.dsl.chcgil.ameritech.net United States Mule/ID Theft
71.241.251.54 static-71-241-251-54.washdc.fios.verizon.net United States Mule/ID Theft
72.38.254.252 s72-38-254-252.static.datacom.cgocable.net Canada Mule/ID Theft
78.134.3.78 78-134-3-78.v4.ngi.it Italy Mule/ID Theft
80.54.67.3 d3.wschowa.net.pl Poland Rogue Pharmacy
82.57.204.68 no PTR Record Italy Mule/ID Theft
82.57.204.77 no PTR Record Italy Mule/ID Theft
86.42.213.98 no PTR Record Ireland Phishing
86.46.239.153 86-46-239-153-dynamic.b-ras1.pgs.portlaoise.eircom.net Ireland Phishing
93.94.56.7 robsmtp01.robot-lda.pt Portugal Mule/ID Theft
98.138.226.180 tm15.bullet.mail.ne1.yahoo.com United States Mule/ID Theft
98.138.229.30 nm37.bullet.mail.ne1.yahoo.com United States Mule/ID Theft

Saturday, April 5, 2014

Infected Website: xnxx.com

Infection Data:
Infection Activity: google.com/safebrowsing/diagnostic?site=xnxx.com
URL Reputation: hosts-file.net/?s=xnxx.com
Host IP Address: 141.0.174.34
Country: Netherlands
Host IP Reputation: virustotal.com/en/ip-address/141.0.174.34/information/
DNS: NS1.RANDOMSERVER.COM - NS6.RANDOMSERVER.COM
DNS Reputation: n/a
Registrant: WGCZ s.r.o.
 
Additional Sites Registered: 
acidgay.com
actresssex.com
adult.net
adultweb.com
amateurs.org
amatuermovies.com
amaturefuck.com
analsexfiles.com
analtoy.com
asianwhores.com
bannedmovies.com
bigbreast.com
blackcameltoe.com
britishwhores.com
buttplug.com
buypornomovies.com
buypornos.com
buysextoys.com
caligula.com
cameltoe.com
chicks.com
chics.com
clits.com
curveymovies.com
cyberporn.com
cyberslut.com
cyberwhores.com
cyberxxx.com
digitalsex.com
dirtydates.com
download-free-sex-movies.net
dvdhunter.com
ebonytube.com
eroticlink.com
eroticlinks.com
eroticonline.com
erotique.com
expolitedteens.com
extacy.com
fatgranny.com
fetishtimes.com
filles.com
flashporn.org
freempegvideo.com
freeporn.com
fuc.com
fuck.sc
funnylunk.com
garcons.com
gogogirls.com
gogoshow.com
good-free-porn.net
gorgeoustalisa.com
gouldesbrough.com
hotasfiya.com
hoterotic.com
ibabe.com
imsolos.com
indiagirl.com
indo-latestinfo.com
internetbabes.com
isexshop.com
koreansex.com
lapdancing.com
latinaction.com
leathergirls.com
lickers.com
lifewealth8.com
links2movies.com
linxxx.com
livegay.com
luckyvirginz.com
male4male.com
matureimage.com
milfporn.com
msproxies.com
mtscrew.com
myfantasy.com
myfriendshottmom.com
myladyrussia.com
nonudeclips.com
nordicgirls.com
nuttbucket.com
nycityopera.com
obscene.com
onlyhotgirls.com
perversion.com
pimp.com
playbabes.com
porn.sc
pornflash.org
pornovore.com
porn-stars.com
pornweb.com
pornworld.com
posterroo.com
pute.com
ratemyboobs.com
rejoboto.com
schoolporn.com
s-e-x.com
sex1.com
sex4free.com
sexbar.com
sexblast.com
sexbookshop.com
sexbox.com
sexfair.com
sexforsex.com
sexfreetube.net
sexfx.com
sexgallery.com
sexhangout.com
sexophone.com
sexpic.com
sexpix.com
sexstream.com
sextale.com
sexuality.com
sexxychyna.com
shimmeringgraphix.com
snowflakeinnjxn.com
spanishwomen.com
spicysex.org
studentporn.com
sweetcumloads.com
swingers.com
teenbeauties.com
teensluts.com
thesex.com
toonporn.com
toysnet.com
triplexbabes.com
tubezzz.com
tvshowsdownload.net
videoxx.com
virginsmania.com
virtualcam.com
webpeepshow.com
whores.org
wildeyeboys.com
wiveswap.com
xnx.xxx
xnxx.co.in
xnxx.org.in
xnxxgallery.com
xnxxlive.xxx
xnxxx.xxx
xvideo.in
xvideos.co.il
xvideos.org
xvideos.org.in
xxx.org
xxxamerica.com
xxxdream.com
xxxgay.com
xxxmail.com
xxxonline.com
xxxsite.com
xxxsites.com
xxxweb.com
xxxwebsite.com
ziggygirl.com
 
Registrar: GANDI SAS
Registrar Reputation: google.com/#q=site:spamhaus.org+%22gandi%22
Payment Processor(s): n/a
Custodian of Records U.S.C. 2257: n/a
 
External Links:
trafficholder.com/aff.php
el-ladies.com
pornorama.com
 
Associated Criminal/Suspicious Activity:

1.) black hat SEO
UnmaskParasites.com/security-report/?page=asianwhores.com
UnmaskParasites.com/security-report/?page=buysextoys.com
UnmaskParasites.com/security-report/?page=dvdhunter.com
UnmaskParasites.com/security-report/?page=gogogirls.com

2.) registered website (lifewealth8.com) linked to investment schemes:
ukraine.com/forums/open-board/5402-lifewealth8-funny-way-make-money.html
asic.gov.au/asic/asic.nsf/byheadline/03-081+LifeWealth8%3A+investor+warning?openDocument
bbb.org/sanjose/business-reviews/pyramid-companies/lifewealth8-in-los-angeles-ca-13205029
dbo.ca.gov/ENF/pdf/2003/LifeWealth.pdf

3.) xnxx.com hosted on a spam-friendly network:
sitevet.com/db/asn/AS46652
cleantalk.org/blacklists/AS46652
malwareurl.com/ns_listing.php?as=AS46652
zeustracker.abuse.ch/monitor.php?as=46652
safebrowsing.clients.google.com/safebrowsing/diagnostic?site=AS:46652

4.) promotion of prostitution/potential human trafficking:
https://encrypted.google.com/search?output=search&sclient=psy-ab&q=site:xnxx.com+%22prostitution%22&btnG=&gbv=1&sei=qT9AU-rVEonOygPJ64KQDw

5.) sells traffic to TrafficHolder; a Traffic  buyer/reseller linked to malware and illegal pornography:
urlquery.net/report.php?id=1396718222193, hosts-file.net/?s=trafficholder.com

6.) adware detected in mobile application:
virustotal.com/en/file/fd54511d46d3f956b45ca672b936ba85a6be445563c7142a3d2c04f917cf75e1/analysis/1396722012/

Mule/ID Theft "Drop" Email Addresses: 3/5/2014 - 3/16/2014

Address
dieingsoulesther@outlook.com
alex.rostov@rambler.ru
dhl.courier_ltd@dr.com
mzgloriamck@gmail.com
drgw.boa@aol.com
westernunion54@qq.com
wu.mtransfer12@gmail.com
smilewis@aol.com
smithlewis66@aol.com
jessicaaali123@gmail.com

Network Scanners, Web Bots, and Affiliated Spammers: 108.186.4.216 - 98.251.18.23

IP Address PTR Record Country Activity Detected
108.186.4.216 no PTR record United States Network Scanner
110.153.0.248 no PTR record China Network Scanner
112.125.93.134 ip112.hichina.com China Network Scanner
113.39.47.55 113x39x47x55.ap113.ftth.ucom.ne.jp Japan Network Scanner
116.10.191.178 no PTR record China Network Scanner
116.10.191.187 no PTR record China Network Scanner
116.10.191.190 no PTR record China Network Scanner
116.10.191.201 no PTR record China Network Scanner
116.10.191.206 no PTR record China Network Scanner
116.10.191.211 no PTR record China Network Scanner
116.10.191.214 no PTR record China Network Scanner
117.104.36.159 fj159.net117104036.thn.ne.jp Japan Network Scanner
117.203.65.198 no PTR record India Network Scanner
118.26.226.103 no PTR record China Network Scanner
119.140.34.223 no PTR record China Network Scanner
124.49.188.99 no PTR record Republic of Korea Network Scanner
134.249.66.76 134-249-66-76-broadband.kyivstar.net Ukraine Network Scanner
142.0.139.197 no PTR record China Network Scanner
142.0.41.225 smtp225.abstractexponent.com United States Network Scanner
157.157.162.253 157-157-162-253-du-tms-is-253.tms.is Iceland Network Scanner
162.243.254.64 proxy.cablematico.net United States Network Scanner
171.111.153.168 no PTR record China Web Bot 
171.217.33.199 no PTR record China Network Scanner
173.219.71.143 173-219-71-143.mid.sta.suddenlink.net United States Network Scanner
173.242.117.182 no PTR record United States Network Scanner
177.73.72.85 no PTR record Brazil Network Scanner
179.30.160.177 r179-30-160-177.dialup.mobile.ancel.net.uy Uruguay Network Scanner
181.135.49.84 BAMovil-181-135-49-84.une.net.co Colombia Network Scanner
182.150.43.16 no PTR record China Network Scanner
185.4.227.26 185-4-227-26.turkrdns.com Turkey Network Scanner
186.93.142.216 no PTR record Venezuela Network Scanner
187.104.248.231 bb68f8e7.virtua.com.br Brazil Network Scanner
187.135.171.177 dsl-187-135-171-177-dyn.prod-infinitum.com.mx Mexico Network Scanner
192.185.70.170 no PTR record United States Network Scanner
193.121.38.48 ns.kender-thijssen.be Belgium Network Scanner
195.177.86.242 c3b156242.1000lecie.pl Poland Network Scanner
195.205.122.71 no PTR record Poland Network Scanner
198.98.115.197 no PTR record United States Network Scanner
199.115.117.69 smsm-by.leaseweb.com United States Network Scanner
200.42.152.122 200-42-152-122.dup.prima.net.ar Argentina Network Scanner
200.68.51.228 mail.cuconcepcion.cl Chile Network Scanner
200.91.29.138 no PTR record Chile Network Scanner
201.155.77.90 dsl-201-155-77-90-sta.prod-empresarial.com.mx Mexico Network Scanner
201.209.204.20 201-209-204-20.genericrev.cantv.net Venezuela Network Scanner
202.79.40.21 coova-00.wlink.com.np Nepal Network Scanner
205.171.59.214 no PTR record United States Network Scanner
206.212.254.12 12.smart-dns.net United States Network Scanner
206.245.177.145 no PTR record United States Network Scanner
207.244.66.108 hosted-by.leaseweb.com United States Network Scanner
211.98.19.22 no PTR record China Network Scanner
213.174.107.61 no PTR record France Network Scanner
213.241.88.99 nsv6w1.internetia.pl Poland Network Scanner
213.66.82.43 213-66-82-43-no95.tbcn.telia.com Sweden Network Scanner
216.172.132.194 808bidz.com United States Network Scanner
217.114.219.160 ns.project-hamm.de Germany Network Scanner
218.205.184.10 no PTR record China Network Scanner
218.76.66.60 no PTR record China Network Scanner
218.77.128.210 210.128.77.218.hk.hi.!dynamic.163data.com.cn China Network Scanner
218.8.57.8 no PTR record China Network Scanner
218.92.164.206 no PTR record China Network Scanner
219.235.8.107 host-219-235-8-107.iphost.gotonets.com China Network Scanner
219.94.167.43 no PTR record Japan Network Scanner
220.128.116.164 220-128-116-164.HINET-IP.hinet.net Taiwan Network Scanner
23.228.245.149 no PTR record United States Web Bot 
27.224.120.225 no PTR record China Network Scanner
42.120.16.78 no PTR record China Network Scanner
47.21.150.178 ool-2f1596b2.static.optonline.net United States Network Scanner
59.30.233.10 no PTR record Republic of Korea Network Scanner
59.63.181.176 no PTR record China Network Scanner
60.50.180.20 20.180.50.60.cbj01-home.tm.net.my Malaysia Network Scanner
61.174.51.205 205.51.174.61.dial.wz.zj.dynamic.163data.com.cn China Network Scanner
64.34.178.183 beach.benon.com United States Network Scanner
66.91.137.210 remote.midpacmedical.com United States Network Scanner
69.12.92.138 69.12.92.138.static.quadranet.com United States Network Scanner
69.39.107.116 jporter.w.midcoast.com United States Network Scanner
71.6.167.142 census9.shodan.io United States Network Scanner
77.75.17.114 77-75-17-114.rz01.sysup.at Austria Network Scanner
78.187.88.138 78.187.88.138.static.ttnet.com.tr Turkey Network Scanner
80.25.160.102 102.Red-80-25-160.staticIP.rima-tde.net Spain Network Scanner
80.82.78.105 no PTR record Netherlands Network Scanner
81.92.36.103 ip-36-103.sn3.eutelia.it Italy Network Scanner
82.148.33.154 adsl-82-148-33-154.fast.net.uk United Kingdom Network Scanner
83.222.181.181 net4-ip181.linkbg.com Bulgaria Network Scanner
92.50.171.242 92.50.171.242.static.ufanet.ru Russian Federation Network Scanner
93.138.13.21 93-138-13-21.adsl.net.t-com.hr Croatia Network Scanner
98.251.18.23 c-98-251-18-23.hsd1.ga.comcast.net United States Network Scanner