2020-07-23 update Problem still exists, spammer hosting located here: http://sa3ssdwefweatkom.diskstation.org/r.php?t=XXX -> https://towelred.com/?a=XXX —> https://click.powerplaypoints.com/click/XXX —> https://winorama77.com/lp/de/MagicFairies/index.html?Inc=XXX $ dig +short towelred.com 34.91.19.56 2020-05-22 update Received: from mail-io1-f72.google.com (mail-io1-f72.google.com [209.85.166.72]) From: Keto Intens <jeramy@panakota.xyz> Date: Fri, 22 May 2020 19:5x:xx -0400 Subject: Gratis Keto Burn Formula uitproberen! Nog 12 pakketten beschikbaar, zie hier >> <https://vogspa.com/?[]> *Wetenschappers zijn… Читать далее Spamvertised website
Рубрика: google.com
Malware distribution @172.217.20.84
The host at this IP address (172.217.20.84) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: https://adobepdf-com.uc.r.appspot.com/Legal_debt_recovery_process_pdf.jar AS number: AS15169 AS name: GOOGLE — Google LLC Hostname: ams15s33-in-f20.1e100.net
Malware distribution @216.58.214.16
The host at this IP address (216.58.214.16) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6cd19c87f44r9fOMiT/Base64Jef.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vW/base64.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6ca94027662Tilxa4P/base.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2cbda22efXk3T7X2/base64.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2f6c8c5aduP2Yiwx/basejefin.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6eb2aa215a8CVWCf6s/fudjs.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6eab37b8dadMY1gX7C/base3.5.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c7921a2cf26cUnJcGVm/nanocoregomes.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aAMus8/go.jpeg https://storage.googleapis.com/wzukusers/user-34654398/documents/5c9e24cc08a4dLmV7CJO/CDT.txt AS number: AS15169 AS name: GOOGLE Hostname: lhr26s05-in-f16.1e100.net
lp01jtrk.com (Spam redirector)
Google hoss the A record and webise of the domain lp01jtrk.com, which provides redirection services in spam sent to advertise the domain everydaywinner.com. The spam is sent to email addressees scraped from websites and similar public forums. The spammer appears to be listwshing email addresses scraped from websites with phoney confirmation emails. Any response to… Читать далее lp01jtrk.com (Spam redirector)
Malware distribution @172.217.17.112
The host at this IP address (172.217.17.112) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6cd19c87f44r9fOMiT/Base64Jef.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6cbd811626fvoj29vW/base64.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6ca94027662Tilxa4P/base.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2cbda22efXk3T7X2/base64.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6e2f6c8c5aduP2Yiwx/basejefin.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6eb2aa215a8CVWCf6s/fudjs.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6eab37b8dadMY1gX7C/base3.5.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c7921a2cf26cUnJcGVm/nanocoregomes.txt https://storage.googleapis.com/wzukusers/user-34654398/documents/5c6fd6b4eb1c08aAMus8/go.jpeg https://storage.googleapis.com/wzukusers/user-34654398/documents/5c9e24cc08a4dLmV7CJO/CDT.txt AS number: AS15169 AS name: GOOGLE — Google LLC Hostname: ams15s29-in-f112.1e100.net
Malware distribution @35.214.96.217
The host at this IP address (35.214.96.217) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: https://inspocoach.com/qvbffy/C/S792vXc3L.zip https://inspocoach.com/xcofiyggsnhy/jeXAphNdW3.zip https://inspocoach.com/qvbffy/I/oTCOavFZG.zip https://inspocoach.com/xcofiyggsnhy/r1ZbbE7YB9.zip https://inspocoach.com/hohesrc/2B/bJ/akM76OqS.zip https://inspocoach.com/hohesrc/o/271PhcFaW.zip https://inspocoach.com/hohesrc/FR32f8nOta.zip https://inspocoach.com/hohesrc/q/hRTA4ldin.zip AS number: AS15169 AS name: GOOGLE Hostname: 217.96.214.35.bc.googleusercontent.com
Malware distribution @35.208.186.108
The host at this IP address (35.208.186.108) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: https://aksidcorp.com/ufnzabpih/y2duMJtMTl.zip https://aksidcorp.com/kkmyw/cve6xBGHzH.zip https://aksidcorp.com/kkmyw/SU/RT/U92u0Ia0.zip https://aksidcorp.com/ufnzabpih/ervmKfmw9T.zip AS number: AS15169 AS name: GOOGLE Hostname: 108.186.208.35.bc.googleusercontent.com
Malware distribution @35.209.53.85
The host at this IP address (35.209.53.85) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: http://bsaleasing.com/eypkeok/q/66hDgn1Ak.zip http://bsaleasing.com/eypkeok/krxV4nHZmh.zip http://bsaleasing.com/nmoqdso/6/WCAt0IPGI.zip http://bsaleasing.com/eypkeok/xdGi3nBWXP.zip http://bsaleasing.com/eypkeok/FUCT18sQ1E.zip http://bsaleasing.com/eypkeok/FE/bz/jmWn0PEM.zip http://bsaleasing.com/eypkeok/47vQ9zFcer.zip http://bsaleasing.com/eypkeok/A/AAvC509rT.zip http://bsaleasing.com/eypkeok/r/R2pYrISCg.zip http://bsaleasing.com/nkpcnfwgyjf/mF55WHPgpY.zip http://bsaleasing.com/nkpcnfwgyjf/EvXbWfpBOi.zip http://bsaleasing.com/nkpcnfwgyjf/tjk9is9Xni.zip http://bsaleasing.com/nkpcnfwgyjf/W/QZNKTad2D.zip AS number: AS15169 AS name: GOOGLE Hostname: 85.53.209.35.bc.googleusercontent.com
Malware distribution @35.214.208.114
The host at this IP address (35.214.208.114) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: https://global-tunnelling-experts.com/vgbdjdrdn/v/ws1SiCfdU.zip https://global-tunnelling-experts.com/vgbdjdrdn/AihFFXCWwW.zip https://global-tunnelling-experts.com/vgbdjdrdn/ne/GV/kuBCKhLy.zip https://global-tunnelling-experts.com/vgbdjdrdn/vMeyt8C6G1.zip https://global-tunnelling-experts.com/vgbdjdrdn/kX/AM/ZnsIt2aM.zip AS number: AS15169 AS name: GOOGLE Hostname: 114.208.214.35.bc.googleusercontent.com
Malware distribution @35.214.108.70
The host at this IP address (35.214.108.70) is either operated by cybercriminals or hosting compromised websites that are being used to distribute malware: https://easepc.co.uk/umijtdk/bcUDCiVk56.zip https://easepc.co.uk/fcckbrhtie/tu/Ov/GxBlNlqW.zip https://easepc.co.uk/fcckbrhtie/hUguWEdFu8.zip https://easepc.co.uk/umijtdk/0/hvsEdKoOi.zip https://easepc.co.uk/umijtdk/cX/Xp/elnFLljK.zip https://easepc.co.uk/umijtdk/sR/b8/5eRKXwiw.zip https://easepc.co.uk/umijtdk/ZJ/aH/bYIMw3oR.zip https://easepc.co.uk/umijtdk/6qV9sg97QM.zip https://easepc.co.uk/umijtdk/k/k8Hipz79p.zip https://easepc.co.uk/umijtdk/63/1n/2BPCNaeD.zip https://easepc.co.uk/umijtdk/I/4prXtUyxV.zip https://easepc.co.uk/umijtdk/DEsrz1D8U2.zip https://easepc.co.uk/umijtdk/hQktCeI58Q.zip https://easepc.co.uk/umijtdk/K3/Ri/geP4xpup.zip https://easepc.co.uk/umijtdk/d/WgiMytqxH.zip https://easepc.co.uk/umijtdk/O/Ro4I2b5rZ.zip https://easepc.co.uk/fcckbrhtie/KZ/o6/dgrmVJJ4.zip AS number: AS15169 AS name: GOOGLE Hostname: 70.108.214.35.bc.googleusercontent.com