The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. RacoonStealer botnet controller located at 104.21.67.139 on port 80 (using HTTP GET): hXXp://telegalive.top/agrybirdsgamerept $ dig +short telegalive.top 104.21.67.139 Referencing malware binaries (MD5 hash): 0f501c684fc4bb8e1b28d00b83f24232 — AV detection:… Читать далее RacoonStealer botnet controller @104.21.67.139
spam emitters
Received: from s3.megojom.ru (78.155.202.67 [78.155.202.67]) Date: Thu, 28 Oct 2021 10:3x:xx +0000 From: Aleksandr <info@s3.megojom.ru> Subject: Предложение 78.155.202.66 grehemon.ru 78.155.202.67 megojom.ru 78.155.202.68 tefalongo.ru 78.155.202.69 raferenco.ru 78.155.202.70 frenkom.ru
Spamvertised website
Received: from unny1.consequat.co (unny1.consequat.co. [188.127.235.205]) From: «LAYLA» <[]@consequat.co> Date: Wed, 27 Oct 2021 20:3x:xx -0700 Subject:Layla_sent_you_more_nude_selfies. https://bit.ly/3pwSP5Y 67.199.248.10 http://importantdeals.net/?VF80ODg3XzA= 51.15.10.70 https://bordmac.com/?a=3020&oc=13816&c=39220&p=r&m=3&s1=2&s2=0&s3=4887&s4= 35.204.82.162 https://track.clickstogold.com/aff_c?offer_id=4099&aff_id=2240&url_id=45041&aff_sub=3020&aff_click_id=[] 107.21.246.48 http://citysweeties.com/landing109?cat=default&pt1=[]&pi=2240&pe=3020 34.72.137.22
RedLineStealer botnet controller @65.108.14.118
The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. Malware botnet controller located at 65.108.14.118 on port 15253 TCP: $ telnet 65.108.14.118 15253 Trying 65.108.14.118… Connected to 65.108.14.118. Escape character… Читать далее RedLineStealer botnet controller @65.108.14.118
affiliate spam @clickstogold.com
Received: from unny1.consequat.co (unny1.consequat.co. [188.127.235.205]) From: «LAYLA» <[]@consequat.co> Date: Wed, 27 Oct 2021 20:3x:xx -0700 Subject:Layla_sent_you_more_nude_selfies. https://bit.ly/3pwSP5Y 67.199.248.10 http://importantdeals.net/?VF80ODg3XzA= 51.15.10.70 https://bordmac.com/?a=3020&oc=13816&c=39220&p=r&m=3&s1=2&s2=0&s3=4887&s4= 35.204.82.162 https://track.clickstogold.com/aff_c?offer_id=4099&aff_id=2240&url_id=45041&aff_sub=3020&aff_click_id=[] 107.21.246.48 http://citysweeties.com/landing109?cat=default&pt1=[]&pi=2240&pe=3020 34.72.137.22
spam emitters
5.188.138.19 empresar003.website 5.188.138.32 empresar003.website 5.188.138.135 empresar003.website 5.188.138.171 empresar003.website 77.223.101.68 empresar003.website 77.223.101.136 empresar003.website 77.223.101.139 empresar003.website
spam emitters
5.188.138.19 empresar003.website 5.188.138.32 empresar003.website 5.188.138.135 empresar003.website 5.188.138.171 empresar003.website 77.223.101.68 empresar003.website 77.223.101.136 empresar003.website 77.223.101.139 empresar003.website
Spamvertised website
2021-10-28 crystals.com.de. 60 IN A 159.65.196.250 2021-10-26 crystals.com.de. 60 IN A 165.232.118.6 2021-10-25 crystals.com.de. 60 IN A 46.101.3.14 Received: from gotogml.com (gotogml.com. [185.122.223.223]) From: 🔔Gemeentelijk Energie <[]@gotogml.com> Date: Fri, 08 Oct 2021 09:1x:xx +0000 Subject: Nieuw in uw gemeente: bespaar via het Gemeentelijke Energie Collectief http://crystals.com.de/rd/[] 185.146.157.69 https://laudypauty.com/[] 209.159.146.166 https://sendt.go2cloud.org/aff_c?offer_id=2893&aff_id=1482&aff_sub=472864&aff_sub2=[]&aff_sub3=31 18.202.12.61
affiliate spam @javaburn.com
Received: from AM6P192CA0102.EURP192.PROD.OUTLOOK.COM (2603:10a6:209:8d::43) From: JAVA BURN ™ <[].global.admin@theemarketers.co.uk> Subject: 🆒📢Try JAVA BURN For Over 80% OFF Today! 📩🆒 Date: Thu, 28 Oct 2021 00:1x:xx +0200 http://theemarketers.co.uk/cl/[] 23.154.81.106 https://javaburn.lpages.co/javaburn/?aff_sub1=3&aff_sub2=16674_1&aff_sub3=[] 35.202.21.90 https://bit.ly/3C8BFPo 67.199.248.10 https://49b53vyeqghrbue5ljf62eqv1k.hop.clickbank.net/?tid=LINK 35.81.35.31 https://javaburnhop.com/go?hop=ariana321 13.224.96.98 https://javaburn.com/welcome?hop=ariana321 13.224.96.84
spam emitters
Received: from s1.megojom.ru (megojom.ru [185.143.174.42]) Date: Thu, 28 Oct 2021 06:3x:xx +0000 From: Aleksandr <info@s1.megojom.ru> Subject: Предложение 185.143.174.42 megojom.ru 185.143.174.43 tefalongo.ru 185.143.174.44 grehemon.ru 185.143.174.45 raferenco.ru 185.143.174.46 frenkom.ru