Thứ Sáu, 16 tháng 9, 2011

Not surprisingly, when the bad guys get a foot in, they take full advantage, and that's exactly what they're doing over at Formspring.me. Having started a campaign, and Formspring seemingly doing nothing to prevent it, the surge is continuing, with new ones being created every day so far.Thanks to someone that used to work for them, those that were reported to him, have been taken care of, but

Thứ Hai, 12 tháng 9, 2011

Date: 13-09-2011* Modified LogSpammerToDB (with thanks to Jay Riley, jayriley.com)+ Added blocklist.deDownload:http://support.it-mate.co.uk/?mode=Products&p=spambotsearchtoolLive example:http://temerc.com/Check_Spammers/http://fspamlist.com/checkspammers/

Thứ Sáu, 9 tháng 9, 2011

Seems there's somewhat of a surge of abuse over at formspring.com lately, same kind of abuse seen previously on similar providers.The following, all leading to varying locations, are currently active, and have been reported to the upstream, since Formspring don't want to publicize an abuse contact (CC'd the report to the address listed in the WhoIs for formspring' parent company).hxxp://

Thứ Ba, 6 tháng 9, 2011

New domains today, still only 71 unique MD5s, and all domains living at;IP: 69.64.72.123PTR: 69-64-72-123.dedicated.codero.netNS: *.dns-diy.netAS: 10316 69.64.64.0/19 CODERO-AS - CoderoSame registrar as all of the rest;Registrant: Frank Jorney / jormwyuh4@hotmail.comRegistrar: ONLINENIC, INC367u3hsl.com/files/18367u3hsl.com/files/19367u3hsl.com/files/23367u3hsl.com/files/24367u3hsl.com/files/

Thứ Bảy, 3 tháng 9, 2011

Well, yesterday Sinowall was at 108.59.2.213, as of today, there's 2 new domains and a new IP - still the same amount of files, same 71 unique MD5s;

sghlymfsbvf.com/files/18 Trojan.Agent
sghlymfsbvf.com/files/19 Trojan.Agent
sghlymfsbvf.com/files/23 Trojan.Agent
sghlymfsbvf.com/files/24 Trojan.Agent
sghlymfsbvf.com/files/25 Trojan.Agent
sghlymfsbvf.com/files/26 Trojan.Agent
sghlymfsbvf.com/files

Thứ Sáu, 2 tháng 9, 2011

Q. What do you get if you cross 108.59.2.213 with a bunch of newly created domains?

A. Over 600 newly malicious URLs of course!

There's actually only a very small amount of domains, but 91 URLs to each domain, serving a grand total across them all, of 498 files and 71 unique MD5s;

File    MD5    Size
f88deaeb24ee0ae8f783ed61c8508b37    aguyet47td.com\files\17    2.00 KB

Thứ Năm, 1 tháng 9, 2011

co.tv have had quite the history, with a plethora of abuse of their service. They've previously been responsive as far as takedowns, but lately there's been no response, and those reported over the past week, have remained active.

A lot of the domains are pointing to an IP that resolves to parking.co.tv, but this isn't actually a parking server - it is a redirector;

Query: fuqayisi.co.tv

HTTP/