WARNING: All sites listed on this page are dangerous (live URL with exploits) which lead to trojans beeing automatically installed on your computer. Do NOT visit them unless you know what you are doing. (only links are safe)
Another very good example on the site below which lead to other domain in the network previously cited "Eurohost LLC " shows that this attack seems to be everywhere.
IFrames injected, pdf malware + viruses. Attached some screenshots.
Infected page:
hxxp://team-sleep.by.ru/default2.html |
Analysis
hxxp://8addition.info/t/?75724cae9d hxxp://sexbases.cn/in.cgi?16&161b72 hxxp://utevox.site90.com/f/index.php |

************ Infected page:
hxxp://team-sleep.by.ru/demo.html |
Analysis
Requests:
hxxp://bizoplata.ru/pay.html? hxxp://bizoplata.ru/ballast.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://bizoplata.ru/post.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://mixbunch.cn/bowling.html hxxp://famajormusic.ru/jjkj/pdf.php |
Redirects:
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php |

************ Infected page: hxxp://team-sleep.by.ru/gold.html |
Analysis
Requests:
hxxp://team-sleep.by.ru/gold.html hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php |
Redirects:
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php |

************ Infected page: hxxp://team-sleep.by.ru/googleanalyticsru.html |
Analysis
Requests:
hxxp://team-sleep.by.ru/googleanalyticsru.html hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://sunmaiamibich.ru/ |
Redirects: hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php |

************ Infected page:
hxxp://team-sleep.by.ru/media.html |
Analysis
Requests: hxxp://team-sleep.by.ru/media.html hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php |
Redirects:
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php |

************ Infected page: hxxp://team-sleep.by.ru/menu.html |
Analysis
Requests:
hxxp://team-sleep.by.ru/menu.html hxxp://bizoplata.ru/pay.html? hxxp://bizoplata.ru/ballast.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://bizoplata.ru/post.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://mixbunch.cn/bowling.html |
Redirects:
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php |

************ Infected page: hxxp://team-sleep.by.ru/news.html |
Analysis
Requests:
hxxp://moneypuller.site90.net/images/gallery/index.php hxxp://error.000webhost.com/not_found.html hxxp://www.000webhost.com/?id=1 hxxp://www.000webhost.com/ hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php |
Redirects:
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php |

************ Infected page: hxxp://team-sleep.by.ru/photo2.html |
Analysis
Requests:
hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php hxxp://bizoplata.ru/pay.html? hxxp://bizoplata.ru/ballast.html hxxp://bizoplata.ru/post.html hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php |
Redirects:
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php |

************ Infected page: hxxp://team-sleep.by.ru/poem.html |
Analysis
Requests:
hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php hxxp://bizoplata.ru/pay.html? hxxp://bizoplata.ru/ballast.html hxxp://bizoplata.ru/post.html |
Redirects:
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php |

************ Infected page:
hxxp://team-sleep.by.ru/press_reviews.html |
Analysis
Requests:
hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php |
Redirects:
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php |

************ Infected page:
hxxp://team-sleep.by.ru/team-sleep.html |
Anaysis
Redirects:
hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php |
Redirects:
hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php
|

************ Infected page:
hxxp://team-sleep.by.ru/gmail.php
|
Analysis
Requests:
hxxp://counnter.cn/top100_00.js hxxp://counnter.cn/z/count.php?o=1 hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php
|
Redirects:
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php
|

************ Infected page:
hxxp://team-sleep.by.ru/haitou.php
|
Analysis
Requests:
hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php
|
************ Infected page:
hxxp://team-sleep.by.ru/in.php
|
Analysis
Requests:
hxxp://www.rogercombs.org/index.php hxxp://5rublei.com/unique/index.php hxxp://tochtonenado.com/yes/index.php
|
************ Infected page:
hxxp://team-sleep.by.ru/photo/team.html
|
Analysis
Requests:
hxxp://analytics-google.info/s/urchin.js hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php hxxp://77.221.133.172/.if/go.html? hxxp://by.ru/info/?where
|
************ Infected page:
hxxp://team-sleep.by.ru/photo/wallz.html
|
Analysis
Requests:
hxxp://analytics-google.info/s/urchin.js hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php hxxp://bizoplata.ru/pay.html? hxxp://bizoplata.ru/ballast.html hxxp://bizoplata.ru/post.html hxxp://by.ru/info/?where
|
************ Infected page:
hxxp://team-sleep.by.ru/photo/live/index2.html
|
Analysis
Requests:
hxxp://utevox.site90.com/f/index.php hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php
|
************ Infected page:
hxxp://team-sleep.by.ru/photo/live/imagepages/image1.html
|
AnalysisRequests:
hxxp://analytics-google.info/s/urchin.js hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php
|
************ Infected page:
hxxp://team-sleep.by.ru/photo/members/imagepages/image1.html
|
Analysis Requests:
hxxp://analytics-google.info/s/urchin.js hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php
|
************ Infected page:
hxxp://team-sleep.by.ru/photo/team/imagepages/image1.html
|
Analysis On this page the domain appears to be previously involved in the Asprox malware campaign. As you can see the fgg.js and script.js are still present on the page.
However all of these are not responding. Finjan report Google Searchfor fgg.js Google Search for www.netcfg9.ru
hxxp://www.jve4.ru/fgg.js hxxp://www.nmr43.ru/fgg.js hxxp://www.mj5f.ru/script.js hxxp://www.vswc.ru/script.js hxxp://www.pkseio.ru/script.js hxxp://www.4log-in.ru/script.js hxxp://www.netcfg9.ru/script.js hxxp://www.sitevgb.ru/script.js hxxp://www.errghr.ru/script.js hxxp://www.81dns.ru/script.js hxxp://mixbunch.cn/thread.html hxxp://mixbunch.cn/golf.html hxxp://tixwagoq.cn/in.cgi?4 hxxp://paylayos.cn/nuc/index.php hxxp://mixbunch.cn/bowling.html hxxp://sunmaiamibich.ru/pupu/in.php hxxp://famajormusic.ru/jjkj/pdf.php

************ Infected page: hxxp://tochtonenado.com/yes/index.php hxxp://tochtonenado.com/yes/load.php?stat=Windows Analysis
Trojan Waledac.GEN Anubis Report Botnet Controller 89.149.244.140:80 - [djbobroff.ru] Request: GET /spm/index.php?id=584E5E43 Response: 200 "OK" Request: GET /spm/index.php?id=584E5E43&download=0000138F Response: 200 "OK" Request: POST /spm/index.php?id=584E5E43&mid=5007 Response: 200 "OK"
C:\WINDOWS\system32\DRIVERS\asyncmac.sys
***************** Exploits:
91.212.41.91
hxxp://mixbunch.cn hxxp://sunmaiamibich.ru |
91.212.65.7
95.129.144.228
hxxp://5rublei.com hxxp://dasretokfin.com hxxp://tochtonenado.com |
95.129.144.13
hxxp://bizoplata.ru hxxp://startdontstop.ru
|
64.235.52.170
************************
Domain Name: mixbunch.cn ROID: 20081108s10001s82359461-cn Domain Status: clientTransferProhibited Registrant Organization: Raymond Keaton Registrant Name: Raymond Keaton Administrative Email: Keaton@cybernauttech.com Sponsoring Registrar: 广东时代互联科技有限公司 Name Server:ns1.softwaresupport-group.com Name Server:ns2.softwaresupport-group.com Registration Date: 2008-11-08 16:06 Expiration Date: 2009-11-08 16:06
domain: sunmaiamibich.ru type: CORPORATE nserver: ns1.softwaresupport-group.com. nserver: ns2.softwaresupport-group.com. state: REGISTERED, DELEGATED person: Private person phone: +7 910 3478712 e-mail: dmitrijstanislavskij@yandex.ru registrar: REGRU-REG-RIPN created: 2009.04.16 paid-till: 2010.04.16 source: TC-RIPN
Domain Name: peskufex.cn ROID: 20090315s10001s50367993-cn Domain Status: clientDeleteProhibited Domain Status: clientTransferProhibited Registrant Organization: 永也进出口公司 Registrant Name: 张龙 Administrative Email: alvin_555@yeah.net Sponsoring Registrar: 易名中国 Name Server:ns2.dnsmytruedns.com Name Server:ns1.dnsmytruedns.com Registration Date: 2009-03-15 15:37 Expiration Date: 2010-03-15 15:37Domain Name: 5rublei.com Registrar: BIZCN.COM, INC. Whois Server: whois.bizcn.com Referral URL: http://www.bizcn.com Name Server: NS1.EVERYDNS.NET Name Server: NS2.EVERYDNS.NET Name Server: NS3.EVERYDNS.NET Name Server: NS4.EVERYDNS.NET Status: clientDeleteProhibited Status: clientTransferProhibited Updated Date: 31-mar-2009 Creation Date: 30-jun-2008 Expiration Date: 30-jun-2010
Domain Name: dasretokfin.com Registrar: REGTIME LTD. Whois Server: whois.regtime.net Referral URL: http://www.webnames.ru Name Server: NS1.AFRAID.ORG Name Server: NS2.AFRAID.ORG Name Server: NS3.AFRAID.ORG Name Server: NS4.AFRAID.ORG Status: ok Updated Date: 24-mar-2009 Creation Date: 18-feb-2009 Expiration Date: 18-feb-2010
Domain Name: tochtonenado.com Registrar: UK2 GROUP LTD. Whois Server: whois.hostingservicesinc.net Referral URL: http://www.uk2group.com/ Name Server: NS1.EVERYDNS.NET Name Server: NS2.EVERYDNS.NET Name Server: NS3.EVERYDNS.NET Name Server: NS4.EVERYDNS.NET Status: clientTransferProhibited Updated Date: 25-mar-2009 Creation Date: 25-mar-2009 Expiration Date: 25-mar-2010
domain: bizoplata.ru type: CORPORATE nserver: ns1.sevensearchon.ru nserver: ns2.sevensearchon.ru state: REGISTERED, DELEGATED person: Private Person phone: +7 495 0000000 e-mail: tuhov83@mail.ru registrar: CT-REG-RIPN created: 2009.01.23 paid-till: 2010.01.23 source: TC-RIPN
domain: startdontstop.ru type: CORPORATE nserver: ns1.sevensearchon.ru. nserver: ns2.sevensearchon.ru. state: REGISTERED, DELEGATED person: Private Person phone: +7 916 7843219 e-mail: ale32888049@yandex.ru registrar: NAUNET-REG-RIPN created: 2009.04.14 paid-till: 2010.04.14 source: TC-RIPN
|