Sunday, May 05, 2019

Historical OSINT - Massive Scareware-Serving Campaign Spotted in the Wild

doremisan7.net?uid=213&pid=3&ttl=319455a3f86 - 67.215.238.189

marketcoms.cn/?pid=123&sid=8ec7ca&uid=213&isRedirected=1 - 91.205.40.5 - Email: JeremyLRademacher@live.com
- MORE REDIRECTORS parked there
browsersafeon.com  A  91.205.40.5
online-income2.cn  A  91.205.40.5
applestore2.cn  A  91.205.40.5
media-news2.cn  A  91.205.40.5
clint-eastwood.cn  A  91.205.40.5
stone-sour.cn  A  91.205.40.5
marketcoms.cn  A  91.205.40.5
fashion-news.cn  A  91.205.40.5

LEADS TO
http://guard-syszone.net/?p=WKmimHVmaWyHjsbIo22EeXZe0KCfZlbVoKDb2YmHWJjOxaCbkX1%2Bal6orKWeYJWfZWVilWWenGOIo6THodjXoGJdpqmikpVuaGVvZG1kbV%2FEkKE%3D
206.53.61.73
http://www.virustotal.com/analisis/e664ff540556bcde19bb7eea967016f491bb024c3d66b455d22f1afb7bd36b3e-1256160669

http://yourspywarescan15.com/scan1/?pid=123&engine=pXT3wjTuNjYzLjE3Ny4xNTMmdGltZT0xMjUxMYkNPAFO - 85.12.24.12
http://www.virustotal.com/analisis/6e28a767b2f067285389758802e81379687f87864ecc85412e022ebe172c01d1-1256160825