BlockersNorthWe.info Another MSN Spam Domain

Hi,

Here reported a fast analysis of the latest domain catched by my MSN-HoneyPot

Today I received the following advisory by my offline contact:

Xxx scrive:
%random2% hello
http://www.BlockersNorthWe.info/ %random3%

Let’s dissect BlockersNorthWe.info

Source code for: http://www.BlockersNorthWe.info/
Server IP: 67.228.41.183 [ 67.228.41.183-static.reverse.softlayer.com ]
hpHosts Status: Not Checked
MDL Status: Not Checked
PhishTank Status: Not Checked
Date: sabato 20 dicembre 2008
Time: 18.01.52.01

<meta HTTP-EQUIV=”REFRESH” content=”0; url=http://reklam.softreklam.com/affiliates/manage.php?affid=2&o=17&c=17&d=1094″>

As you can see its used a Metarefresh = 0 that silently redirects you to

http://reklam.softreklam.com/affiliates/manage.php?affid=2&o=17&c=17&d=1094

<script language=”JavaScript”>
self.moveTo(0,0);self.resizeTo(screen.availWidth,screen.availHeight);setInterval(“x()”,10);setInterval(“y()”,500000);self.focus();
function x(){window.status=”SOHBET”}
function y(){self.focus()};
</script>

<meta http-equiv=”refresh” content=”0;url= http://www.flycell.it/offer/?ref=2900&transid=IT2“>

Another Metarefresh for http://www.flycell.it/offer/?ref=2900&transid=IT2

This is the Destination URL..

as you can understand this time we are in front off an MSN Spam Domain..

Server Type: Apache/2.2.9 (Unix) mod_ssl/2.2.9 OpenSSL/0.9.7a
mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
PHP/5.2.6
IP Address: 67.228.41.183
Whois
|

Reverse-IP
|

Ping
|

DNS Lookup
|

Traceroute

IP Location Malaysia
– Wilayah Persekutuan – Kuala Lumpur – Whei Meng Wong
Response Code: 200
Domain Status: Registered And Active Website

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: