infernomag.com then redirects users to one of at least two Leaseweb-hosted servers at 85.17.19.201 and 85.17.19.203 (possibly others). These servers have a number of domains on them that appear to belong to legitimate domains registered at GoDaddy by (mostly) UK users - it is likely that their domain control panels have been compromised. Examples are:
actually2.weddingphotographersurrey.net
amount9.gwdempseyjr.com
are5.gwdempseyjr.com
background1.photographbcn.com
brought0.gwdempseyjr.com
captain5.photographbcn.com
captain6.gwdempseyjr.com
charge7.photographbcn.com
signal6.photographbcn.com
completely8.gwdempseyjr.com
congress1.airduct-ventcleaning-mn.com
hard9.photographbcn.com
leading1.airduct-ventcleaning-mn.com
party4.gwdempseyjr.com
providence5.gwdempseyjr.com
safe1.gwdempseyjr.com
she1.weddingphotographerkent.net
tax6.weddingphotographersurrey.net
theory7.weddingphotographerkent.net
am1.theimperialsuspects.com
area6.bettyjaneware.com
belief7.theimperialsuspects.com
contact2.theimperialsuspects.com
cultural5.boneki.com
direct2.theimperialsuspects.com
enemy2.theimperialsuspects.com
baby3.trycue.com
liberal6.trycue.com
most0.ladyofvirtuestore.com
professional0.ladyofvirtuestore.com
Two domains on those servers that do not fit the pattern are:
gfaster.net
fortreecom.net
The WHOIS details are probably fake, for infernomag.com and gtracking.org they are:
Felix Maurer
sherman66@ymail.com
Waldowstr. 61
Gschwend Gschwend
74417 DE
+49 98466101
sherman66@ymail.com
Waldowstr. 61
Gschwend Gschwend
74417 DE
+49 98466101
fortreecom.net uses the same email address but a different name:
Bernd Austerlit (sherman66@ymail.com)
Alt Reinickendorf 94
Ziemetshausen
Bayern,86471
DE
Tel. +82.84991251
Alt Reinickendorf 94
Ziemetshausen
Bayern,86471
DE
Tel. +82.84991251
Detection rates are rubbish. AntiVir detects the payload as TR/Dropper.Gen, BitDefender as Gen:Variant.Zbot.34, Ikarus as Trojan.Win32.Pirminay and Sophos as Mal/Ponmocup-A. Other products do not seem to detect anything at all.
Blocking those IPs of 85.17.132.194, 85.17.19.201 and 85.17.19.203 is safer than trying to block the domains. Blocking the whole /24s instead would probably cause very little inconvenience.
1 comment:
Yea I have been having issues with this infernomag.com things for a two or three months now.
My tech guy has tried to clean ti and I even have service at wewatchyourwebsite.com and the hacker keeps injecting .htcacess files into my FTP. I have scanned my PC for malware and am using new and difficult passwords. I copy and paste the passwords on my PC and do not type them in.
And now today my site is suspended even until they can figure out what to do.
All the fun has been taken out of blogging for em really by this sort of thing.
Bill
Post a Comment