All the posts are similar, but they come from IP addresses all over the world. Here are the latest ones:
IP address | event occured | Country |
---|---|---|
125.7.106.36 | 2011-01-25 03:15:01.097 | AUSTRALIA |
194.71.15.242 | 2011-01-25 00:15:28.947 | SWEDEN |
58.1.236.52 | 2011-01-24 23:48:23.503 | JAPAN |
62.189.102.229 | 2011-01-24 22:36:23.813 | UNITED KINGDOM |
84.170.167.1 | 2011-01-24 22:16:55.657 | |
174.133.230.40 | 2011-01-24 21:20:31.047 | UNITED STATES |
71.101.103.247 | 2011-01-24 19:31:49.997 | UNITED STATES |
186.88.170.223 | 2011-01-24 14:23:03.003 | VENEZUELA |
216.185.76.74 | 2011-01-24 08:58:20.940 | CANADA |
193.137.203.231 | 2011-01-24 06:30:30.783 | PORTUGAL |
74.121.148.3 | 2011-01-24 05:55:59.257 | UNITED STATES |
219.234.246.248 | 2011-01-24 03:32:39.443 | CHINA |
68.238.66.113 | 2010-12-09 23:07:47.327 | UNITED STATES |
202.108.50.70 | 2010-12-09 09:54:13.323 | CHINA |
190.177.66.185 | 2010-12-09 05:13:55.220 | ARGENTINA |
212.178.200.72 | 2010-12-09 05:09:22.023 | NETHERLANDS |
200.55.16.50 | 2010-12-09 05:04:51.767 | ARGENTINA |
187.9.58.194 | 2010-12-09 01:14:22.237 | BRAZIL |
212.71.32.94 | 2010-12-09 01:06:39.560 | SAUDI ARABIA |
193.56.241.125 | 2010-12-08 23:53:00.620 | FRANCE |
85.255.197.125 | 2010-12-08 21:19:54.407 | |
79.125.121.121 | 2010-12-08 17:09:40.170 | IRELAND |
The thing would not be alarming but the emails (with the java and HTML removed) are all nearly identical. They all look something like this:
Dx6CQw ccvpfvghxsko, [url=http://qdzwgbbwegwf.com/]qdzwgbbwegwf[/url], [link=http://zadpuhxlkcme.com/]zadpuhxlkcme[/link], http://yvetloauhztz.com/
Don't worry, I tried looking for these domains and they are all unregistered. The real payload of the post must have been in the HTML/JavaScript. It is my hope in posting these that some of you googling upon this page might see this and have some insight as to what the point might be. If so, please comment below.
Bryan Valencia is a contributing editor and founder of Visual Studio Journey. He owns and operates Software Services, a web design and hosting company in Manteca, California.
No comments:
Post a Comment