# # this list of ponmocup malware redirection domains and infected web-servers is maintained by # email: toms.security.stuff -at- gmail.com # twitter: @c_APT_ure # blog: http://c-apt-ure.blogspot.com/ # # for use with CIF see malware-feeds here: # http://security-research.dyndns.org/pub/malware-feeds/ # date started: Tue May 5 12:00:02 PDT 2020 checking domain: www.jacquestrifin.be --> seems to be INFECTED: http://golfforkids.assistlist.com/fpc.pl --> DNS: golfforkids.assistlist.com (golfforkids.assistlist.com) / 18.211.9.206 checking domain: upetterbeek.be --> seems to be INFECTED: http://seelback.tfgjustsayin.net/avatar/b8805389ee4391c3f8f9b91ce3cf11b9 --> DNS: seelback.tfgjustsayin.net (seelback.tfgjustsayin.net) / failed: Name or service not known. checking domain: www.dynasun.com --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / failed: Name or service not known. checking domain: www.aca-uccle.be --> seems to be INFECTED: http://omonkhegbele.wenerdhard.com/t.gif --> DNS: omonkhegbele.wenerdhard.com (omonkhegbele.wenerdhard.com) / 31.210.96.155 checking domain: www.upetterbeek.be --> seems to be INFECTED: http://seelback.tfgjustsayin.net/s --> DNS: seelback.tfgjustsayin.net (seelback.tfgjustsayin.net) / failed: Name or service not known. checking domain: 1980622.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 184.168.221.74 checking domain: afag.com.br --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 154.194.2.173 checking domain: agirazul.com.br --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / failed: Name or service not known. checking domain: agroservis.rs --> seems to be INFECTED: http://voictoall.com/cgi-bin/r.cgi --> DNS: voictoall.com (voictoall.com) / failed: Name or service not known. checking domain: arlington.ph --> seems to be INFECTED: http://simcast.com --> DNS: simcast.com (simcast.com) / 173.230.130.175 checking domain: avionhome.com.tw --> seems to be INFECTED: http://intronetech.com/cgi-bin/r.cgi --> DNS: intronetech.com (intronetech.com) / 216.127.180.149 checking domain: blackcanyoncoffee.com --> seems to be INFECTED: http://mudras.jordandowney.net/s --> DNS: mudras.jordandowney.net (mudras.jordandowney.net) / failed: Name or service not known. checking domain: blog.autourdeminuit.com --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / failed: Name or service not known. checking domain: bluewingz.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 204.11.56.48 checking domain: cdcookingbook.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 103.224.182.228 checking domain: eniaktesting.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 103.224.182.228 checking domain: espn-la.com --> seems to be INFECTED: http://guillaran.newcarsat.com/new2/www/delivery/lg.php --> DNS: guillaran.newcarsat.com (guillaran.newcarsat.com) / failed: Name or service not known. checking domain: exclusivesms.com --> seems to be INFECTED: http://ifteiha.lions-mark.com/s --> DNS: ifteiha.lions-mark.com (ifteiha.lions-mark.com) / 204.11.56.48 checking domain: ezkahuda.cz --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.177.51 checking domain: harlawacademy.org --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 181.214.86.147 checking domain: janeece.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 185.53.177.52 checking domain: kw-dl.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 184.168.221.82 checking domain: laserme.de --> seems to be INFECTED: https://www.domainkompetenz.de/domain/index.php --> DNS: www.domainkompetenz.de (www.domainkompetenz.de) / 62.26.9.51 checking domain: ncpo.cc --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 154.194.2.173 checking domain: perca.pl --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 184.168.221.79 checking domain: php2.twinner.com.tw --> seems to be INFECTED: http://36865.flatblastard.com/url --> DNS: 36865.flatblastard.com (36865.flatblastard.com) / 91.207.4.51 checking domain: phuongdanhvonghe.edu.vn --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / failed: Name or service not known. checking domain: pileus.fr --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 103.224.182.228 checking domain: pmmilrec.com --> seems to be INFECTED: http://elinah.midnightastronomy.com/t.gif --> DNS: elinah.midnightastronomy.com (elinah.midnightastronomy.com) / 31.210.96.155 checking domain: police.moraga.ca.us --> seems to be INFECTED: http://clubshop.boeckman.net/f.gif --> DNS: clubshop.boeckman.net (clubshop.boeckman.net) / failed: Name or service not known. checking domain: sseo.elk.pl --> seems to be INFECTED: http://gensapa.valentinesalesevent.com/imghover --> DNS: gensapa.valentinesalesevent.com (gensapa.valentinesalesevent.com) / failed: Name or service not known. checking domain: stw-eu.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / failed: Name or service not known. checking domain: syrena.gminanekla.pl --> seems to be INFECTED: http://apartliberal.com/cgi-bin/r.cgi --> DNS: apartliberal.com (apartliberal.com) / 204.11.56.48 checking domain: watchourvideo.net --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / failed: Name or service not known. checking domain: wbu.wroc.pl --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 154.194.2.173 checking domain: workpanel.de --> seems to be INFECTED: http://creighton.wenerdhard.com/new2/www/delivery/lg.php --> DNS: creighton.wenerdhard.com (creighton.wenerdhard.com) / 31.210.96.155 checking domain: www.actiogen.com --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 181.214.86.147 checking domain: www.alnimrexpo.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 103.224.182.228 checking domain: www.apmc.com.hk --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 69.164.223.52, 2600:3c03:1::45a4:df34 checking domain: www.bodasexclusivas.com --> seems to be INFECTED: http://compass.automotiveeventregistration.com/__utm.gif --> DNS: compass.automotiveeventregistration.com (compass.automotiveeventregistration.com) / 72.21.92.51 checking domain: www.comune.santa-maria-capua-vetere.ce.it --> seems to be INFECTED: http://gesneriaceae.telecomillinois.com/pview --> DNS: gesneriaceae.telecomillinois.com (gesneriaceae.telecomillinois.com) / failed: Name or service not known. checking domain: www.creatingyourfreedom.com --> seems to be INFECTED: /redirect.php --> DNS: www.awesomedomains.com (www.awesomedomains.com) / 13.225.146.8, 13.225.146.106, 13.225.146.75, / checking domain: www.doctorhelp.de --> seems to be INFECTED: http://switchett.virtualsofts.com/delivery/ajs.php --> DNS: switchett.virtualsofts.com (switchett.virtualsofts.com) / 173.239.8.164, 173.239.5.6 checking domain: www.dreamboxturk.com --> seems to be INFECTED: http://baylet.autoeventregistration.com/api/getCount2.php --> DNS: baylet.autoeventregistration.com (baylet.autoeventregistration.com) / failed: Name or service not known. checking domain: www.dulceselsombreron.com --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / failed: Name or service not known. checking domain: www.elsiedesigns.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 185.53.177.50 checking domain: www.enimex.gr --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 184.168.221.74 checking domain: www.farmasanmodababy.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 204.11.56.48 checking domain: www.fatherlinh.com --> seems to be INFECTED: http://germanattention.org/cgi-bin/r.cgi --> DNS: germanattention.org (germanattention.org) / 137.220.156.252 checking domain: www.freesure.com.tr --> seems to be INFECTED: http://earlyanswered.com/cgi-bin/r.cgi --> DNS: earlyanswered.com (earlyanswered.com) / 204.11.56.48 checking domain: www.freilandschwein.info --> seems to be INFECTED: http://earlyanswered.com/cgi-bin/r.cgi --> DNS: earlyanswered.com (earlyanswered.com) / 204.11.56.48 checking domain: www.geoffwhite.ws --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / failed: Name or service not known. checking domain: www.greenfieldadvisorsltd.com --> seems to be INFECTED: http://moutsiouna.iretarpg.com/t.gif --> DNS: moutsiouna.iretarpg.com (moutsiouna.iretarpg.com) / failed: Name or service not known. checking domain: www.highsport.se --> seems to be INFECTED: http://udomchum.telecommichigan.com/api/getCount2.php --> DNS: udomchum.telecommichigan.com (udomchum.telecommichigan.com) / failed: Name or service not known. checking domain: www.hostal3soles.com --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 183.90.228.14 checking domain: www.hostpix.de --> seems to be INFECTED: http://xlau.kalkanturqouise.com/dcsis0ifv10000gg3ag82u4rf_7b1e/dcs.gif --> DNS: xlau.kalkanturqouise.com (xlau.kalkanturqouise.com) / failed: Name or service not known. checking domain: www.jalba.gr --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 107.163.58.12 checking domain: www.jtcomms.com --> seems to be INFECTED: http://solichana.telecommichigan.com/safe_image.php --> DNS: solichana.telecommichigan.com (solichana.telecommichigan.com) / failed: Name or service not known. checking domain: www.larcheedmonton.org --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 69.164.223.52, 2600:3c03:1::45a4:df34 checking domain: www.log-in-verlag.de --> seems to be INFECTED: http://wcameron.powerplaycreative.com/pview --> DNS: wcameron.powerplaycreative.com (wcameron.powerplaycreative.com) / failed: Name or service not known. checking domain: www.mazus-art.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 185.53.177.50 checking domain: www.msm.mc --> seems to be INFECTED: http://poserio.thecaregrouppc.net/b --> DNS: poserio.thecaregrouppc.net (poserio.thecaregrouppc.net) / 104.247.81.100 checking domain: www.mywoom.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 185.53.177.52 checking domain: www.nwd-ly.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 204.11.56.48 checking domain: www.oo5.com --> seems to be INFECTED: http://uglyugly.savedalyfield.com/s --> DNS: uglyugly.savedalyfield.com (uglyugly.savedalyfield.com) / failed: Name or service not known. checking domain: www.rollershop.de --> seems to be INFECTED: http://yinpou.aredietsok.com/_xhr/ugccomments/ --> DNS: yinpou.aredietsok.com (yinpou.aredietsok.com) / failed: Name or service not known. checking domain: www.santuariodalapa.pt --> seems to be INFECTED: http://tixon.theafternoonjoker.com/api/getCount2.php --> DNS: tixon.theafternoonjoker.com (tixon.theafternoonjoker.com) / 31.210.96.158 checking domain: www.sdfbd.org --> seems to be INFECTED: http://handsexual.com/cgi-bin/r.cgi --> DNS: handsexual.com (handsexual.com) / 184.168.131.241 checking domain: www.sri.cmu.ac.th --> seems to be INFECTED: http://twansha.yourcakedecoratingclass.com/t.gif --> DNS: twansha.yourcakedecoratingclass.com (twansha.yourcakedecoratingclass.com) / failed: Name or service not known. checking domain: www.successinteaching.info --> seems to be INFECTED: http://protechere.com/cgi-bin/r.cgi --> DNS: protechere.com (protechere.com) / 154.208.190.110 checking domain: www.therapiehyperbare.com --> seems to be INFECTED: http://tagipur.mrsstyleseeker.com/delivery/lg.php --> DNS: tagipur.mrsstyleseeker.com (tagipur.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.timelessimagesmi.com --> seems to be INFECTED: http://abusalewm.exceltoner.com/gampad/ads --> DNS: abusalewm.exceltoner.com (abusalewm.exceltoner.com) / 31.210.96.158 checking domain: www.vfbhermsdorf.de --> seems to be INFECTED: http://hinouchi.greatserviceforless.com/gadgets/ifr --> DNS: hinouchi.greatserviceforless.com (hinouchi.greatserviceforless.com) / failed: Name or service not known. checking domain: www.vitaminbude.de --> seems to be INFECTED: http://karepii.dealerholidayevent.com/__utm.gif --> DNS: karepii.dealerholidayevent.com (karepii.dealerholidayevent.com) / failed: Name or service not known. checking domain: www.wallyontheweb.com --> seems to be INFECTED: http://ichinohe.casabodamia.com/b --> DNS: ichinohe.casabodamia.com (ichinohe.casabodamia.com) / failed: Name or service not known. checking domain: www.wonderwhistle.co.uk --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 208.91.197.46 checking domain: www.zoeblitzer-natursteine.de --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 183.90.228.14 date finished: Tue May 5 12:28:20 PDT 2020