# # this list of ponmocup malware redirection domains and infected web-servers is maintained by # email: toms.security.stuff -at- gmail.com # twitter: @c_APT_ure # blog: http://c-apt-ure.blogspot.com/ # # for use with CIF see malware-feeds here: # http://security-research.dyndns.org/pub/malware-feeds/ # date started: Tue 11 Jul 2023 12:00:02 AM PDT checking domain: www.aca-uccle.be --> seems to be INFECTED: http://omonkhegbele.wenerdhard.com/avatar/13f845eeeca251fc34e2823d2af5c0c0 --> DNS: omonkhegbele.wenerdhard.com (omonkhegbele.wenerdhard.com) / failed: Name or service not known. checking domain: www.destrangers.org --> seems to be INFECTED: http://bidin.golfnewslouisiana.com/delivery/lg.php --> DNS: bidin.golfnewslouisiana.com (bidin.golfnewslouisiana.com) / failed: Name or service not known. checking domain: 1980622.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / failed: Name or service not known. checking domain: afag.com.br --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.242.150 checking domain: agroservis.rs --> seems to be INFECTED: http://voictoall.com/cgi-bin/r.cgi --> DNS: voictoall.com (voictoall.com) / 107.158.11.16 checking domain: avicennaglobal.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 104.26.7.37, 172.67.70.191, 104.26.6.37, / checking domain: bcrwd.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 104.26.6.37, 104.26.7.37, 172.67.70.191, / checking domain: blackcanyoncoffee.com --> seems to be INFECTED: http://mudras.jordandowney.net/__utm.gif --> DNS: mudras.jordandowney.net (mudras.jordandowney.net) / failed: Name or service not known. checking domain: blog.autourdeminuit.com --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / failed: Name or service not known. checking domain: bluewingz.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / failed: Name or service not known. checking domain: cdcookingbook.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 172.82.137.5 checking domain: desifucker.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 104.26.6.37, 104.26.7.37, 172.67.70.191, / checking domain: d-math1.com --> seems to be INFECTED: http://renolla.golfnewsnewyork.com/data/RNRoc1azVY00oW --> DNS: renolla.golfnewsnewyork.com (renolla.golfnewsnewyork.com) / failed: Name or service not known. checking domain: eniaktesting.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 172.82.137.5 checking domain: harlawacademy.org --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / failed: Name or service not known. checking domain: hdstreamangas.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 104.26.7.37, 172.67.70.191, 104.26.6.37, / checking domain: janeece.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 104.247.81.52 checking domain: kw-dl.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / failed: Name or service not known. checking domain: laserme.de --> seems to be INFECTED: https://www.domainkompetenz.de/domain/index.php --> DNS: www.domainkompetenz.de (www.domainkompetenz.de) / 94.130.190.96 checking domain: ncpo.cc --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 199.59.242.150 checking domain: nitpl.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 104.26.6.37, 104.26.7.37, 172.67.70.191, / checking domain: optipaint.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 104.26.7.37, 172.67.70.191, 104.26.6.37, / checking domain: phuongdanhvonghe.edu.vn --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / failed: Name or service not known. checking domain: pileus.fr --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 172.82.137.5 checking domain: pmmilrec.com --> seems to be INFECTED: http://elinah.midnightastronomy.com/tracker --> DNS: elinah.midnightastronomy.com (elinah.midnightastronomy.com) / failed: Name or service not known. checking domain: police.moraga.ca.us --> seems to be INFECTED: http://jesusonlynet.org/cgi-bin/r.cgi --> DNS: jesusonlynet.org (jesusonlynet.org) / 199.59.243.223 checking domain: rollingonline.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 172.67.70.191, 104.26.7.37, 104.26.6.37, / checking domain: stillcatholic.com --> seems to be INFECTED: http://zahasky.greatserviceforless.com/safe_image.php --> DNS: zahasky.greatserviceforless.com (zahasky.greatserviceforless.com) / failed: Name or service not known. checking domain: stw-eu.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / failed: Name or service not known. checking domain: swchan.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 104.26.7.37, 104.26.6.37, 172.67.70.191, / checking domain: vidimozz.com --> seems to be INFECTED: https://www.directdomains.com/profile/vidimozz.com --> DNS: www.directdomains.com (www.directdomains.com) / 104.18.27.246, 104.18.26.246 checking domain: watchourvideo.net --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / failed: Name or service not known. checking domain: webdesignfm.com --> seems to be INFECTED: https://www.hugedomains.com/domain_profile.cfm --> DNS: www.hugedomains.com (www.hugedomains.com) / 172.67.70.191, 104.26.7.37, 104.26.6.37, / checking domain: www.apmc.com.hk --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 3.211.231.130, 107.20.136.125 checking domain: www.bodasexclusivas.com --> seems to be INFECTED: http://compass.automotiveeventregistration.com/safe_image.php --> DNS: compass.automotiveeventregistration.com (compass.automotiveeventregistration.com) / 72.21.92.51 checking domain: www.elsiedesigns.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 116.202.118.107 checking domain: www.farmasanmodababy.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / failed: Name or service not known. checking domain: www.geoffwhite.ws --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / failed: Name or service not known. checking domain: www.hostal3soles.com --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 160.121.167.99 checking domain: www.log-in-verlag.de --> seems to be INFECTED: http://wcameron.powerplaycreative.com/__utm.gif --> DNS: wcameron.powerplaycreative.com (wcameron.powerplaycreative.com) / failed: Name or service not known. checking domain: www.loxsavvy.com.au --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / failed: Name or service not known. checking domain: www.mazus-art.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 116.202.118.107 checking domain: www.mywoom.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 104.247.81.52 checking domain: www.rollershop.de --> seems to be INFECTED: http://yinpou.aredietsok.com/__utm.gif --> DNS: yinpou.aredietsok.com (yinpou.aredietsok.com) / failed: Name or service not known. checking domain: www.sdfbd.org --> seems to be INFECTED: http://handsexual.com/cgi-bin/r.cgi --> DNS: handsexual.com (handsexual.com) / failed: Name or service not known. checking domain: www.therapiehyperbare.com --> seems to be INFECTED: http://tagipur.mrsstyleseeker.com/redirect --> DNS: tagipur.mrsstyleseeker.com (tagipur.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.timelessimagesmi.com --> seems to be INFECTED: http://abusalewm.exceltoner.com/pview --> DNS: abusalewm.exceltoner.com (abusalewm.exceltoner.com) / 31.210.96.158 checking domain: www.vitaminbude.de --> seems to be INFECTED: http://karepii.dealerholidayevent.com/imgres --> DNS: karepii.dealerholidayevent.com (karepii.dealerholidayevent.com) / failed: Name or service not known. checking domain: www.wonderwhistle.co.uk --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 74.208.236.107, 2607:f1c0:100f:f000::21a checking domain: www.zoeblitzer-natursteine.de --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 160.121.167.99 date finished: Tue 11 Jul 2023 12:29:49 AM PDT