Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save adamlwgriffiths/eb19e28d44fc14f1afd661239ee59eac to your computer and use it in GitHub Desktop.
Save adamlwgriffiths/eb19e28d44fc14f1afd661239ee59eac to your computer and use it in GitHub Desktop.
tr563.com malware info
<a style="z-index: 2147483647; padding: 0px; margin: 0px; cursor: default; opacity: 0.01; position: fixed; top: 0px; left: 0px; background: transparent; width: 100%; height: 100%; display: block;" href="http://piz7ohhujogi.com/click?h=Ax722bagzrmvscV2hXNSER-g860Bsl6pLE7d10jAA9ZY7fWL6G9qXT5TWJiDTaJyCQk-5mIyOJUcsoCtiQc5UUQZWFsMBJ1fXDbPzIjlLXibzaM840JIm2B7ICKSkUjB9Ktv3NPoGFcA2IAjj381XGAHXuy6kp5VmKekuEqfMgmpq3ZJjakQiACjz4ixLQiEc7w2xOmWW1TFmf2gLDBrQtxCBC0i_9X1RsHB2NR1-PhdUJUEPM5oHmIUcgB69yzU6QlO-aLLGzRkAwuESnQf4XCGijsTbS9kxdP6cgOdSfot0ayvZlFEz_6-RAXy_bdGIK4z5cUm2i8-WhoRM8vVZ7_oIXueKMOJRqpxSeLPEpucItmd7jzUaeorTj5lCqGLr_IsY2TBrBRcii3BbOMrYLpTIbkSxuTHZSD6xZYCou95_-w3B8qduRt0owus0RBPskF-r1hIATRW_5pnZY29x3Hx-HA2f2au7QZfPDpmpXiJ24N_oWxYLekOL1BcrYGGVms2Yx2faA4KmTKYlBThLjxWJtfhXuI54dv966UkkQ_mvr6VlIEdTbYKudl2hmbjvAzNVAaYPRvHvijI5kEsIFg8k5DaWtp0GHVeXzzsTiyE0-UdwVxp5AV6UFR3nbqLmyXCZ7vsXe8B7-qRIPhMMZJIYpqFHCyx8bf5-ai3jdi2vtJdgYu-DKYDfypXtts_6k2jFTisyheGs11lzwiZ-UgNA7hcagKcn95rQAUslzWKyQbhlzMAXb2gVWGRXhzPVqQS_T6idD-eKbR3O38Hm7B4l51Pg39uiclJ_cQ1ac8ey2HcBfQmxXH7NUv9PrhIJ-ojVhYEqFCeHJcN4FPN2Pg5amUkH-ge&amp;subid=g-88648758-dc961194644f45adab4bc9872e1414cd-&amp;data_test=2017051114_c&amp;data_fb=no&amp;data_rtt=973&amp;data_proto=https%3A&amp;data_ic=false&amp;data_bf=1&amp;bf=1&amp;data_fo=1&amp;fo=1&amp;data_ss=878x1436&amp;bf=1&amp;fo=1&amp;rt=14&amp;data_sid=9e856fedc7dfdc74a8b9ad7e31f08dc9" target="ld893__b3f61d1639c911e7b2f30ad033bde3ba,f_380__1494892413">&nbsp;</a>
These URLs were redirected to when I attempted to download Malware Bytes.
It attempted to download a similarly named (mb2...) executable (.exe) instead.
http://www.reimagemac.com/mac/?tracking=revz2&banner=ak%20efix%20ron%20au%20cpi%204&adgroup=direct&ads_name=direct&keyword=malwarebytes.com&context=591a431e025ed400135f9163
http://7spzz.detect.005732.xyz/PCV816advancedmacALL.html
http://7spzz.detect.005732.xyz/?sov=87986171&hid=bfndfdftfppfhfhn&&redid=39705&gsid=453&campaign_id=12&p_id=12255&id=XNSX.glob-r39705-t453&impid=de69b3ca-39cb-11e7-b4a4-12c26be3c49e
http://www.advancedmactools.com//ytz/1/?x-context=M212EVOCLQD8D83Y&utm_source=mytzcps1&utm_campaign=mytzcps1&pxl=MYT1698_MYT1663_RUNT&utm_pubid=39705&x-at=de69b3ca-39cb-11e7-b4a4-12c26be3c49e
http://eflzz.alldownloads.hapc.gdn/?sov=87986171&hid=brdndfdrtfppfhfhn&&redid=39705&gsid=453&campaign_id=12&p_id=12255&id=XNSX.glob-r39705-t453&impid=ea076c86-39cb-11e7-8b24-aa1f778d2780
http://all.shipyards.xyz/?sov=87986171&id=XNSX.glob-r39705-t453-&tov=637816&v=&hid=bjdnfjdrtfppfhfhn&mov=downloads.mini&redid=39705&redid=39705&campaign_id=12&gsid=453&p_id=12255&impid=ea076c86-39cb-11e7-8b24-aa1f778d2780&noexpand=1&alert=1&audio=1&pop=1
http://all.shipyards.xyz/PCV816advancedmacALL.html
http://piz7ohhujogi.com/click?h=Ax722bagzrmkZb2UbLg_-RhE6fgoCXWgwR_KRukUOrej8X-L1NMpgzyvTo9UAzOQVx6AGAgchnJi8rs1rekkopdLnqNnVF1-dCPZ_khpIDum_4gH6M0r4QjvMvoUQQQDkK6JHI1AjJsznlCOE18K1JmPCtnQaD-RXcH465TAnszEZfKYFCTx02N6wOVABoGVjuyR6QJuMyFAxzAzyHjDxxkR65L6JlFbzMR0CsKOW2Hz43laZeu9pzzAYTzFkd_jWYQAYguP7BMpbYax81FZG9wgpHjjdtF6SrxElPYFR_WgZcKRNtRHdXlsW6RZfyc4MhT-zj-oXgHNl8d-7fGb_cyQ1OIcjyGty0LhHlXaymE_u56IU3IUp3Pz2dh3q_eG1hCiaSfvJVKKc0D5KysrEWPSmxyVD_D7QlM8j-hNjdPx04z9cGyCtgWIjss5rJU6DrUMfv2wXksDaBbmpGJd0VwgtGXxQzCKCwpL7TfPliOe19SsTMKTPyBHwt79Fnf69Vt-1qZsRXaP3C9TEMJ_rg7QtyIASeQCjFu2_EQwWUa0q4nO0A8xFGDtMjrvu7iGnUjM4XNWa7UsRxWRYGMlAJ9yZBvfbROFAlUQCt2Sps5YPRhQU2DmiRc5D4zLCeFsznuBV7rgqCP5pUGRuEtL-s_svOZGKqlJKyoA-vM3Bs8yc4d04KpnmJYpCZoArid_ZjGuUuXkWsa23qHAzDVRU0blf5i8sY3D-bdiP0JUnkQg6Dfhm4FcB366x3AvEHVlEnaxZtFGSLdHXKl4OfVpc-5BGwKKwxISQxawy4jajAL1jp2wSY_XHU6YIG-Ezui8dyrwIwcYsEqK_Af6Jq7Uo57PYJ3SqNDh&subid=g-88648758-0833e68c8b6a4af9a267715bace8189a-&data_test=2017051114_c&data_fb=no&data_rtt=1295&data_proto=https%3A&data_ic=false&data_ss=878x1436&t=https%3A%2F%2Fnews.ycombinator.com%2Fuser%3Fid%3Dcompumike&rt=98525&data_sid=9e856fedc7dfdc74a8b9ad7e31f08dc9
http://zrryzi.com/mc/total10.htm?ip=49.188.8.62&os=OS%20X&browser=Chrome&isp=Optus%20Internet&voluumdata=BASE64dmlkLi4wMDAwMDAwMi0yYzNkLTQxMWItODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjM4ZjM1ODAwLTM5YzItMTFlNy04ZWFlLTQ4MWJmMzNlNGJkMV9fY2FpZC4uZWE3MTlhYzMtMGMxMS00YTVmLWE4MGMtYjljNjUzNTMzZDYzX19ydC4uUl9fbGlkLi5jODA4Mzg2Yy1iNzZjLTQ3MjItODUxZC0yMDQ3Y2NhODhiMjlfX29pZDEuLmVkNTE0NzAwLWQ3OGItNGZhMC04YjE4LTE4ZTYwMjQ3OWE0OV9fdmFyMS4ubmV3c1wuXHljb21iaW5hdG9yXC5cY29tX192YXIyLi4ocnVuIG9mIG5ldHdvcmspX192YXIzLi4yMzQ3X192YXI0Li44ODY0ODc1OF9fdmFyNS4uNTBfX3ZhcjYuLntvZmZlcn1fX3ZhcjcuLjQ5NDYzMDkwX192YXI4Li4wX192YXI5Li5jcjU3X19yZC4uX19haWQuLl9fYWIuLl9fc2lkLi5fX2NyaS4uX19wdWIuLl9fZGlkLi5fX2RpdC4uX19waWQuLl9faXQuLl9fdnQuLjE0OTQ4OTI0MTE0Njc&domain=news.ycombinator.com&target=(run%20of%20network)&pid=2347&zone=88648758&channel=50&offer={offer}&domain_id=49463090&hindsight=0&bid=0.005&click_id=3343108dbf0448c6a59f9d925a6c1e3d
http://piz7ohhujogi.com/click?h=Ax722bagzrmvscV2hXNSER-g860Bsl6pLE7d10jAA9ZY7fWL6G9qXT5TWJiDTaJyCQk-5mIyOJUcsoCtiQc5UUQZWFsMBJ1fXDbPzIjlLXibzaM840JIm2B7ICKSkUjB9Ktv3NPoGFcA2IAjj381XGAHXuy6kp5VmKekuEqfMgmpq3ZJjakQiACjz4ixLQiEc7w2xOmWW1TFmf2gLDBrQtxCBC0i_9X1RsHB2NR1-PhdUJUEPM5oHmIUcgB69yzU6QlO-aLLGzRkAwuESnQf4XCGijsTbS9kxdP6cgOdSfot0ayvZlFEz_6-RAXy_bdGIK4z5cUm2i8-WhoRM8vVZ7_oIXueKMOJRqpxSeLPEpucItmd7jzUaeorTj5lCqGLr_IsY2TBrBRcii3BbOMrYLpTIbkSxuTHZSD6xZYCou95_-w3B8qduRt0owus0RBPskF-r1hIATRW_5pnZY29x3Hx-HA2f2au7QZfPDpmpXiJ24N_oWxYLekOL1BcrYGGVms2Yx2faA4KmTKYlBThLjxWJtfhXuI54dv966UkkQ_mvr6VlIEdTbYKudl2hmbjvAzNVAaYPRvHvijI5kEsIFg8k5DaWtp0GHVeXzzsTiyE0-UdwVxp5AV6UFR3nbqLmyXCZ7vsXe8B7-qRIPhMMZJIYpqFHCyx8bf5-ai3jdi2vtJdgYu-DKYDfypXtts_6k2jFTisyheGs11lzwiZ-UgNA7hcagKcn95rQAUslzWKyQbhlzMAXb2gVWGRXhzPVqQS_T6idD-eKbR3O38Hm7B4l51Pg39uiclJ_cQ1ac8ey2HcBfQmxXH7NUv9PrhIJ-ojVhYEqFCeHJcN4FPN2Pg5amUkH-ge&subid=g-88648758-dc961194644f45adab4bc9872e1414cd-&data_test=2017051114_c&data_fb=no&data_rtt=973&data_proto=https%3A&data_ic=false&data_bf=1&bf=1&data_fo=1&fo=1&data_ss=878x1436&bf=1&fo=1&rt=248188&data_sid=9e856fedc7dfdc74a8b9ad7e31f08dc9
http://helpmymacfaster.trade/landings/197/?affid=mzb_309.30805910.1494892663.28.mzb&utm_source=zrprk&utm_medium=cpm&utm_campaign=mk_zrprk_pop_src_wl_au&utm_term=&utm_content=&userDefiner=mzb_2950&alert=13&trt=29_313511156&tid_ext=mike-wed-IWhmtQR8;zvb3f6b8b539c911e782bf128963222f2abbf51da004214b3498bd95767386ed4a020783a35f5154478b;lateritious-cod&redirect=loadblue
http://piz7ohhujogi.com/click?h=Ax722bagzrl7EWGSWO7crS1fZBD4lcWXkU9DdZjBJijULFg7lId-X3GKWXZAJkkwlIbPMqDs2Ro9J09pVHS3mLtBWx5QwPPET7CEhwAoLT5qiac6SWjQc0q0Ai5mS_M7QkF2oehBovPrvsxEJLi8qRC8iwcmVFUYqwqnRa-6oCqhyeYooG5GMmvwmz3rt4SpRuPoWKeYt3Pg6KXG1x9yOE3cLNpvySlZo82hfuIxiWYkbRXU-pRetHHSwAVYCVu1LR2GerY-I8W2dy8hGD9PH_wD5HWcFQfc5pwdHI1Rg3FTikUzyDHL_2E2XNkoJdlXcxHOaWITyV1EB-76EIc0pDg5lFa-FTg4klV5SVg-Ba7THZf8hI6W4bM-4KiGR_-eJTvCs_hN8-WNtA2AY0MQh1IjvdBpVfDeMlNPEBnZ-9KtncO7Y3LqnSn4MKfGGm7FWzd_lJplLOxzf5CLJs0QcdPGLqULoK88oJne22LSIP8S8i8z6BM-ac2Q2zEXqaR2Q9-3VX_yCxeNBNk-DbhGspUSNmcdEeLsBbOaqeN0dAJFPPGEy-_2JVugPRY7ZY4En0T-yhzaln0Y3ku0FIgbtblpVAJ0kMyu9Vv83fdK3U_gCO0271hJpvgLH6sjd6kZWjxQIHZwd53-w9p3OGaJiWgd-cJYqydHsIXgp5U2Xt_Wg0oVPXcQw_Gd55-SK7cv-zj6VKhVeq0M-MKRuIhtwXPfVqPII-HG9US1Iz_QHPXlE9eDhtADYipW9PS93HhTnSE8nQOTqkiaiN8TxhUXXnxl4F6LuOLVpEPcB9YG2TddYwsi-Bg5VRAeu7MhAy3ip3ilp5PTKlcqNEkoQBVv3dt2PbfOLrza9DsOtIFY5EwnGv5w-SzLuX_EgE7HpDtFY26bZ1-ZKte8HHr9uFaUmhcne_0UhGlJ4FmKGncLwEeZMod41Qh7tCbHomHseMmLPOCrxI34D9Bet-cbB3ehu57PYJ3SqNDh&subid=g-88648758-00025d22f5ca4a848ba552bc1c20260d-&data_test=2017051114_c&data_fb=no&data_rtt=1250&data_proto=https%3A&data_ic=false&data_ss=878x1436&rt=25504&data_sid=9e856fedc7dfdc74a8b9ad7e31f08dc9
http://mysearches.ga/base.php?c=177&key=e78a4bc1b4de54aa1e8a7c09a30087cd&keyword=malwaretips.com&tid=619683&domainid=malwaretips.com&campid=1870092&cid=1663493&clickid=ead3f7195e6e4da187b991070e747930countryid=AU
http://mysearches.ga/baseredirect.php?url=%3A%2F%2Fgothrgh.pro%2F%3Ftarget%3D-4AAKYIAJSBgAAAAAAAAAAAAT9tkI3AA%26subacc%3D%7Btarget_id%7D%26subacc2%3D%7Bcampaign_id%7D%26subacc3%3D%7Bclick_id%7D%26subacc4%3D%7Bcountry%7Dvqq0gnlo_177_129929%26clcsr%3D1
http://gothrgh.pro/?target=-4AAKYIAJSBgAAAAAAAAAAAAT9tkI3AA&subacc={target_id}&subacc2={campaign_id}&subacc3={click_id}&subacc4={country}vqq0gnlo_177_129929&clcsr=1
http://app3.letmacwork.world/landings/123.14/?affid=mzb_429.4215731.1494893273.30.mzb&utm_source=dcmb&utm_medium=cpi&utm_campaign=mk_dcmb_cpi_t1_12314&utm_term=&utm_content=&userDefiner=mzb_2832&alert=13&trt=29_3114511156&tid_ext=a3e115353f46908297e8d00e98d5273a;-4A25sMQKYIAJSBgRH-ze_AAEAAQAC3wUBAAEAAdsC5AQEc4FzqQA
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment