last data update: 2011/10/15, 06:50

Website loading time

during the test: 1.99 s

cable connection (average): 2.41 s

DSL connection (average): 2.83 s

modem (average): 24.92 s

HTTP headers

Information about DNS servers

contagiodump.blogspot.comCNAMEblogspot.l.google.comIN3600

Received from the first DNS server

Received from the second DNS server

Subdomains (the first 50)

Typos (misspells)

xontagiodump.blogspot.com
vontagiodump.blogspot.com
fontagiodump.blogspot.com
dontagiodump.blogspot.com
cintagiodump.blogspot.com
ckntagiodump.blogspot.com
clntagiodump.blogspot.com
cpntagiodump.blogspot.com
c0ntagiodump.blogspot.com
c9ntagiodump.blogspot.com
cobtagiodump.blogspot.com
comtagiodump.blogspot.com
cojtagiodump.blogspot.com
cohtagiodump.blogspot.com
conragiodump.blogspot.com
confagiodump.blogspot.com
congagiodump.blogspot.com
conyagiodump.blogspot.com
con6agiodump.blogspot.com
con5agiodump.blogspot.com
contzgiodump.blogspot.com
contsgiodump.blogspot.com
contwgiodump.blogspot.com
contqgiodump.blogspot.com
contafiodump.blogspot.com
contaviodump.blogspot.com
contabiodump.blogspot.com
contahiodump.blogspot.com
contayiodump.blogspot.com
contatiodump.blogspot.com
contaguodump.blogspot.com
contagjodump.blogspot.com
contagkodump.blogspot.com
contagoodump.blogspot.com
contag9odump.blogspot.com
contag8odump.blogspot.com
contagiidump.blogspot.com
contagikdump.blogspot.com
contagildump.blogspot.com
contagipdump.blogspot.com
contagi0dump.blogspot.com
contagi9dump.blogspot.com
contagiosump.blogspot.com
contagioxump.blogspot.com
contagiocump.blogspot.com
contagiofump.blogspot.com
contagiorump.blogspot.com
contagioeump.blogspot.com
contagiodymp.blogspot.com
contagiodhmp.blogspot.com
contagiodjmp.blogspot.com
contagiodimp.blogspot.com
contagiod8mp.blogspot.com
contagiod7mp.blogspot.com
contagiodunp.blogspot.com
contagiodukp.blogspot.com
contagiodujp.blogspot.com
contagiodumo.blogspot.com
contagioduml.blogspot.com
contagiodum-.blogspot.com
contagiodum0.blogspot.com
ontagiodump.blogspot.com
cntagiodump.blogspot.com
cotagiodump.blogspot.com
conagiodump.blogspot.com
contgiodump.blogspot.com
contaiodump.blogspot.com
contagodump.blogspot.com
contagidump.blogspot.com
contagioump.blogspot.com
contagiodmp.blogspot.com
contagiodup.blogspot.com
contagiodum.blogspot.com
ocntagiodump.blogspot.com
cnotagiodump.blogspot.com
cotnagiodump.blogspot.com
conatgiodump.blogspot.com
contgaiodump.blogspot.com
contaigodump.blogspot.com
contagoidump.blogspot.com
contagidoump.blogspot.com
contagioudmp.blogspot.com
contagiodmup.blogspot.com
contagiodupm.blogspot.com
ccontagiodump.blogspot.com
coontagiodump.blogspot.com
conntagiodump.blogspot.com
conttagiodump.blogspot.com
contaagiodump.blogspot.com
contaggiodump.blogspot.com
contagiiodump.blogspot.com
contagioodump.blogspot.com
contagioddump.blogspot.com
contagioduump.blogspot.com
contagiodummp.blogspot.com
contagiodumpp.blogspot.com

Location

IP: 209.85.175.132

continent: NA, country: United States (USA), city: Mountain View

Website value

rank in the traffic statistics:

There is not enough data to estimate website value.

Basic information

website build using CSS

code weight: 160.52 KB

text per all code ratio: 15 %

title: contagio

description:

keywords:

encoding: UTF-8

language: en

Website code analysis

one word phrases repeated minimum three times

PhraseQuantity
and3

two word phrases repeated minimum three times

three word phrases repeated minimum three times

B tags

IBM111

So keen and greedy to confound a man:

Qihoo 360. As noted by

bbs.kafan.cn and

the infection starts with a binary with MD5

that downloads the actual dropper MD5 BB5511A6586BA04335712E6C65E83671. While looking for the samples, I found one domain referenced on CleanMX on

that was used for distribution of the downloader with binary called

 

Introducing ESAT NQD32 and "Test Version" of Windows

Version 13. Aug 20, 2011

Version 13 exploit pack table additions:

The full table in xls format - Version 13 can be downloaded from here.

List of packs in the table in alphabetical order

List of Flash Player Vulnerabilities with CVE and Flash version numbers

Old versions of Flash Player for download

U tags

the share of malware from Russia .

I tags

(The Merchant of Venice W. Shakespeare Act 3, Scene 2 )

On September 13, 2011, Marco Giuliani from Webroot posted a detailed analysis of Mebromi - BIOS rootkit affecting Chinese computers with AWARD BIOS, which was earlier discovered by Qihoo 360. As noted by cfans

kerne1_madman

the share of malware from Russia .

Version 13. Aug 20, 2011

(many thanks to kahusecurity.com)+

(many thanks to kahusecurity.com)

images

file namealternative text
contagio

headers

H1

H2

Friday, October 7, 2011

Thursday, October 6, 2011

Wednesday, September 28, 2011

Wednesday, September 21, 2011

Monday, September 19, 2011

Sunday, September 11, 2011

Saturday, September 3, 2011

Monday, August 29, 2011

Saturday, August 20, 2011

Thursday, August 11, 2011

Wednesday, August 10, 2011

Shared by

About contagio

About Contagio Mobile

Recent posts

Blog List

Search This Blog

Malware collections

Blog Archive

Shortcuts

Categories - sort of

Malware Lists and Collections

Subscribe To

Share

contagio Dropbox

Follow by Email

H3

Friday, October 7, 2011

Thursday, October 6, 2011

Wednesday, September 28, 2011

Wednesday, September 21, 2011

Monday, September 19, 2011

Sunday, September 11, 2011

Saturday, September 3, 2011

Monday, August 29, 2011

Saturday, August 20, 2011

Thursday, August 11, 2011

Wednesday, August 10, 2011

Shared by

About contagio

About Contagio Mobile

Recent posts

Blog List

Search This Blog

Malware collections

Blog Archive

Shortcuts

Categories - sort of

Malware Lists and Collections

Subscribe To

Share

contagio Dropbox

Follow by Email

H4

H5

H6

internal links

addressanchor text
Mobile and print friendly view
Rustock samples and analysis links. Rustock.C, E, I, J and other variants
read more...
12:29 AM
Rustock
Links to this post
Sep 28 CVE-2010-3333 Manuscript with Taidoor (Trojan.Matryoshka by CyberESI)
read more...
10:38 PM
taidoor
Links to this post
Sept. 23 CVE-2011-1991 type (1) deskpan.dll Windows components DLL loading vulnerability
Apr 13 CVE-2011-2100 PDF - Adobe DLL Loading Vulnerability - Agenda.7z,
read more...
1:10 PM
CVE-2011-1991
Links to this post
Sept 21 Greedy Shylock - financial malware
read more...
6:23 PM
shylock
Links to this post
Mebromi BIOS rootkit affecting Award BIOS (aka "BMW" virus)
read more...
2:15 PM
mebromi
Links to this post
Russian Black SEO ❤ Google.ru.
read more...
4:50 PM
Black SEO
Links to this post
So long and thanks for all the phish
3:32 AM
Links to this post
Sept 3. Liberating Taiwan: one phish at a time. 2010-2011
read more...
3:22 AM
taiwan phish
Links to this post
Aug 28 Morto / Tsclient - RDP worm with DDoS features
read more...
7:15 AM
Morto
worm
Links to this post
An Overview of Exploit Packs (Update 13) August 20, 2011
read more...
1:43 PM
exploit pack
Links to this post
Targeted attacks against personal Gmail accounts Part II - CNAS Report
1 Targeted attacks against personal accounts of military, government employees and associates
read more...
2:14 AM
1 comments
gmail
Links to this post
Microsoft and Adobe Flash patches vs corresponding document and web exploits (non PDF, CVE numbered)
read more...
1:09 AM
1 comments
Links to this post
Older Posts
Home
Posts (Atom)
Home
Rustock samples and analysis links. Rustock.C, E, I, J and other variants
Sep 28 CVE-2010-3333 Manuscript with Taidoor (Trojan.Matryoshka by CyberESI)
Sept. 23 CVE-2011-1991 type (1) deskpan.dll Windows components DLL loading vulnerability
Sept 21 Greedy Shylock - financial malware info
Mebromi BIOS rootkit affecting Award BIOS (aka "BMW" virus)
Russian Black SEO ❤ Google.ru.
Sept 3. Liberating Taiwan: one phish at a time. 2010-2011
Take a sample, leave a sample. Mobile malware mini-dump
2011
October
Rustock samples and analysis links. Rustock.C, E, ...
Sep 28 CVE-2010-3333 Manuscript with Taidoor (Troj...
September
Sept. 23 CVE-2011-1991 type (1) deskpan.dll Window...
Sept 21 Greedy Shylock - financial malware
Mebromi BIOS rootkit affecting Award BIOS (aka "BM...
Russian Black SEO ❤ Google.ru.
So long and thanks for all the phish
Sept 3. Liberating Taiwan: one phish at a time. 20...
August
Aug 28 Morto / Tsclient - RDP worm with DDoS feat...
An Overview of Exploit Packs (Update 13) August 20...
Targeted attacks against personal Gmail accounts P...
Microsoft and Adobe Flash patches vs corresponding...
Adobe Reader versions vs corresponding exploits (C...
July
Jul 25 Mac Olyx backdoor + Gh0st Backdoor in RAR ...
Jul 12 RTLO rar with trojan Taidoor - former Presi...
Why contagio will never have ads
Jul 13 CVE-2010-2883 PDF Meeting Agenda with more ...
Jul 5 CVE-2010-2883 PDF invitation.pdf with Poison...
New CONTAGIOminiDUMP - mobile malware is moving !!...
Take a sample, leave a sample. Mobile malware mini...
Rootkit TDL-4 (TDSS, Alureon.DX, Olmarik, TDL) 32-...
June
Jun 22 CVE-2011-0611 PDF-SWF "Fruits of economic g...
Jun 27 PDF - SWF CVE-2011-0611 Two Views On The S...
New blog design. Yay or Nay?
Jun 17 SCR (RTLO) South China Sea Territorial Disp...
I2P ... the *other* Anonymous Network - Sempersecu...
Apr 13 CVE-2011-2100 PDF - Adobe DLL Loading Vuln...
May-June 2011 Trojan Taidoor "Louisvilleheartsurge...
Jun 13 CVE-2009-4324 PDF navy procurement.pdf from...
Jun 1 CVE-2010-3333 DOC You are my King from compr...
May 31 CVE-2010-3333 DOC President Obama's Speech....
May 31 CVE-2010-3333 DOC Q and A.doc compromised l...
Jun 1 CVE-2010-3333 DOC 2011 Insider's Guide to M...
Six ways sensitive data finds its way to personal ...
May
May 17 CVE-2010-2883 PDF Bin Laden's successor fro...
W32.Qakbot aka W32/Pinkslipbot or infostealer worm...
May 2 MAC Defender + May 11 Mac Protector Fake Ant...
May 3 CVE-2010-3333 DOC Courier who led U.S. to Os...
April
Hwp.exe in Apr. 8 CVE-2011-0611 Flash Player Zero ...
Please welcome "Targeted Email Attacks http://tar...
Contagio data - targeted email senders by country ...
Apr 22 CVE-2011-0611 PDF-SWF Marshall Plan for the...
Apr 20 CVE-2011-0611 PDF - SWF China's Charm diplo...
Malware Analysis
Apr 21 CVE-2011-0611 PDF - SWF Data requirements.p...
Apr 21 CVE-2011-0611 PDF - SWF CNO Guidance from y...
Apr 20 CVE-2010-3333 DOC Join Forces with Us.doc -...
Apr 16 CVE-2011-0611 DOC urgent files from 97.66.1...
Apr. 8 CVE-2011-0611 Flash Player Zero day - SWF i...
Version 4 April 2011 - 11,355+ Malicious document...
March
February
January
2010
December
November
October
September
August
July
June
May
April
March
February
January
2009
December
November
October
September
June
May
April
2008
May
Mobile Malware mini-dump. Take a sample, leave a sample.
Mobile Malware Google Group
Defcon 18 Materials (CD)- 2010 Las Vegas
Black Hat USA 2010 (Las Vegas and DC) materials
APT malware
APT - Advanced Persistent Threat / Targeted Attacks links
Collection of Web Backdoors & Shells
Dictionary. Ru (computer slang) - Eng (Google machine) - Eng (human)
Malware Analysis -- Links and resources for malware samples
Malware Analysis and Forensics tools links
Overview of Exploit Packs (Update 11)
Crimepack 3.1.3 Exploit kit info
Phoenix 2.0 Exploit kit
Top Twenty (Former Top Ten) targeted attack emails of 2009-2010
ZeuS Version scheme by the trojan author
Zeus Trojan Research Links
- ANDROID OS
- CMDEXPLOITS
- HTA files
- INTERNET EXPLORER 6
- INTERNET EXPLORER 6 SP1
- INTERNET EXPLORER 7
- JAVA
- MOBILE MALWARE
- MS EXCEL 2002 SP3
- MS EXCEL 2003
- MS EXCEL 2003 SP3
- MS WORD 2003 SP2
- OSX
- RAR + ZIP
- WORDPAD
2011-2100
Android.FakePlayer.A
APT
Aurora
Banking Trojans
Black Hat
Black SEO
botnets
conferences
CONFICKER
Crimepack
CVE-2006-2389
CVE-2006-2492
CVE-2007-0071
CVE-2007-5659
CVE-2008-0081
CVE-2008-2992
CVE-2008-3005
CVE-2008-4841
CVE-2008-5353
CVE-2009-0556
CVE-2009-0658
CVE-2009-0806
CVE-2009-0927
CVE-2009-1129
CVE-2009-1869
CVE-2009-3129
CVE-2009-3867
CVE-2009-3957
CVE-2009-4324
CVE-2010-0188
CVE-2010-0806
CVE-2010-1240
CVE-2010-1297
CVE-2010-1885
CVE-2010-2568
CVE-2010-2883
cve-2010-3333
CVE-2010-3654
CVE-2010-3970
CVE-2010-4091
CVE-2011-0609
CVE-2011-0611
Defcon18
mebromi
Mobile Malware Group
Morto
ransomware
RAT
Rootkit ZeroAccess (aka MAX++)
RTLO
Rustock
shylock
Stuxnet
taidoor
taiwan phish
Targeted attacks - about
TDL
TOOLS
TWITTER
worm;Qakbot
Zeus
* Malicious documents archive for signature testing and research
* Mobile Malware Collection
Adobe Reader versions vs corresponding exploits (CVE numbered) - Downloads for testing
Microsoft and Adobe Flash patches vs corresponding document and web exploits (non PDF, CVE numbered)

external links

addressanchor text
img
img
Trojan.Matryoshka and Trojan.Einstein
img
Here
strict requirements for execution
img
img
Qihoo 360.
bbs.kafan.cn
hi.baidu.com/kerne1_madman
referenced on CleanMX on
2011-08-31
by Prevx
img
the share of malware from Russia
img
img
img
jsunpack.jeek.org
malc0de.com
img
Kahusecurity issued an updated version of their Wild Wild West graphic
(many thanks to kahusecurity.com)+
(many thanks to kahusecurity.com)
(many thanks to kahusecurity.com)
The full table in xls format - Version 13 can be downloaded from here.
img
Google mention in their blogpost in June 2011
img
Malware Tracker
List of Flash Player Vulnerabilities with CVE and Flash version numbers
Old versions of Flash Player for download
View my complete profile
Contagio mobile mini-dump
img
img
RE blogs collection
CURRENT PDF THREATS - Malware Tracker
************** ViCheck.ca - Malware check tool*************
* I want it ALL
Malware list (don't think i have time to keep it up)
Malware list
Blogger