See: http://zulu.zscaler.com/submission/show/78e6d9ea7fd8cb82dd0e904b36d39624-1342551094
See: http://zulu.zscaler.com/submission/show/77882267cc1085f18f83273df9ef6372-1342551319
See: http://zulu.zscaler.com/submission/show/d9664f0b41aba50ae531d98b7ff21029-1342551420
Nasty ads script not-out-of-the-box VBulletin code running on port “37935” is suspicous: → htXp://127.0.0.1:37935/xpopup.js
(inserting some security JS?)
IP has live PHP shell code malware
Certainly PHISHING going on: http://urlquery.net/report.php?id=94374
AS has malicious URLs? Yes
…badware? Yes
…botnet C&C servers? Yes
…exploit servers? No
…Zeus botnet servers? Yes
…Current Events? Yes
polonus