Checkpoint IPS:
Suspicious Malvertising Redirection
http://www.checkpoint.com/defense/advisories/public/2017/cpa
URL: hxxp://go.pub 2srv.com/apu.php?zoneid=749957
Checkpoint IPS:
Suspicious Malvertising Redirection
http://www.checkpoint.com/defense/advisories/public/2017/cpa
https://sitecheck.sucuri.net/results/de.remedy-info.com/
URL: hxxp://go.ocla srv.com/apu.php?zoneid=1090379
Checkpoint IPS:
Suspicious Malvertising Redirection
http://www.checkpoint.com/defense/advisories/public/2017/cpa
URL: hxxp://go.oclas rv.com/apu.php?zoneid=813021
Sophos AV:
Virus/PUS: "Mal/DrodZp-A" found!,URL: hxxp://l3ij.o2-rechnung24.org/file/rechnung.zip
Virus/PUS: "Mal/DrodZp-A" found!,URL: hxxp://jp70.o2-rechnung24.org/file/rechnung.zip
https://www.virustotal.com/de/url/573165346650d9867a4bbdaec2
https://www.virustotal.com/de/url/77f80e31af73630fc815ff6641
Server IP: 188.127.249.70
Sophos AV:
Virus/PUS: "Mal/DrodZp-A" found!,URL: hxxp://kt16.o2rechnung.net/file/rechnung.zip
Virus/PUS: "Mal/DrodZp-A" found!,URL: hxxp://l3ij.o2-rechnung24.org/file/rechnung.zip
Virus/PUS: "Mal/DrodZp-A" found!,URL: hxxp://jp70.o2-rechnung24.org/file/rechnung.zip
http://sitereview.bluecoat.com/sitereview.jsp#/?search=o2rec