Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- // Kelihos botnet IP for downloading payload using .RU's DGA domains,
- // We reported at http://pastebin.com/zxhk5mKB ,
- // Is still up and alive in the wild now!
- // The shutdown request was executed but only 4 domains shutdown at this moment.
- // The weekend is starting to come so PLEASE BLOCK THESE KELIHOS INFECTOR DOMAINS A.S.A.P.:
- // I think our Tango will not make it before weekend.
- // PoC of infector domains used is UP AND ALIVE:
- @unixfreaxjp /malware/checkdomains]$ date
- Fri Jul 19 20:01:00 JST 2013
- uhipyvob.ru,178.150.17.118,
- ollopdub.ru,176.8.3.144,
- fafehwiz.ru,91.217.58.74,
- fuhxodyz.ru,77.122.197.86,
- ikqydkod.ru,37.229.144.253,
- bopefidi.ru,118.34.132.154,
- ycsycxyd.ru,95.140.214.250,
- sojouvyc.ru,188.129.218.87,
- vadlubiq.ru,178.93.135.94,
- kazlyjva.ru,109.162.94.114,
- funfubap.ru,213.37.166.193,
- goryzcob.ru,213.37.166.193,
- motbajsi.ru,178.158.158.182,
- xymkapaq.ru,93.185.219.213,
- runevfoh.ru,89.215.115.4,
- virerceb.ru,94.153.36.164,
- xatzyjha.ru,93.79.152.211,
- makgivus.ru,79.135.211.87,
- avryjpet.ru,178.211.105.168,
- kyjaqcoz.ru,46.119.144.106,
- hiznizoc.ru,46.250.7.179,
- giktyxvu.ru,77.123.79.211,
- ynhazcel.ru,178.172.246.30,
- gazgowry.ru,93.89.208.202,
- vetarwep.ru,5.248.164.41,
- gulaxxax.ru,46.119.144.106,
- onhugxic.ru,109.251.126.26,
- ahfamzyk.ru,46.49.47.254,
- sykevked.ru,93.77.96.252,
- ydhicdor.ru,94.137.172.44,
- kifectah.ru,109.122.40.111,
- busasxyv.ru,77.121.199.73,
- yjnaqwew.ru,77.121.255.183,
- xuktalez.ru,91.123.150.115,
- lygyucce.ru,94.158.74.230,
- taykenid.ru,109.108.252.136,
- bysjyhuf.ru,5.1.22.63,
- najniner.ru,126.65.174.136,
- dakacdyn.ru,109.254.67.25,
- higrikpy.ru,78.154.168.74,
- dipteqna.ru,188.190.75.232,
- kykywpik.ru,109.122.33.79,
- cimmitic.ru,153.180.71.144,
- suyzerew.ru,217.196.171.35,
- yhzelbyp.ru,77.123.80.174,
- aflyzkac.ru,93.185.220.213,
- tejjetzo.ru,93.89.208.202,
- lysopzoh.ru,178.168.22.114,
- dyvgigim.ru,46.211.75.123,
- jehrecyp.ru,87.69.55.36,
- cyrkapov.ru,190.220.70.79,
- niqtasoz.ru,178.150.17.118,
- ginkyvub.ru,77.123.80.174,
- zyvjofat.ru,93.79.152.211,
- ihurvyun.ru,94.231.190.74,
- izytexuf.ru,31.192.237.101,
- adtyuhuz.ru,84.252.56.59,
- aggaxsef.ru,94.230.201.36,
- bomuxvis.ru,84.240.19.130,
- xejabfom.ru,178.158.186.24,
- sapigrys.ru,95.69.187.249,
- sodkanxo.ru,117.197.245.69,
- paxgeqjo.ru,49.205.210.193,
- xoqhozaz.ru,95.160.83.57,
- usfezhyk.ru,46.119.212.183,
- hipahsah.ru,109.87.200.213,
- talozzum.ru,31.133.52.8,
- yrupxyen.ru,91.224.168.65,
- nacwoman.ru,178.150.90.223,
- libcikak.ru,46.119.128.115,
- uphinjaq.ru,109.162.9.212,
- aziwolge.ru,178.150.17.118,
- oktizsez.ru,78.139.153.169,
- kiyvryhy.ru,79.133.254.238,
- fugegwyf.ru,188.190.75.232,
- urxibzep.ru,91.225.173.12,
- bawoxgud.ru,31.133.55.240,
- xudsahbu.ru,195.24.155.245,
- dypqysro.ru,31.170.137.75,
- jyuhysdo.ru,78.154.168.74,
- hupjiwuc.ru,188.121.198.247,
- cypseguv.ru,176.8.249.131,
- confikja.ru,93.171.77.37,
- tofhermi.ru,36.224.71.20,
- ybtoptag.ru,180.61.12.116,
- qeisybyg.ru,77.122.124.210,
- mihumcuf.ru,93.185.220.213,
- pywudcoz.ru,89.201.116.227,
- kosnutef.ru,79.164.250.218,
- acaqizwy.ru,178.150.244.54,
- lymimnib.ru,117.197.15.103,
- sisvizub.ru,89.28.52.30,
- hozfezbe.ru,178.210.222.205,
- // These domains are down now...
- cibowjuv.ru,,
- pedtokid.ru,,
- ankoweco.ru,,
- uxmadjox.ru,,
- ----
- #MalwareMustDie!
- Checked by @unixfreaxjp at:
- @unixfreaxjp /malware/checkdomains]$ date
- Fri Jul 19 20:13:52 JST 2013
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement