Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Wed, Feb 26 2014
- #DhiaLite - Predicted next IPs to host Nuclear Pack EK subdomains
- A new IP range set up to host Nuclear Exploit kit domains
- 5.101.173.11
- 5.101.173.12
- 5.101.173.13
- 5.101.173.14
- 5.101.173.15
- 5.101.173.16
- 5.101.173.17
- 5.101.173.18
- 5.101.173.19
- 5.101.173.20
- So far, 5.101.173.11, 5.101.173.12, 5.101.173.13, 5.101.173.14 have been used.
- The Nuclear EK subdomains use these name servers for now
- DNS1.VIAGISONE.RU on 198.50.212.137
- and
- DNS2.VIAGISONE.RU on 198.50.178.137
- VIAGISONE.RU registered Fen 24th
- 198.50.212.137 is part of the range 198.50.212.136 - 198.50.212.143
- Same actor also reserverd the below ranges as discussed in http://pastebin.com/KuxpNJwV
- 198.50.212.128 - 198.50.212.131
- 198.50.212.132 - 198.50.212.135
- 198.50.212.136 - 198.50.212.143
- 198.50.178.137 is part of the range 198.50.178.136 - 198.50.178.139
- Same actor also reserved 198.50.178.140 - 198.50.178.143
- Block/monitor/take down EK domains and their nameservers.
- Block/monitor full IP ranges for subdomains and name servers.
- Reference:
- http://labs.umbrella.com/2014/02/14/when-ips-go-nuclear/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement