Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- // #MalwareMustDie! $ date
- // Thu Aug 8 16:40:00 JST 2013
- // Current Kelihos payload IP addresses
- // Milked & sorted by: @chrisjwilsoncom
- // This data is published for the CLEANUP purpose per regions.
- // The Graphic statistic of infection is here: http://ge.tt/6CshMJo/v/1
- // Latest Update is in http://pastebin.com/raw.php?i=s7q1Yyr3
- // Firstly the PoC of UP and ALive: (snipped via @unixfreaxjp report)
- --2013-08-08 15:31:10-- hxxp://117.74.46.13/rasta01.exe
- Connecting to 117.74.46.13:80... connected.
- HTTP request sent, awaiting response... 200
- Length: 1221261 (1.2M) []
- Saving to: ‘rasta01.exe.4’
- 100%[==============>] 1,221,261 371KB/s in 3.2s
- 2013-08-08 15:31:36 (371 KB/s) - ‘rasta01.exe.4’ saved [1221261/1221261]
- --2013-08-08 15:31:56-- hxxp://218.110.111.80/rasta01.exe
- Connecting to 218.110.111.80:80... connected.
- HTTP request sent, awaiting response... 200
- Length: 1221261 (1.2M) []
- Saving to: ‘rasta01.exe.5’
- 100%[==============>] 1,221,261 1.64MB/s in 0.7s
- 2013-08-08 15:32:02 (1.64 MB/s) - ‘rasta01.exe.5’ saved [1221261/1221261]
- --2013-08-08 15:32:22-- hxxp://111.67.162.60/rasta01.exe
- Connecting to 111.67.162.60:80... connected.
- HTTP request sent, awaiting response... 200
- Length: 1221261 (1.2M) []
- Saving to: ‘rasta01.exe.6’
- 100%[==============>] 1,221,261 443KB/s in 2.7s
- 2013-08-08 15:33:17 (443 KB/s) - ‘rasta01.exe.6’ saved [1221261/1221261]
- --2013-08-08 15:33:34-- hxxp://210.148.165.67/rasta01.exe
- Connecting to 210.148.165.67:80... connected.
- HTTP request sent, awaiting response... 200
- Length: 1221261 (1.2M) []
- Saving to: ‘rasta01.exe.7’
- 100%[==============>] 1,221,261 1.99MB/s in 0.6s
- 2013-08-08 15:33:42 (1.99 MB/s) - ‘rasta01.exe.7’ saved [1221261/1221261]
- --2013-08-08 15:33:58-- hxxp://114.178.77.6/rasta01.exe
- Connecting to 114.178.77.6:80... connected.
- HTTP request sent, awaiting response... 200
- Length: 1221261 (1.2M) []
- Saving to: ‘rasta01.exe.8’
- 100%[==============>] 1,221,261 1.05MB/s in 1.1s
- 2013-08-08 15:34:04 (1.05 MB/s) - ‘rasta01.exe.8’ saved [1221261/1221261]
- // Here is the LIST with with the Country, ISP Network Info and ASN
- 93.78.76.236|Ukraine|VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC|AS25229
- 111.254.192.63|Taiwan|HINET Data Communication Business Group|AS3462
- 46.250.16.2|Ukraine|BREEZE-NETWORK TOV TRK _Briz_|AS34661
- 220.142.123.97|Taiwan|HINET Data Communication Business Group|AS3462
- 114.47.161.112|Taiwan|HINET Data Communication Business Group|AS3462
- 89.185.30.50|Ukraine|TVCOM-AS TVCOM Ltd.|AS34092
- 92.115.198.208|Moldova, Republic of|MOLDTELECOM-AS Moldtelecom SA|AS8926
- 114.38.44.145|Taiwan|HINET Data Communication Business Group|AS3462
- 188.27.114.74|Romania|RCS-RDS RCS & RDS SA|AS8708
- 5.248.25.109|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 124.111.249.204|Korea, Republic of|HANARO-AS Hanaro Telecom Inc.|AS9318
- 111.250.108.4|Taiwan|HINET Data Communication Business Group|AS3462
- 176.8.203.155|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 31.170.142.105|Ukraine|UA-KICHKAS PE Kotova Alina Volodymyrivna|AS42714
- 176.62.100.91|Russian Federation|OMKC-AS Omskie kabelnye seti Ltd.|AS47165
- 178.187.50.130|Russian Federation|SIBIRTELECOM-AS OJSC Rostelecom|AS41440
- 117.74.46.13|Japan|TDNC Community Network Center Inc.|AS9354
- 176.15.193.76|Russian Federation|CORBINA-AS OJSC _Vimpelcom_|AS8402
- 61.227.54.135|Taiwan|HINET Data Communication Business Group|AS3462
- 46.118.209.230|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 2.134.150.105|Kazakhstan|KAZTELECOM-AS JSC Kazakhtelecom|AS9198
- 176.37.121.102|Ukraine|LANETUA-AS Lanet Network Ltd.|AS39608
- 123.110.73.214|Taiwan|SEEDNET Digital United Inc.|AS4780
- 178.150.55.54|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 109.254.23.233|Ukraine|DEC-AS Donbass Electronic Communications Ltd.|AS20590
- 220.133.139.83|Taiwan|HINET Data Communication Business Group|AS3462
- 31.133.61.129|Ukraine|TRUBNIKOV-AS FOP Trubnikov Valeriy Muhaylovich|AS52091
- 178.171.64.247|Russian Federation|ELIGHT-AS E-Light-Telecom|AS39927
- 213.164.250.131|Romania|LGI-UPC Liberty Global Operations B.V.|AS6830
- 82.202.79.46|Czech Republic|CDT-AS CD-Telematika a.s.|AS25512
- 46.211.77.101|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 31.28.242.233|Ukraine|SEVSTAR Lancom Ltd.|AS35816
- 78.30.226.70|Ukraine|SEVSTAR Lancom Ltd.|AS35816
- 31.28.255.186|Ukraine|SEVSTAR Lancom Ltd.|AS35816
- 195.228.13.160|Hungary|HTC-AS Magyar Telekom plc.|AS5483
- 178.74.237.85|Ukraine|EVEREST-AS _Everest_ Broadcasting Company Ltd|AS49223
- 46.174.223.81|Ukraine|SIVASH-AS DP BKS-Sivash|AS39248
- 94.137.172.44|Georgia|RUSTAVI2ONLINEAS Caucasus Online LLC|AS16010
- 46.35.250.181|Ukraine|SEVSTAR Lancom Ltd.|AS35816
- 93.185.220.213|Ukraine|TVCOM-ALTAIR-AS TVCOM Ltd.|AS57033
- 203.186.42.238|Hong Kong|HKBN-AS-AP Hong Kong Broadband Network Ltd.|AS9269
- 69.244.175.93|United States|CMCS - Comcast Cable Communications, Inc.|AS33668
- 61.227.160.166|Taiwan|HINET Data Communication Business Group|AS3462
- 109.108.233.133|Ukraine|EVEREST-AS _Everest_ Broadcasting Company Ltd|AS49223
- 218.110.111.80|Japan|SO-NET So-net Entertainment Corporation|AS2527
- 36.230.173.221|Taiwan|HINET Data Communication Business Group|AS3462
- 109.229.189.86|Kazakhstan|ASKET-AS LLP Asket|AS51997
- 91.228.13.154|Ukraine|WEBNETWORK Individual entrepreneur Dyachenko Valentina Ivanovna|AS57100
- 36.239.72.222|Taiwan|HINET Data Communication Business Group|AS3462
- 115.245.49.110|India|BSES-AS-AP BSES TeleCom Limited|AS17803
- 201.225.70.75|Panama|Cable & Wireless Panama|AS11556
- 159.224.81.49|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 95.58.139.116|Kazakhstan|KAZTELECOM-AS JSC Kazakhtelecom|AS9198
- 77.121.241.200|Ukraine|VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC|AS25229
- 178.137.27.81|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 77.122.0.33|Ukraine|VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC|AS25229
- 178.150.244.54|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 178.165.18.207|Ukraine|CITYNET-AS Maxnet Autonomous System|AS34700
- 31.42.73.133|Ukraine|VOSTOKLTD VOSTOK Ltd.|AS29688
- 77.39.44.182|Russian Federation|STATEL-AS Rostelecom|AS12683
- 114.26.6.80|Taiwan|HINET Data Communication Business Group|AS3462
- 118.161.170.98|Taiwan|HINET Data Communication Business Group|AS3462
- 109.86.83.144|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 37.139.105.6|Ukraine|SEVSTAR Lancom Ltd.|AS35816
- 114.43.3.202|Taiwan|HINET Data Communication Business Group|AS3462
- 140.115.61.193|Taiwan|NCU-TW National Central University|AS18420
- 123.205.26.62|Taiwan|TINP-TW Taiwan Infrastructure Network Technologie|AS18049
- 111.249.245.105|Taiwan|HINET Data Communication Business Group|AS3462
- 1.172.233.77|Taiwan|HINET Data Communication Business Group|AS3462
- 178.137.35.78|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 109.86.21.122|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 109.87.158.196|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 111.240.192.80|Taiwan|HINET Data Communication Business Group|AS3462
- 111.240.1.127|Taiwan|HINET Data Communication Business Group|AS3462
- 111.67.162.60|Japan|HANSHIN ITEC HANKYU HANSHIN CO.,LTD.|AS7524
- 123.241.183.90|Taiwan|SEEDNET Digital United Inc.|AS4780
- 91.187.16.110|Belarus|BELINFONET Belinfonet Autonomus System, Minsk, Belarus|AS24827
- 91.200.138.241|Ukraine|SIVASH-AS DP BKS-Sivash|AS39248
- 46.73.143.231|Russian Federation|TI-AS Net By Net Holding LLC|AS12714
- 1.161.167.99|Taiwan|HINET Data Communication Business Group|AS3462
- 109.87.75.251|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 109.229.97.3|Russian Federation|TELECOM-NETWORKS-AS OJSC Telecommunication networks|AS49136
- 77.70.87.124|Bulgaria|MEGALAN MOBILTEL EAD|AS35141
- 109.87.127.68|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 123.195.24.188|Taiwan|TFN-TW Taiwan Fixed Network, Telco and Network Service Provider.|AS9924
- 46.254.162.44|Russian Federation|ITNET33 Informatsionnye Tekhnologii LLC|AS50596
- 101.63.135.105|India|BSES-AS-AP BSES TeleCom Limited|AS17803
- 81.5.115.182|Russian Federation|MIPT-NET Non state educational institution _Educational Scientific and Experimental Center of Moscow Institute of Physics and Technology_|AS25100
- 114.39.53.154|Taiwan|HINET Data Communication Business Group|AS3462
- 109.200.236.242|Ukraine|BREEZE-NETWORK TOV TRK _Briz_|AS34661
- 178.137.218.33|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 46.161.128.108|Russian Federation|NEWTELESYSTEMS New Telesystems - TV, Ltd.|AS31036
- 117.197.230.88|India|BSNL-NIB National Internet Backbone|AS9829
- 2.180.38.203|Iran, Islamic Republic of|TIC-AS Telecommunication Infrastructure Company|AS48159
- 111.184.33.70|Taiwan|MULTIMEDIA-AS-AP Hoshin Multimedia Center Inc.|AS9416
- 109.202.38.208|Russian Federation|KAMENSKTEL-AS CJSC Radiotelephone AS|AS39812
- 124.8.128.27|Taiwan|TFN-TW Taiwan Fixed Network, Telco and Network Service Provider.|AS9924
- 46.161.173.55|Russian Federation|NEWTELESYSTEMS New Telesystems - TV, Ltd.|AS31036
- 217.25.225.80|Russian Federation|IC-VORONEZH-AS IC-VORONEZH|AS6856
- 109.162.94.114|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 114.40.76.212|Taiwan|HINET Data Communication Business Group|AS3462
- 176.74.95.3|Georgia|EGRISI-AS Egrisi JSC.|AS34797
- 195.114.149.69|Ukraine|DATAGROUP PRIVATE JOINT STOCK COMPANY _DATAGROUP_|AS21219
- 46.162.219.0|Armenia|ORG-UL31-RIPE UCOM LLC|AS44395
- 91.196.61.56|Ukraine|ARHAT-AS PE Bondar TN|AS50204
- 37.221.142.107|Ukraine|ABUA-AS LLC AB Ukraine|AS43266
- 95.81.94.166|Iran, Islamic Republic of|HAMARA-AS Hamara System Tabriz Engineering Company|AS47262
- 109.191.25.23|Russian Federation|INTERSVYAZ-AS Intersvyaz-2 JSC|AS8369
- 89.151.154.187|Russian Federation|RU-CHTTS OJSC Rostelecom|AS43468
- 109.122.48.79|Ukraine|MEGASTYLE MegaStyle-Service|AS12872
- 114.40.143.213|Taiwan|HINET Data Communication Business Group|AS3462
- 175.181.219.235|Taiwan|SEEDNET Digital United Inc.|AS4780
- 176.74.96.132|Georgia|EGRISI-AS Egrisi JSC.|AS34797
- 180.215.33.65|India|MTS-INDIA-IN 334,Udyog Vihar|AS131222
- 111.251.194.114|Taiwan|HINET Data Communication Business Group|AS3462
- 114.45.224.193|Taiwan|HINET Data Communication Business Group|AS3462
- 188.27.168.54|Romania|RCS-RDS RCS & RDS SA|AS8708
- 213.111.209.237|Ukraine|MAINSTREAM-AS PP MainStream|AS44924
- 5.187.45.114|Russian Federation|LOGOS-AS CJSC _Digital network _Logos_|AS199096
- 114.40.103.158|Taiwan|HINET Data Communication Business Group|AS3462
- 109.227.97.51|Ukraine|MCLAUT-AS LLC _McLaut-Invest_|AS25133
- 178.90.24.46|Kazakhstan|KAZTELECOM-AS JSC Kazakhtelecom|AS9198
- 178.150.159.117|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 46.191.189.144|Russian Federation|UBN-AS OJSC _Ufanet_|AS24955
- 46.98.71.3|Ukraine|FREGAT-AS ISP _Fregat_ Ltd.|AS15377
- 190.208.139.17|Chile|Telmex Servicios Empresariales S.A.|AS6535
- 46.50.249.85|Russian Federation|ZSTTKAS JSC _Zap-Sib TransTeleCom_, Novosibirsk|AS21127
- 111.255.130.13|Taiwan|HINET Data Communication Business Group|AS3462
- 46.118.69.179|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 114.44.52.111|Taiwan|HINET Data Communication Business Group|AS3462
- 93.79.70.247|Ukraine|VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC|AS25229
- 32.64.90.108|United States|WORLDNET5-10 - AT&T WorldNet|AS8030
- 5.152.214.150|United Kingdom|REDSTATION Redstation Limited|AS35662
- 93.77.68.168|Ukraine|VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC|AS25229
- 190.108.29.37|Uruguay|Tecnowind S.A.|AS20255
- 61.70.69.158|Taiwan|MULTIMEDIA-AS-AP Hoshin Multimedia Center Inc.|AS9416
- 78.159.37.171|Ukraine|FREENET-AS Freenet Ltd.|AS31148
- 122.118.138.173|Taiwan|HINET Data Communication Business Group|AS3462
- 37.229.224.61|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 109.251.181.44|Ukraine|FREENET-AS Freenet Ltd.|AS31148
- 46.211.106.199|Ukraine|KSNET-AS _Kyivstar_ PJSC|AS15895
- 94.28.220.157|Russian Federation|AS_TULATEL OJSC Rostelecom|AS8675
- 210.148.165.67|Japan|IIJ Internet Initiative Japan Inc.|AS2497
- 115.187.49.219|India|ALLIANCE-GATEWAY-AS-AP Alliance Broadband Services Pvt. Ltd.|AS23860
- 36.238.229.56|Taiwan|HINET Data Communication Business Group|AS3462
- 5.164.21.197|Russian Federation|TULA-AS CJSC _ER-Telecom Holding_|AS52207
- 119.15.220.69|Taiwan|MONAD-TW-AP Monad Digitnamic Corp.|AS17809
- 220.138.252.195|Taiwan|HINET Data Communication Business Group|AS3462
- 114.42.72.197|Taiwan|HINET Data Communication Business Group|AS3462
- 218.166.194.88|Taiwan|HINET Data Communication Business Group|AS3462
- 36.226.117.81|Taiwan|HINET Data Communication Business Group|AS3462
- 218.166.2.199|Taiwan|HINET Data Communication Business Group|AS3462
- 109.87.12.75|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 176.37.191.24|Ukraine|LANETUA-AS Lanet Network Ltd.|AS39608
- 219.68.163.80|Taiwan|MULTIMEDIA-AS-AP Hoshin Multimedia Center Inc.|AS9416
- 178.204.101.65|Russian Federation|TATTELECOM-AS OJSC _OAO TATTELECOM_|AS28840
- 114.178.77.6|Japan|OCN NTT Communications Corporation|AS4713
- 1.163.56.51|Taiwan|HINET Data Communication Business Group|AS3462
- 109.87.133.37|Ukraine|BANKINFORM-AS TOV _Bank-Inform_|AS13188
- 109.197.146.200|Russian Federation|ARS-AS Arctic Region Svyaz OJSC|AS50639
- 212.76.20.26|Kazakhstan|2DAY Telecom LLP|AS13082
- #MalwareMustDie!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement