Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #MalwareMustDie - Copy of official report of more Kelihos NEW .COM Domains
- Hello all,
- The below domains are also spotted as new Kelihos .COM domains:
- hayznep.com
- ikfubla.com
- joejkab.com
- mulocxu.com
- nemicki.com
- sotlequ.com
- enpomaf.com
- ofciwox.com
- Source: http://pastebin.com/g0EVfqKi by DhiaLite/Umbrella Labs
- Same MO as per previous spotted and reported OFCIWOX.COM
- Domain Name: HAYZNEP.COM
- Registrar: PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
- Whois Server: whois.PublicDomainRegistry.com
- Referral URL: http://www.PublicDomainRegistry.com
- Name Server: NS1.HAYZNEP.COM
- Name Server: NS2.HAYZNEP.COM
- Name Server: NS3.HAYZNEP.COM
- Name Server: NS4.HAYZNEP.COM
- Name Server: NS5.HAYZNEP.COM
- Name Server: NS6.HAYZNEP.COM
- Status: clientTransferProhibited
- Updated Date: 08-aug-2013
- Creation Date: 08-aug-2013
- Expiration Date: 08-aug-2014
- >>> Last update of whois database: Fri, 09 Aug 2013 15:58:59 UTC <<<
- Domain Name: IKFUBLA.COM
- Registrar: PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
- Whois Server: whois.PublicDomainRegistry.com
- Referral URL: http://www.PublicDomainRegistry.com
- Name Server: NS1.IKFUBLA.COM
- Name Server: NS2.IKFUBLA.COM
- Name Server: NS3.IKFUBLA.COM
- Name Server: NS4.IKFUBLA.COM
- Name Server: NS5.IKFUBLA.COM
- Name Server: NS6.IKFUBLA.COM
- Status: clientTransferProhibited
- Updated Date: 08-aug-2013
- Creation Date: 08-aug-2013
- Expiration Date: 08-aug-2014
- >>> Last update of whois database: Fri, 09 Aug 2013 15:58:29 UTC <<<
- Domain Name: JOEJKAB.COM
- Registrar: PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
- Whois Server: whois.PublicDomainRegistry.com
- Referral URL: http://www.PublicDomainRegistry.com
- Name Server: NS1.JOEJKAB.COM
- Name Server: NS2.JOEJKAB.COM
- Name Server: NS3.JOEJKAB.COM
- Name Server: NS4.JOEJKAB.COM
- Name Server: NS5.JOEJKAB.COM
- Name Server: NS6.JOEJKAB.COM
- Status: clientTransferProhibited
- Updated Date: 08-aug-2013
- Creation Date: 08-aug-2013
- Expiration Date: 08-aug-2014
- >>> Last update of whois database: Fri, 09 Aug 2013 15:59:45 UTC <<<
- [..and so on...]
- With the same Registration Service Provided By: DOMALAND
- Domain Name: JOEJKAB.COM
- Registration Date: 08-Aug-2013
- Expiration Date: 08-Aug-2014
- Status:LOCKED
- Note: This Domain Name is currently Locked.
- This feature is provided to protect against fraudulent acquisition of the domain name,
- as in this status the domain name cannot be transferred or modified.
- Name Servers:
- ns1.joejkab.com
- ns2.joejkab.com
- ns3.joejkab.com
- ns4.joejkab.com
- ns5.joejkab.com
- ns6.joejkab.com
- Registrant Contact Details:
- N/A
- Anstice Selby (anstice_selby7250@cyberdude.com)
- 12721 Ceder St
- Manor
- TX,78653
- US
- Tel. +1.2530260685
- [ and so on...]
- With serving hlux to...
- @unixfreaxjp ~]$ while true; do dig +short hayznep.com; sleep 1; done
- 111.241.130.235
- 46.250.24.36
- 46.37.197.45
- 5.165.158.112
- 92.52.148.100
- 188.129.195.85
- ^C
- @unixfreaxjp ~]$ while true; do dig +short ikfubla.com; sleep 1; done
- 93.77.103.167
- 46.187.78.6
- 46.52.237.127
- 91.241.104.9
- ^C
- @unixfreaxjp ~]$ while true; do dig +short joejkab.com; sleep 1; done
- 109.106.20.232
- 91.225.74.13
- 178.150.203.178
- 88.81.35.196
- ^C
- @unixfreaxjp ~]$ while true; do dig +short mulocxu.com; sleep 1; done
- 111.242.40.241
- 80.99.210.196
- 5.152.214.150
- ^C
- [...]
- @unixfreaxjp ~]$ while true; do dig +short ofciwox.com; sleep 1; done
- 114.27.128.253
- 83.246.151.18
- 218.209.154.20
- 114.38.209.98
- 93.78.76.236
- ^C
- // The IP addresses are the same as per milked 1,200+
- ----
- #MalwareMustDie!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement