Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Sat, Feb 1, 2014
- #DhiaLite - New Browlock IP range on 5.104.111.29-38
- All IPs are hosting Browlock urls, e.g
- http://5.104.111.29/interpol/Cv6QkDLfZcpKb3iaL0iOwO8LVQmpGkY1CdQVeI7sAN_/tk1YbFPn2XKTMXSK-Rm_/60xMG1uig5B9/wxGGJQatQOw%7E%7E/YjhhMDUzMDFkOTVkYjUwZmYyMGU3NmRiNWU4NjllYjU
- http://5.104.111.38/ec3/IjXyTg32i71CUMbU1E7LWmODH3bXbR2mq1WeXZ14AjeWMpTu5ajAeTX3zN8zXjPgoJXh0OOazKYh/u1hP7o5vxg%7E%7E/MTk0MWM2NDMyYzI4YjhhY2Y2NzAzNDQ2MTMxMDcxMWU
- Just form the url with the path /interpol/Cv6QkDLfZcpKb3iaL0iOwO8LVQmpGkY1CdQVeI7sAN_/tk1YbFPn2XKTMXSK-Rm_/60xMG1uig5B9/wxGGJQatQOw%7E%7E/YjhhMDUzMDFkOTVkYjUwZmYyMGU3NmRiNWU4NjllYjU
- or
- /ec3/IjXyTg32i71CUMbU1E7LWmODH3bXbR2mq1WeXZ14AjeWMpTu5ajAeTX3zN8zXjPgoJXh0OOazKYh/u1hP7o5vxg%7E%7E/MTk0MWM2NDMyYzI4YjhhY2Y2NzAzNDQ2MTMxMDcxMWU
- or other possible paths
- under http://5.104.111.x in the 5.104.111.29-38 range and you will get a live Browlock page
- The IPs 5.104.111.29,30,31,32,34,35,36 are already hosting Browlock subdomains injected under compromised GoDaddy domains.
- 5.104.111.33,37,38 are not hosting domains yet.
- Likely more subdomains will be injected under Compromised GoDaddy domains and will be made point to 5.104.111.33,37,38
- More subdomains are appearing.
- #Sample compromised Godaddy 2LDs
- 90-4-life.com
- 90-4-life.mobi
- 90-4-life.net
- 90-4-life.org
- 90-for-life.com
- 90forlifeleaders.com
- 90forlifestyletour.com
- 90forlifestyletour.net
- 90forlifevideos.com
- 90forlifewebinars.com
- averageamericanbillionaire.biz
- averageamericanbillionaire.com
- averageamericanbillionaire.net
- averageamericanmillionaire.biz
- avgamericanmillionaire.com
- beyoutifulminerals.com
- billandreoli.biz
- billandreoli.com
- billandreoli.net
- caddcrusade.com
- cadd.mobi
- checkrealty.info
- exopy.com
- howtocureerictiledysfunction.com
- howtocureerictiledysfunction.info
- howtocureerictiledysfunction.net
- listingssales.com
- uscoinandjewelry.info
- wanttobuy.biz
- wayneslist.info
- #Sample urls of the Browloack page
- http://myufg.cadd.mobi/ec3/IjXyTg32i71CUMbU1E7LWmODH3bXbR2mq1WeXZ14AjeWMpTu5ajAeTX3zN8zXjPgoJXh0OOazKYh/u1hP7o5vxg%7E%7E/MTk0MWM2NDMyYzI4YjhhY2Y2NzAzNDQ2MTMxMDcxMWU
- http://myufg.cadd.mobi/interpol/Cv6QkDLfZcpKb3iaL0iOwO8LVQmpGkY1CdQVeI7sAN_/tk1YbFPn2XKTMXSK-Rm_/60xMG1uig5B9/wxGGJQatQOw%7E%7E/YjhhMDUzMDFkOTVkYjUwZmYyMGU3NmRiNWU4NjllYjU
- VT reports
- https://www.virustotal.com/en/ip-address/5.104.111.29/information/
- https://www.virustotal.com/en/ip-address/5.104.111.30/information/
- https://www.virustotal.com/en/ip-address/5.104.111.31/information/
- https://www.virustotal.com/en/ip-address/5.104.111.32/information/
- https://www.virustotal.com/en/ip-address/5.104.111.34/information/
- https://www.virustotal.com/en/ip-address/5.104.111.35/information/
- #Sample Browlock subdomains on 5.104.111.29-36
- yhjntyy.billandreoli.net
- vdfzgdg.billandreoli.com
- myufg.cadd.mobi
- czxvd.caddcrusade.com
- bngch.billandreoli.net
- bnfuu.cadd.mobi
- xcvzsdd.billandreoli.com
- vzsdgd.avgamericanmillionaire.com
- vcnch.billandreoli.biz
- zxczsf.90forlifewebinars.com
- zxcvfnb.averageamericanmillionaire.biz
- zdfhxf.billandreoli.biz
- xzvczsd.avgamericanmillionaire.com
- xstsjhy.averageamericanbillionaire.net
- xhdjtyr.averageamericanmillionaire.biz
- vbnyfjd.averageamericanbillionaire.net
- hthftm.averageamericanbillionaire.com
- hgfyjy.averageamericanbillionaire.com
- gfjyjt.averageamericanbillionaire.biz
- dfhxdg.beyoutifulminerals.com
- cxzvdd.beyoutifulminerals.com
- bnxfgj.averageamericanbillionaire.biz
- nujkf.90forlifestyletour.com
- caefxc.90forlifewebinars.com
- zdgstrt.90-for-life.com
- zdgrr.90-4-life.org
- xcvncg.90forlifeleaders.com
- vxzces.90forlifestyletour.net
- vdzg.90-4-life.org
- vcnhfu.90forlifevideos.com
- tfjtyjgvn.90forlifevideos.com
- sdvfrr.90-4-life.net
- nikuu.90-4-life.mobi
- jdtyiyfr.90forlifeleaders.com
- gjytyfj.90forlifestyletour.com
- fhdtr.90-4-life.net
- dgdrfg.90forlifestyletour.net
- vjkuy.90-4-life.mobi
- zdgz.howtocureerictiledysfunction.info
- yfjify.wayneslist.info
- xhtfg.howtocureerictiledysfunction.net
- tyujht.listingssales.com
- nmfu.wayneslist.info
- ndryu.listingssales.com
- hntrgg.wanttobuy.biz
- gertg.howtocureerictiledysfunction.net
- fyjtsty.90-4-life.com
- fhdtyf.wanttobuy.biz
- dryhdt.uscoinandjewelry.info
- bnxfg.90-4-life.com
- yjytcd.exopy.com
- drryr.howtocureerictiledysfunction.com
- zsdfwe.checkrealty.info
- rgdff.howtocureerictiledysfunction.com
- ntrdyuj.exopy.com
- fvseds.checkrealty.info
- END
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement