Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Thu, Nov 14 2013
- #DhiaLite - New campaign of suspicious short lived .pl subdomains shifted from 109.236.83.184 to start resolving to 109.236.83.185 today and still going on.
- Follow up to http://pastebin.com/s8ARXGd2
- Spike in traffic for these subdomains then they stop resolving.
- Possibly used for a similar Malvertising -> EK -> ransomware campaign as in
- http://www.malekal.com/2013/07/31/en-urausy-adultfriendzfinder-malvertising-banner/
- Yet to be confirmed.
- Currently about 180+ subdomains have resolved to this IP, and more are popping up.
- These subdomains are registered under the Polish cities 2LDs
- olecko.pl
- pruszkow.pl
- #Sample of subdomains on 109.236.83.185
- warkz.immowelt.pruszkow.pl
- votef.immowelt.pruszkow.pl
- unite.geradorcpf.pruszkow.pl
- twitt.ultimate-codecs.pruszkow.pl
- triip.immowelt.pruszkow.pl
- telsp.ultimate-codecs.pruszkow.pl
- taomi.geradorcpf.pruszkow.pl
- softc.googlewebmastercentral.pruszkow.pl
- sipel.adready.pruszkow.pl
- silic.ultimate-codecs.pruszkow.pl
- shopc.googlewebmastercentral.pruszkow.pl
- shema.immowelt.pruszkow.pl
- selfp.geradorcpf.pruszkow.pl
- ptb.googlewebmastercentral.pruszkow.pl
- podfo.ultimate-codecs.pruszkow.pl
- pisoc.adready.pruszkow.pl
- offrm.googlewebmastercentral.pruszkow.pl
- nnsta.immowelt.pruszkow.pl
- nhe.ultimate-codecs.pruszkow.pl
- natur.googlewebmastercentral.pruszkow.pl
- morph.rusavtobus.pruszkow.pl
- mabul.geradorcpf.pruszkow.pl
- livin.geradorcpf.pruszkow.pl
- listl.ultimate-codecs.pruszkow.pl
- kunst.googlewebmastercentral.pruszkow.pl
- krist.googlewebmastercentral.pruszkow.pl
- kinli.googlewebmastercentral.pruszkow.pl
- jvep.immowelt.pruszkow.pl
- jooml.googlewebmastercentral.pruszkow.pl
- jirit.geradorcpf.pruszkow.pl
- iread.geradorcpf.pruszkow.pl
- idcco.googlewebmastercentral.pruszkow.pl
- huizh.adready.pruszkow.pl
- hsbc.adready.pruszkow.pl
- hlera.googlewebmastercentral.pruszkow.pl
- goolb.adready.pruszkow.pl
- goind.adready.pruszkow.pl
- genpi.rusavtobus.pruszkow.pl
- funti.adready.pruszkow.pl
- ftimg.adready.pruszkow.pl
- foris.immowelt.pruszkow.pl
- flixh.ultimate-codecs.pruszkow.pl
- fairb.ultimate-codecs.pruszkow.pl
- eskim.rusavtobus.pruszkow.pl
- diabl.geradorcpf.pruszkow.pl
- devil.adready.pruszkow.pl
- deser.geradorcpf.pruszkow.pl
- carlo.ultimate-codecs.pruszkow.pl
- burgc.geradorcpf.pruszkow.pl
- betds.adready.pruszkow.pl
- berke.immowelt.pruszkow.pl
- baker.geradorcpf.pruszkow.pl
- afric.immowelt.pruszkow.pl
- addur.rusavtobus.pruszkow.pl
- zeist.ctvwm.olecko.pl
- yytcd.hytera.olecko.pl
- yumen.verisign.olecko.pl
- yoshi.bmbets.olecko.pl
- wigif.ristrutturazioni-case.olecko.pl
- wifih.hooriat.olecko.pl
- whorl.bmbets.olecko.pl
- whole.americansongwriter.olecko.pl
- werwi.hooriat.olecko.pl
- wallb.americansongwriter.olecko.pl
- vienn.ctvwm.olecko.pl
- vidya.lineshjose.olecko.pl
- victo.bmbets.olecko.pl
- venau.verisign.olecko.pl
- venam.americansongwriter.olecko.pl
- uprb.appriver.olecko.pl
- unsha.jumbo.olecko.pl
- ubala.talesfromtammylyne.olecko.pl
- tubes.verisign.olecko.pl
- trade.talesfromtammylyne.olecko.pl
- topha.mix-computer.olecko.pl
- tiger.dalailama.olecko.pl
- thetr.ristrutturazioni-case.olecko.pl
- thecf.uaudio.olecko.pl
- thcgr.lineshjose.olecko.pl
- surfc.appriver.olecko.pl
- straw.verisign.olecko.pl
- start.americansongwriter.olecko.pl
- sodom.dalailama.olecko.pl
- sitec.jumbo.olecko.pl
- shmil.jumbo.olecko.pl
- setev.verisign.olecko.pl
- sensa.appriver.olecko.pl
- semin.hooriat.olecko.pl
- scu2c.uaudio.olecko.pl
- scano.verisign.olecko.pl
- salom.ctvwm.olecko.pl
- riode.uaudio.olecko.pl
- ricks.hytera.olecko.pl
- rejas.hytera.olecko.pl
- redar.mix-computer.olecko.pl
- rdica.amazeelabs.olecko.pl
- rakba.usi.olecko.pl
- quepu.bmbets.olecko.pl
- py4ki.usi.olecko.pl
- proxy.ctvwm.olecko.pl
- pront.usi.olecko.pl
- photo.jumbo.olecko.pl
- perpu.uaudio.olecko.pl
- ovb.isis.olecko.pl
- optip.verisign.olecko.pl
- onlyw.jumbo.olecko.pl
- onlin.americansongwriter.olecko.pl
- newst.talesfromtammylyne.olecko.pl
- nasai.uaudio.olecko.pl
- nadpr.mix-computer.olecko.pl
- myher.jumbo.olecko.pl
- mwome.dalailama.olecko.pl
- mweor.bmbets.olecko.pl
- mutoj.usi.olecko.pl
- music.mix-computer.olecko.pl
- micha.isis.olecko.pl
- meyam.hytera.olecko.pl
- mediz.americansongwriter.olecko.pl
- masti.amazeelabs.olecko.pl
- marke.talesfromtammylyne.olecko.pl
- makec.ctvwm.olecko.pl
- lovem.ctvwm.olecko.pl
- lovec.hooriat.olecko.pl
- liber.rusavtobus.pruszkow.pl
- letsc.ctvwm.olecko.pl
- lescm.usi.olecko.pl
- leice.lineshjose.olecko.pl
- ksc.hooriat.olecko.pl
- kentu.talesfromtammylyne.olecko.pl
- jahan.dalailama.olecko.pl
- inspi.lineshjose.olecko.pl
- infob.ctvwm.olecko.pl
- iconi.talesfromtammylyne.olecko.pl
- homet.appriver.olecko.pl
- heyra.ristrutturazioni-case.olecko.pl
- hansn.ristrutturazioni-case.olecko.pl
- golfg.bmbets.olecko.pl
- go4sm.appriver.olecko.pl
- giftb.jumbo.olecko.pl
- funfo.usi.olecko.pl
- franq.dalailama.olecko.pl
- flahe.americansongwriter.olecko.pl
- firew.amazeelabs.olecko.pl
- fastp.lineshjose.olecko.pl
- farso.verisign.olecko.pl
- elpat.usi.olecko.pl
- ellap.dalailama.olecko.pl
- ejecu.hooriat.olecko.pl
- eigoe.mix-computer.olecko.pl
- ecol.ctvwm.olecko.pl
- dobal.lineshjose.olecko.pl
- diceb.ristrutturazioni-case.olecko.pl
- csccs.lineshjose.olecko.pl
- cpeas.rusavtobus.pruszkow.pl
- coupo.usi.olecko.pl
- conte.verisign.olecko.pl
- concr.isis.olecko.pl
- cnl.usi.olecko.pl
- cnjia.verisign.olecko.pl
- choic.dalailama.olecko.pl
- child.talesfromtammylyne.olecko.pl
- cheer.appriver.olecko.pl
- catho.amazeelabs.olecko.pl
- blogc.amazeelabs.olecko.pl
- bible.hooriat.olecko.pl
- belgi.ctvwm.olecko.pl
- bdweb.ctvwm.olecko.pl
- bdsma.hytera.olecko.pl
- bayen.usi.olecko.pl
- baiju.amazeelabs.olecko.pl
- azlog.usi.olecko.pl
- audio.bmbets.olecko.pl
- ateli.hytera.olecko.pl
- astur.jumbo.olecko.pl
- ashta.appriver.olecko.pl
- artio.amazeelabs.olecko.pl
- antic.amazeelabs.olecko.pl
- aneca.appriver.olecko.pl
- analp.ctvwm.olecko.pl
- amazi.amazeelabs.olecko.pl
- allac.mix-computer.olecko.pl
- END
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement