// #MalwareMustDie! Mon Nov 4 23:33:17 JST 2013 // Zombie PC IP Address are used for Multiple Malware // Infection and Botnet. A die hard nodes. Literally "Zombies". // // This post was contribution from OP-Kelihos of MalwareMustDie, // Thank's to the team (further announce is in BotConf) // Which successfully figured the list of zombies used // For multiple Botnets as malicious DNS or etc services. // *) PS: We changed the details, regularly upon updates. // THIS POST IS FOR REFERENCE TAKEDOWN / #TANGO EFFORT - #MMD // IP ADDRESS LIST OF THE ACTIVE ZOMBIES: 106.1.136.109 109.104.175.206 109.106.5.176 109.160.120.112 109.162.101.37 109.239.46.209 111.216.125.132 114.198.185.127 115.165.6.125 119.194.106.139 121.3.74.49 122.250.89.174 123.0.224.85 123.216.223.34 134.249.66.121 176.194.219.212 176.222.255.174 176.50.139.111 176.8.195.123 176.8.203.95 176.8.221.233 176.8.36.164 178.137.35.78 178.137.98.2 178.149.181.242 178.150.134.218 178.150.139.157 178.150.192.50 178.165.32.18 178.206.206.163 178.207.102.167 178.207.86.122 186.22.121.213 188.230.93.206 190.162.80.52 212.21.21.252 212.66.58.220 213.111.203.236 213.157.45.117 213.231.54.89 213.240.209.237 219.110.214.136 219.115.158.12 219.29.85.91 222.230.176.97 31.133.43.89 36.239.190.84 36.239.218.157 36.245.213.112 37.115.143.134 37.115.78.180 37.229.119.183 37.229.72.28 37.57.48.3 46.108.62.76 46.118.204.252 46.211.33.20 46.237.81.153 46.35.227.141 5.104.60.9 5.105.23.87 5.28.111.240 58.3.135.176 60.237.116.235 61.46.101.18 74.129.164.17 77.120.134.104 77.123.227.61 78.84.44.14 79.101.42.7 80.234.86.157 82.33.2.11 87.252.234.72 87.252.245.232 88.206.57.41 89.109.238.163 89.165.154.172 89.176.184.25 89.185.18.68 89.205.2.163 92.52.181.18 93.177.191.145 93.78.123.111 94.154.224.58 95.87.36.234 // Country Region of those Zombies IP: // These can be divided in region ( to confirm the effort possibilities) UA (Ukraine) 35 JP (Japan) 13 RU (Russia) 11 BG (Bulgary) 4 TW (Taiwan) 5 RO (Romania) 2 RS (Serbia) 2 KZ (Kazakstan) 2 BY (Belarus) 2 GB (United Kingdom) 1 GE (Georgia) 1 DE (Germany) 1 AR (Argentine) 1 CL (Chile) 1 US (USA) 1 CZ (Czech) 1 MK (Macedonia) 1 // Zombie IP Addresses per Network details: 106.1.136.109|Tue Oct 29 17:31:02 JST 2013||9924 | 106.1.0.0/16 | TFN | TW | KBRONET.COM.TW | KBRO CO. LTD. 109.104.175.206|Tue Oct 29 17:31:04 JST 2013|ppp-109-104-175-206.wildpark.net.|31272 | 109.104.160.0/19 | WILDPARK | RU | WILDPARK.NET | WILDPARK CO 109.106.5.176|Tue Oct 29 17:31:06 JST 2013|109.106.5.176.sumtel.ua.|15936 | 109.106.0.0/19 | UTN | UA | UKRTRANSSET.COM | UKRTRANS NETWORK LLC 109.160.120.112|Tue Oct 29 17:31:07 JST 2013||12615 | 109.160.120.0/24 | GCN | BG | GCN.BG | GLOBAL COMMUNICATION NET PLC 109.162.101.37|Tue Oct 29 17:31:09 JST 2013|109-162-101-37-sthn.broadband.kyivstar.net.|15895 | 109.162.64.0/18 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 109.239.46.209|Tue Oct 29 17:31:11 JST 2013|209-46-239-109.customers.almanet.kz.|39824 | 109.239.44.0/22 | ALMANET | KZ | ALMATV.KZ | JSC ALMATV 111.216.125.132|Tue Oct 29 17:31:13 JST 2013|pd87d84.sitmnt01.ap.so-net.ne.jp.|2527 | 111.216.0.0/15 | SO | JP | SO-NET.NE.JP | SO-NET SERVICE 114.198.185.127|Tue Oct 29 17:31:15 JST 2013||9924 | 114.198.176.0/20 | TFN | TW | TFN.NET.TW | TFN MEDIA CO. LTD. 115.165.6.125|Tue Oct 29 17:31:16 JST 2013|h115-165-6-125.catv02.itscom.jp.|9365 | 115.165.0.0/17 | ITSCOM | JP | ITSCOM.JP | ITS COMMUNICATIONS INC. 119.194.106.139|Tue Oct 29 17:31:18 JST 2013||4766 | 119.192.0.0/13 | KIXS-AS | KR | KT.COM | KOREA TELECOM 121.3.74.49|Tue Oct 29 17:31:19 JST 2013|p034a31.kngwnt01.ap.so-net.ne.jp.|2527 | 121.2.0.0/15 | SO | JP | SO-NET.NE.JP | SO-NET SERVICE 122.250.89.174|Tue Oct 29 17:31:21 JST 2013|cyadg089174.c-able.ne.jp.|18077 | 122.250.0.0/17 | C | JP | C-ABLE.NE.JP | YAMAGUCHI CABLE VISION CO. LTD. 123.0.224.85|Tue Oct 29 17:31:22 JST 2013|123-0-224-85.nty.dy.tbcnet.net.tw.|4780 | 123.0.224.0/22 | SEEDNET | TW | TBC.US | TBC 123.216.223.34|Tue Oct 29 17:31:24 JST 2013|p1034-ipbf1103sapodori.hokkaido.ocn.ne.jp.|4713 | 123.216.0.0/13 | OCN | JP | OCN.NE.JP | OPEN COMPUTER NETWORK 134.249.66.121|Tue Oct 29 17:31:26 JST 2013|134-249-66-121-gprs.kyivstar.net.|15895 | 134.249.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 176.194.219.212|Tue Oct 29 17:31:29 JST 2013|ip-176-194-219-212.bb.netbynet.ru.|12714 | 176.194.0.0/15 | TI | RU | NETBYNET.RU | NET BY NET HOLDING LLC 176.222.255.174|Tue Oct 29 17:31:30 JST 2013|host-176-222-255-174.ugmk-telecom.ru.|41560 | 176.222.254.0/23 | UT | RU | UGMK-TELECOM.RU | UGMK-TELECOM LLC 176.50.139.111|Tue Oct 29 17:31:32 JST 2013|176.50.139-111.xdsl.ab.ru.|41440 | 176.50.128.0/18 | SIBIRTELECOM | RU | SIBIRTELECOM.RU | OJSC SIBIRTELECOM 176.8.195.123|Tue Oct 29 17:31:34 JST 2013|176-8-195-123-krr.broadband.kyivstar.net.|15895 | 176.8.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 176.8.203.95|Tue Oct 29 17:31:35 JST 2013|176-8-203-95-khe.broadband.kyivstar.net.|15895 | 176.8.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 176.8.221.233|Tue Oct 29 17:31:37 JST 2013|176-8-221-233-smln.broadband.kyivstar.net.|15895 | 176.8.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 176.8.36.164|Tue Oct 29 17:31:38 JST 2013|176-8-36-164-broadband.kyivstar.net.|15895 | 176.8.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 178.137.35.78|Tue Oct 29 17:31:40 JST 2013|178-137-35-78-kre.broadband.kyivstar.net.|15895 | 178.137.0.0/17 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 178.137.98.2|Tue Oct 29 17:31:42 JST 2013|178-137-98-2-krr.broadband.kyivstar.net.|15895 | 178.137.0.0/17 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 178.149.181.242|Tue Oct 29 17:31:45 JST 2013|cable-178-149-181-242.dynamic.sbb.rs.|31042 | 178.149.0.0/16 | SERBIA-BROADBAND | RS | SBB.RS | SERBIA BROADBAND 178.150.134.218|Tue Oct 29 17:31:46 JST 2013|218.134.150.178.triolan.net.|13188 | 178.150.132.0/22 | BANKINFORM | UA | UKR.NET | TOV BANK-INFORM 178.150.139.157|Tue Oct 29 17:31:48 JST 2013|157.139.150.178.triolan.net.|13188 | 178.150.136.0/22 | BANKINFORM | UA | UKR.NET | TOV BANK-INFORM 178.150.192.50|Tue Oct 29 17:31:50 JST 2013|50.192.150.178.triolan.net.|13188 | 178.150.192.0/21 | BANKINFORM | UA | UKR.NET | TOV BANK-INFORM 178.165.32.18|Tue Oct 29 17:31:52 JST 2013|undef-salt-kh.maxnet.ua.|34700 | 178.165.0.0/18 | CITYNET | UA | MAXNET.UA | MAXNET TELECOM LTD 178.206.206.163|Tue Oct 29 17:31:54 JST 2013||28840 | 178.206.192.0/19 | TATTELECOM | RU | KGTS.RU | TATARSTAN BROAD-BAND ACCESS POOLS 178.207.102.167|Tue Oct 29 17:31:55 JST 2013||28840 | 178.207.0.0/16 | TATTELECOM | RU | KGTS.RU | TATARSTAN BROAD-BAND ACCESS POOLS 178.207.86.122|Tue Oct 29 17:31:57 JST 2013||28840 | 178.207.80.0/20 | TATTELECOM | RU | KGTS.RU | TATARSTAN BROAD-BAND ACCESS POOLS 186.22.121.213|Tue Oct 29 17:31:59 JST 2013|cpe-186-22-121-213.telecentro-reversos.com.ar.|27747 | 186.22.112.0/20 | Telecentro | AR | TELECENTRO-REVERSOS.COM.AR | TELECENTRO S.A. 188.230.93.206|Tue Oct 29 17:32:00 JST 2013|ip-188-230-93-206.airbites.net.ua.|43266 | 188.230.92.0/23 | ABUA | UA | AIRBITES.NET.UA | LLC AB UKRAINE 190.162.80.52|Tue Oct 29 17:32:02 JST 2013|pc-52-80-162-190.cm.vtr.net.|22047 | 190.162.80.0/21 | VTR | CL | VTR.NET | VTR BANDA ANCHA S.A. 212.21.21.252|Tue Oct 29 17:32:04 JST 2013|252.21.21.212.vpn.mgn.ru.|8427 | 212.21.16.0/20 | MAGINFO | RU | MGN.RU | MAGINFO JSC 212.66.58.220|Tue Oct 29 17:32:05 JST 2013||6886 | 212.66.48.0/20 | INTS | UA | INTS.NET | DATA INTERNET LTD 213.111.203.236|Tue Oct 29 17:32:07 JST 2013|236.203-pool.nikopol.net.|44924 | 213.111.192.0/18 | MAINSTREAM | UA | NIKOPOL.NET | PP MAINSTREAM 213.157.45.117|Tue Oct 29 17:32:09 JST 2013||8393 | 213.157.45.0/24 | NEWTECH | KZ | ASTEL.NET | ASTEL JSC 213.231.54.89|Tue Oct 29 17:32:11 JST 2013|213.231.54.89.pool.breezein.net.|34661 | 213.231.0.0/18 | BREEZE | UA | BREEZEIN.NET | TOV TRK BRIZ 213.240.209.237|Tue Oct 29 17:32:14 JST 2013||13124 | 213.240.208.0/20 | IBGC | BG | BLIZOO.BG | BLIZOO MEDIA AND BROADBAND EAD 219.110.214.136|Tue Oct 29 17:32:15 JST 2013|h219-110-214-136.catv02.itscom.jp.|9365 | 219.110.0.0/16 | ITSCOM | JP | ITSCOM.JP | ITS COMMUNICATIONS INC. 219.115.158.12|Tue Oct 29 17:32:17 JST 2013|zaqdb739e0c.zaq.ne.jp.|9617 | 219.115.128.0/19 | ZAQ | JP | JCOM.CO.JP | J:COM WEST CO. LTD. 219.29.85.91|Tue Oct 29 17:32:18 JST 2013|softbank219029085091.bbtec.net.|17676 | 219.29.0.0/16 | GIGAINFRA | JP | SOFTBANKBB.CO.JP | SOFTBANK BB CORP 222.230.176.97|Tue Oct 29 17:32:20 JST 2013|s97.176.230.222.fls.vectant.ne.jp.|2519 | 222.230.0.0/16 | VECTANT | JP | FNJ.CO.JP | FAMILY NET JAPAN INCORPORATED 31.133.43.89|Tue Oct 29 17:32:21 JST 2013||52091 | 31.133.32.0/19 | TRUBNIKOV | UA | - | FOP TRUBNIKOV VALERIY MUHAYLOVICH 36.239.190.84|Tue Oct 29 17:32:23 JST 2013|36-239-190-84.dynamic-ip.hinet.net.|3462 | 36.239.0.0/16 | HINET | TW | CHT.COM.TW | CHTD CHUNGHWA TELECOM CO. LTD. 36.239.218.157|Tue Oct 29 17:32:30 JST 2013||3462 | 36.239.0.0/16 | HINET | TW | CHT.COM.TW | CHTD CHUNGHWA TELECOM CO. LTD. 36.245.213.112|Tue Oct 29 17:32:32 JST 2013|em36-245-213-112.pool.e-mobile.ne.jp.|9609 | 36.244.0.0/15 | EACCESS | JP | EACCESS.NET | EACCESS LTD. 37.115.143.134|Tue Oct 29 17:32:34 JST 2013|37-115-143-134-broadband.kyivstar.net.|15895 | 37.115.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 37.115.78.180|Tue Oct 29 17:32:36 JST 2013|37-115-78-180-broadband.kyivstar.net.|15895 | 37.115.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 37.229.119.183|Tue Oct 29 17:32:37 JST 2013|37-229-119-183-broadband.kyivstar.net.|15895 | 37.229.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 37.229.72.28|Tue Oct 29 17:32:38 JST 2013|37-229-72-28-broadband.kyivstar.net.|15895 | 37.229.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 37.57.48.3|Tue Oct 29 17:32:40 JST 2013|3.48.57.37.triolan.net.|13188 | 37.57.48.0/21 | BANKINFORM | UA | UKR.NET | TOV BANK-INFORM 46.108.62.76|Tue Oct 29 17:32:43 JST 2013|hosted-by.levelhost.net.|5541 | 46.108.60.0/22 | ADNET | RO | HOSTPAY.RO | C&A CONNECT SRL 46.118.204.252|Tue Oct 29 17:32:44 JST 2013|SOL-FTTB.252.204.118.46.sovam.net.ua.|15895 | 46.118.0.0/16 | KSNET | UA | SOVAM.NET.UA | GOLDEN TELECOM 46.211.33.20|Tue Oct 29 17:32:46 JST 2013|46-211-33-20-chg.broadband.kyivstar.net.|15895 | 46.211.0.0/17 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC 46.237.81.153|Tue Oct 29 17:32:48 JST 2013|46-237-81-153.pz.ddns.bulsat.com.|43205 | 46.237.64.0/18 | BULSATCOM-BG | BG | BULSAT.COM | BULSATCOM AD 46.35.227.141|Tue Oct 29 17:32:49 JST 2013|141-227-35-46.host.sevstar.net.|35816 | 46.35.224.0/19 | SEVSTAR | UA | LANCOM.GR | LANCOM LTD. 5.104.60.9|Tue Oct 29 17:32:51 JST 2013|5-104-60-9.mytrinity.com.ua.| | | | UA | MYTRINITY.COM.UA | CIFROVYE DISPETCHERSKIE SISTEMY 5.105.23.87|Tue Oct 29 17:32:53 JST 2013|5-105-23-87.mytrinity.com.ua.|43554 | 5.105.0.0/16 | CDS | UA | MYTRINITY.COM.UA | CIFROVYE DISPETCHERSKIE SISTEMY 5.28.111.240|Tue Oct 29 17:32:55 JST 2013|cable-5-28-111-240.cust.telecolumbus.net.|20880 | 5.28.64.0/18 | BLUE | DE | BLUE-CABLE.NET | TELE COLUMBUS GMBH 58.3.135.176|Tue Oct 29 17:32:57 JST 2013|58-3-135-176.ppp.bbiq.jp.|7679 | 58.3.128.0/17 | QTNET | JP | QTNET.CO.JP | KYUSHU TELECOMMUNICATION NETWORK CO. INC. 60.237.116.235|Tue Oct 29 17:32:59 JST 2013|FLH1Aaz107.myg.mesh.ad.jp.|2518 | 60.236.0.0/14 | BIGLOBE | JP | BIGLOBE.NE.JP | NEC BIGLOBE LTD. 61.46.101.18|Tue Oct 29 17:33:00 JST 2013|zaq3d2e6512.zaq.ne.jp.|9617 | 61.46.0.0/17 | ZAQ | JP | JCOM.CO.JP | J:COM WEST CO. LTD. 74.129.164.17|Tue Oct 29 17:33:02 JST 2013|74-129-164-17.dhcp.insightbb.com.|10796 | 74.128.0.0/12 | SCRR-10796 | US | MYINSIGHT.COM | INSIGHT COMMUNICATIONS COMPANY L.P. 77.120.134.104|Tue Oct 29 17:33:05 JST 2013|77-120-134-104.dynamic-FTTB.datasvit.net.|25229 | 77.120.128.0/18 | VOLIA | UA | VOLIA.NET | KYIVSKI TELEKOMUNIKATSIYNI MEREZHI LLC 77.123.227.61|Tue Oct 29 17:33:07 JST 2013||48169 | 77.123.224.0/19 | IVC | UA | VOLIA.NET | KYIVSKI TELEKOMUNIKATSIYNI MEREZHI LLC 78.84.44.14|Tue Oct 29 17:33:08 JST 2013||12578 | 78.84.0.0/16 | APOLLO | LV | - | ADDRESS POOL FOR LTC-HOME CUSTOMERS 79.101.42.7|Tue Oct 29 17:33:10 JST 2013||8400 | 79.101.0.0/16 | TELEKOM | RS | - | SA ELEKTRONIK KOSOVSKA MITROVICA 80.234.86.157|Tue Oct 29 17:33:12 JST 2013||15500 | 80.234.0.0/17 | OJSC | RU | TOLCOM.RU | FOR CLIENT TOGLIATTI COMMUNICATION TSINFORM 82.33.2.11|Tue Oct 29 17:33:14 JST 2013|cpc3-jarr13-2-0-cust522.16-2.cable.virginm.net.|5089 | 82.32.0.0/15 | NTL | GB | VIRGINMEDIA.COM | VIRGIN MEDIA LIMITED 87.252.234.72|Tue Oct 29 17:33:16 JST 2013|87.252.234.72.vpn.garant.by.|50334 | 87.252.234.0/24 | GARANT | BY | NETLAND.BY | MOBILE SERVICE LTD. 87.252.245.232|Tue Oct 29 17:33:17 JST 2013||50334 | 87.252.245.0/24 | GARANT | BY | NETLAND.BY | MOBILE SERVICE LTD. 88.206.57.41|Tue Oct 29 17:33:19 JST 2013|pool-88-206-57-41.is74.ru.|8369 | 88.206.0.0/17 | INTERSVYAZ | RU | IS74.RU | INTERSVYAZ-2 JSC 89.109.238.163|Tue Oct 29 17:33:21 JST 2013||25515 | 89.109.192.0/18 | CTCNET | RU | - | ROSTELECOM MOSCOW REGION BRANCH 89.165.154.172|Tue Oct 29 17:33:22 JST 2013|89-165-154-172.next-gen.ro.|48161 | 89.165.152.0/22 | NG | RO | NEXT-GEN.RO | ODORHEIU SECUIESC 89.176.184.25|Tue Oct 29 17:33:24 JST 2013|ip-89-176-184-25.net.upcbroadband.cz.|6830 | 89.176.0.0/16 | LGI | CZ | UPCBROADBAND.CZ | UPC CESKA REPUBLIKA A.S. 89.185.18.68|Tue Oct 29 17:33:26 JST 2013|CPE137068.tvcom.net.ua.|57033 | 89.185.16.0/21 | TVCOM-ALTAIR | UA | TVCOM.NET.UA | TVCOM LTD. 89.205.2.163|Tue Oct 29 17:33:27 JST 2013|89.205.2.163.robi.com.mk.|41557 | 89.205.0.0/21 | MEGANET | MK | ROBI.COM.MK | MEGANET 92.52.181.18|Tue Oct 29 17:33:29 JST 2013|| | | | UA | BIT.TE.UA | BITTERNET LTD 93.177.191.145|Tue Oct 29 17:33:42 JST 2013|host-93-177-191-145.customer.co.ge.| | | | GE | CAUCASUS.NET | CAUCASUS ONLINE LTD. 93.78.123.111|Tue Oct 29 17:33:45 JST 2013||25229 | 93.78.112.0/20 | VOLIA | UA | VOLIA.NET | KYIVSKI TELEKOMUNIKATSIYNI MEREZHI LLC 94.154.224.58|Tue Oct 29 17:33:46 JST 2013|ip-e03a.d-net.kiev.ua.| | | | UA | D-NET.KIEV.UA | DELTA-NET LLC 95.87.36.234|Tue Oct 29 17:33:49 JST 2013|ip-95-87-36-234.trakiacable.net.|38924 | 95.87.0.0/18 | AS | BG | TRAKIACABLE.NET | TRAKIA KABEL OOD // HOW LONG CAN THESE IP GOES?? // Behold the PoC of the "Anniversary" Zombie-IP: 94.154.224.58 : "bugfivin.ru.","bugfivin.ru","A","94.154.224.58","2013-01-27 04:08:08","2013-01-27 04:08:31","2","0:00:23" "didcufun.ru.","didcufun.ru","A","94.154.224.58","2013-01-31 02:04:51","2013-01-31 02:04:51","1","0:00:00" "diteqciq.ru.","diteqciq.ru","A","94.154.224.58","2013-01-28 00:07:21","2013-01-28 00:07:32","2","0:00:11" "ecrihgep.ru.","ecrihgep.ru","A","94.154.224.58","2013-01-31 23:27:43","2013-01-31 23:27:43","1","0:00:00" "www.isbegisy.ru.","isbegisy.ru","A","94.154.224.58","2013-01-31 02:03:49","2013-01-31 02:03:49","1","0:00:00" "iwhuwugy.ru.","iwhuwugy.ru","A","94.154.224.58","2013-01-30 01:10:31","2013-03-16 03:03:29","4","45 days "joljihuk.ru.","joljihuk.ru","A","94.154.224.58","2013-01-29 04:21:07","2013-02-26 01:33:55","3","27 days "merwiqca.ru.","merwiqca.ru","A","94.154.224.58","2013-01-28 04:01:26","2013-02-17 23:08:48","5","20 days "soduvnec.ru.","soduvnec.ru","A","94.154.224.58","2013-01-29 04:07:32","2013-02-27 03:50:51","8","28 days "ip-e03a.d-net.kiev.ua.","d-net.kiev.ua","A","94.154.224.58","2013-01-28 06:27:59","2013-10-06 00:47:35","180","250 days "oparle.com.","oparle.com","A","94.154.224.58","2013-01-27 01:50:11","2013-05-19 00:05:54","194","111 days "ns1.oparle.com.","oparle.com","A","94.154.224.58","2013-01-28 05:23:10","2013-05-18 02:26:03","19","109 days "ns2.oparle.com.","oparle.com","A","94.154.224.58","2013-01-31 01:52:47","2013-03-25 13:39:18","91","53 days "ns3.oparle.com.","oparle.com","A","94.154.224.58","2013-01-31 01:52:47","2013-04-17 05:19:07","113","76 days "ns4.oparle.com.","oparle.com","A","94.154.224.58","2013-01-27 03:16:43","2013-04-19 05:08:43","69","82 days "ns1.boomsco.com.","boomsco.com","A","94.154.224.58","2013-01-29 23:25:30","2013-04-12 04:02:48","73","72 days "ns2.boomsco.com.","boomsco.com","A","94.154.224.58","2013-01-31 03:28:21","2013-03-24 03:04:17","110","51 days "ns3.boomsco.com.","boomsco.com","A","94.154.224.58","2013-01-30 03:29:59","2013-04-05 02:11:39","1903","64 days "ns4.boomsco.com.","boomsco.com","A","94.154.224.58","2013-01-27 01:43:35","2013-03-04 02:44:58","809","36 days "ns5.boomsco.com.","boomsco.com","A","94.154.224.58","2013-01-29 23:25:30","2013-03-04 05:40:37","52","33 days "ns6.boomsco.com.","boomsco.com","A","94.154.224.58","2013-01-27 02:39:11","2013-04-05 01:13:29","77","67 days "ns1.larstor.com.","larstor.com","A","94.154.224.58","2013-01-27 04:06:42","2013-05-06 03:18:29","286","98 days "ns2.larstor.com.","larstor.com","A","94.154.224.58","2013-01-27 04:07:10","2013-04-05 06:13:37","74","68 days "ns3.larstor.com.","larstor.com","A","94.154.224.58","2013-01-27 04:06:42","2013-03-23 01:26:52","35","54 days "ns4.larstor.com.","larstor.com","A","94.154.224.58","2013-01-27 04:06:42","2013-04-05 05:13:26","129","68 days "ns5.larstor.com.","larstor.com","A","94.154.224.58","2013-01-27 20:38:37","2013-04-05 00:14:13","160","67 days "ns6.larstor.com.","larstor.com","A","94.154.224.58","2013-01-28 04:01:42","2013-04-05 04:12:08","84","67 days "ns3.newrect.com.","newrect.com","A","94.154.224.58","2013-01-30 01:04:56","2013-04-02 04:05:44","592","62 days "ns4.newrect.com.","newrect.com","A","94.154.224.58","2013-01-29 02:07:53","2013-04-09 13:12:08","232","70 days "ns6.newrect.com.","newrect.com","A","94.154.224.58","2013-01-27 21:34:00","2013-04-05 20:13:15","311","67 days --- #MalwareMustDIE!!!!!! OP-KELIHOS, MMD, 2013. @VriesHd @kellewic @DhiaLite @Secluded_Memory @unixfreaxjp