Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Thu, Nov 14 2013
- #DhiaLite - New campaign of suspicious short lived .pl subdomains shifted from 5.152.194.51 and started resolving to 5.152.194.52 since yesterday and still going on.
- Spike in traffic for these subdomains then they stop resolving.
- Possibly used for a similar Malvertising -> EK -> ransomware campaign as in
- http://www.malekal.com/2013/07/31/en-urausy-adultfriendzfinder-malvertising-banner/
- Yet to be confirmed.
- Currently about 190+ subdomains have resolved to this IP, and more are popping up.
- These subdomains are registered under the Polish city 2LD
- olecko.pl
- #Sample of subdomains on 5.152.194.52
- yugio.demandmetric.olecko.pl
- wowsh.carrapide.olecko.pl
- world.cospi.olecko.pl
- westo.how-to-learn-any-language.olecko.pl
- webgr.snowinn.olecko.pl
- visas.videochat-nonadult.olecko.pl
- urban.rudebox.olecko.pl
- updat.ktaby.olecko.pl
- uoct.carrapide.olecko.pl
- ultra.curatorseye.olecko.pl
- uktut.seuhentai.olecko.pl
- tubex.ktaby.olecko.pl
- thevo.how-to-learn-any-language.olecko.pl
- thesk.card-db.olecko.pl
- there.nanokamo.olecko.pl
- theda.networksaigon.olecko.pl
- thecp.elbagalindo.olecko.pl
- takem.rudebox.olecko.pl
- subir.carrapide.olecko.pl
- store.card-db.olecko.pl
- start.hellobc.olecko.pl
- stamb.rhinoslider.olecko.pl
- ssm.armaniwatchescheap.olecko.pl
- spide.ummulqura.olecko.pl
- skymi.iraqiyat.olecko.pl
- shofh.ummulqura.olecko.pl
- seria.snowinn.olecko.pl
- seopu.rhinoslider.olecko.pl
- seodn.apexoo.olecko.pl
- senib.rudebox.olecko.pl
- seika.ashro.olecko.pl
- safet.cospi.olecko.pl
- royle.koyalwholesale.olecko.pl
- robyn.apexoo.olecko.pl
- respu.networksaigon.olecko.pl
- regin.card-db.olecko.pl
- redho.hellobc.olecko.pl
- reatr.freecsstemplates.olecko.pl
- ptzce.carrapide.olecko.pl
- promo.networksaigon.olecko.pl
- promo.momseries.olecko.pl
- prcit.card-db.olecko.pl
- pot.momseries.olecko.pl
- portm.hellobc.olecko.pl
- pokaz.rhinoslider.olecko.pl
- pinks.apexoo.olecko.pl
- picpa.ktaby.olecko.pl
- phpbb.seuhentai.olecko.pl
- paxba.rhinoslider.olecko.pl
- ourla.mamahawaa.olecko.pl
- optim.nanokamo.olecko.pl
- notef.ummulqura.olecko.pl
- newyo.curatorseye.olecko.pl
- naxaf.videochat-nonadult.olecko.pl
- naini.momseries.olecko.pl
- mylds.hellobc.olecko.pl
- mpmca.koyalwholesale.olecko.pl
- mostp.armaniwatchescheap.olecko.pl
- mn123.demandmetric.olecko.pl
- mmnew.polibiobraga.olecko.pl
- misst.iraqiyat.olecko.pl
- minda.snowinn.olecko.pl
- michn.iraqiyat.olecko.pl
- masr.cospi.olecko.pl
- masco.ktaby.olecko.pl
- manke.paperjobsads.olecko.pl
- makin.armaniwatchescheap.olecko.pl
- loven.networksaigon.olecko.pl
- livep.cospi.olecko.pl
- light.videochat-nonadult.olecko.pl
- lesbi.mamahawaa.olecko.pl
- lerel.momseries.olecko.pl
- lendi.elbagalindo.olecko.pl
- kycdc.apexoo.olecko.pl
- kubun.snowinn.olecko.pl
- koneb.freecsstemplates.olecko.pl
- koles.iraqiyat.olecko.pl
- kesou.iraqiyat.olecko.pl
- juliu.seuhentai.olecko.pl
- jnd.makelove.olecko.pl
- jelli.rhinoslider.olecko.pl
- inter.mamahawaa.olecko.pl
- inter.carrapide.olecko.pl
- intel.apexoo.olecko.pl
- infoc.seuhentai.olecko.pl
- indig.mamahawaa.olecko.pl
- imark.koyalwholesale.olecko.pl
- ikent.demandmetric.olecko.pl
- iffmh.carrapide.olecko.pl
- hpmcs.card-db.olecko.pl
- hmong.armaniwatchescheap.olecko.pl
- globa.ashro.olecko.pl
- gilse.mamahawaa.olecko.pl
- gfsrv.freecsstemplates.olecko.pl
- gamet.ktaby.olecko.pl
- galar.rudebox.olecko.pl
- g4s.how-to-learn-any-language.olecko.pl
- fxcpr.demandmetric.olecko.pl
- friso.armaniwatchescheap.olecko.pl
- freec.rudebox.olecko.pl
- freeb.ktaby.olecko.pl
- frank.curatorseye.olecko.pl
- flucc.ashro.olecko.pl
- fishn.iraqiyat.olecko.pl
- feech.seuhentai.olecko.pl
- fathe.momseries.olecko.pl
- editi.curatorseye.olecko.pl
- ecred.how-to-learn-any-language.olecko.pl
- eastw.polibiobraga.olecko.pl
- dortm.snowinn.olecko.pl
- dekuc.momseries.olecko.pl
- dealm.elbagalindo.olecko.pl
- deadc.card-db.olecko.pl
- dce.nanokamo.olecko.pl
- david.mamahawaa.olecko.pl
- daddy.ashro.olecko.pl
- ctek.rhinoslider.olecko.pl
- cread.seuhentai.olecko.pl
- comas.paperjobsads.olecko.pl
- clubt.mamahawaa.olecko.pl
- clipa.polibiobraga.olecko.pl
- class.rudebox.olecko.pl
- cieka.apexoo.olecko.pl
- chine.nanokamo.olecko.pl
- centr.makelove.olecko.pl
- cente.demandmetric.olecko.pl
- ccpcj.nanokamo.olecko.pl
- camer.videochat-nonadult.olecko.pl
- bolga.freecsstemplates.olecko.pl
- bobri.polibiobraga.olecko.pl
- blog.ashro.olecko.pl
- black.how-to-learn-any-language.olecko.pl
- beast.ummulqura.olecko.pl
- artil.momseries.olecko.pl
- aluae.ashro.olecko.pl
- allsu.videochat-nonadult.olecko.pl
- agitk.videochat-nonadult.olecko.pl
- advan.koyalwholesale.olecko.pl
- ace.curatorseye.olecko.pl
- xexun.evolver.olecko.pl
- winju.smartbuy.olecko.pl
- whats.searchbug.olecko.pl
- tubel.realtid.olecko.pl
- toyru.realtid.olecko.pl
- total.i3tracking.olecko.pl
- theim.i3tracking.olecko.pl
- tcte.realtid.olecko.pl
- suppo.hotlist.olecko.pl
- super.mercialfred.olecko.pl
- sunto.hotlist.olecko.pl
- sourc.mercialfred.olecko.pl
- sexok.hotlist.olecko.pl
- qads1.i3tracking.olecko.pl
- publi.articlecabi.olecko.pl
- pront.mercialfred.olecko.pl
- pratt.articlecabi.olecko.pl
- pestw.articlecabi.olecko.pl
- perfo.pushbuttoncomputing.olecko.pl
- param.i3tracking.olecko.pl
- paraj.articlecabi.olecko.pl
- pandu.smartbuy.olecko.pl
- packe.pushbuttoncomputing.olecko.pl
- over3.evolver.olecko.pl
- onlin.mercialfred.olecko.pl
- onest.i3tracking.olecko.pl
- nucoo.searchbug.olecko.pl
- mohse.searchbug.olecko.pl
- miche.i3tracking.olecko.pl
- mcwto.smartbuy.olecko.pl
- lorea.evolver.olecko.pl
- laure.smartbuy.olecko.pl
- ippom.mercialfred.olecko.pl
- inves.pushbuttoncomputing.olecko.pl
- inupp.i3tracking.olecko.pl
- hotel.searchbug.olecko.pl
- heell.hotlist.olecko.pl
- girls.realtid.olecko.pl
- ginno.hotlist.olecko.pl
- freew.realtid.olecko.pl
- festi.articlecabi.olecko.pl
- every.searchbug.olecko.pl
- eliza.pushbuttoncomputing.olecko.pl
- elear.evolver.olecko.pl
- edjo.realtid.olecko.pl
- downl.pushbuttoncomputing.olecko.pl
- didyo.pushbuttoncomputing.olecko.pl
- conve.articlecabi.olecko.pl
- civil.evolver.olecko.pl
- cheap.realtid.olecko.pl
- andik.smartbuy.olecko.pl
- aasga.pushbuttoncomputing.olecko.pl
- a7lam.evolver.olecko.pl
- END
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement