Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ====================================================
- #MalwareMustDie!
- Registrar Name.com LLC's stolen/hacked user's domains
- is used to serve evil DNS malware infector
- with base service IP:PORT 173.246.102.246:80
- Serving Blackholes & Ransomwares
- @unixfreaxjp /malware]$ date
- Fri Jan 11 20:18:19 JST 2013
- ====================================================
- //Infector IP to block:
- 173.246.102.246
- //infector domains:
- 11.livinghistorytheatre.ca
- 11.laptopvspc.com
- 11.sephoracouponscode.com
- 11.awarenesscreateschange.com
- 11.livinghistorytheatre.com
- 11.b2cviaggi.com
- 11.13dayz.com
- 11.lamarianella.info
- 11.lwin.ws
- 11.studiocitynorth.tv
- 11.scntv.tv
- :
- ===========================
- Malware infector activities
- ==========================
- // Blackholes.....
- http://11.lamarianella.info/read/engineering_best.php
- http://11.studiocitynorth.tv/read/defined_regulations-frequently.php?eshx=1m:30:2v:1h:1k&fkil=1h:1l:1k:2v:32:2w:32:30:1f:1o&xkqsl=1i&lcmsip=juhkht&pszv=ldafumo
- http://11.studiocitynorth.tv/read/defined_regulations-frequently.php?iakwxmo=1m:30:2v:1h:1k&mtall=1h:1l:1k:2v:32:2w:32:30:1f:1o&cwyop=1i&npjhxobh=xylrx&dwx=fgqc
- http://11.studiocitynorth.tv/read/defined_regulations-frequently.php?ibpxx=1m:30:2v:1h:1k&khxl=1h:1l:1k:2v:32:2w:32:30:1f:1o&wutyjk=1i&rfmnwhj=havwt&zxzd=lxpghowa
- http://11.studiocitynorth.tv/read/defined_regulations-frequently.php?wilfelbh=1m:30:2v:1h:1k&agr=1h:1l:1k:2v:32:2w:32:30:1f:1o&eokmsy=1i&zqkgp=ogwhwrwi&pfs=faz
- // Payload Malware Trojans...
- http://11.lamarianella.info/adobe/update_flash_player.exe //Ransomware
- http://11.laptopvspc.com/adobe/update_flash_player.exe //Ransomware
- http://11.b2cviaggi.com/adobe/update_flash_player.exe //Ransomware
- http://11.13dayz.com/adobe/update_flash_player.exe //Zbot
- http://11.duote.com.cn/papawnagshangyoulaingkdie.zip //Dropper
- :
- //URLQuery records:
- http://urlquery.net/search.php?q=173.246.102.246&type=string&start=2012-12-27&end=2013-01-11&max=100
- //NS Resolved PoC
- Resolving 11.lamarianella.info... seconds 0.00, 173.246.102.246
- Caching 11.lamarianella.info => 173.246.102.246
- Connecting to 11.lamarianella.info|173.246.102.246|:80
- Resolving 11.studiocitynorth.tv... seconds 0.00, 173.246.102.246
- Caching 11.studiocitynorth.tv => 173.246.102.246
- Connecting to 11.studiocitynorth.tv|173.246.102.246|:80... seconds
- Resolving 11.laptopvspc.com... seconds 0.00, 173.246.102.246
- Caching 11.laptopvspc.com => 173.246.102.246
- Connecting to 11.laptopvspc.com|173.246.102.246|:80
- Resolving 11.b2cviaggi.com... seconds 0.00, 173.246.102.246
- Caching 11.b2cviaggi.com => 173.246.102.246
- Connecting to 11.b2cviaggi.com|173.246.102.246|:80
- Resolving 11.13dayz.com... seconds 0.00, 173.246.102.246
- Caching 11.13dayz.com => 173.246.102.246
- Connecting to 11.13dayz.com|173.246.102.246|:80
- // Usage of Random Subdomains EVIL DNS Server of
- ----------------------------------------------------
- ns[a-z0-9]{4}\.name\.com Registrar: NAME.COM LLC
- ----------------------------------------------------
- ns1fkl.name.com.
- ns4bht.name.com.
- ns3cfp.name.com.
- ns2nsw.name.com.
- ----------------------------
- Registrar: NAME.COM LLC
- Server Name: NS1FKL.NAME.COM
- IP Address: 108.168.138.47
- Server Name: NS3CFP.NAME.COM
- IP Address: 208.43.116.46
- Server Name: NS4BHT.NAME.COM
- IP Address: 184.72.223.255
- Server Name: NS2NSW.NAME.COM
- IP Address: 5.153.6.221
- // PoC
- ;; AUTHORITY SECTION:
- lamarianella.info. 3600 IN NS ns4fmx.name.com.
- lamarianella.info. 3600 IN NS ns2dhj.name.com.
- lamarianella.info. 3600 IN NS ns3flt.name.com.
- lamarianella.info. 3600 IN NS ns1kpv.name.com.
- 13dayz.com. 3600 IN NS ns1fkl.name.com.
- 13dayz.com. 3600 IN NS ns4bht.name.com.
- 13dayz.com. 3600 IN NS ns3cfp.name.com.
- 13dayz.com. 3600 IN NS ns2nsw.name.com.
- studiocitynorth.tv. 3600 IN NS ns3cfp.name.com.
- studiocitynorth.tv. 3600 IN NS ns4bht.name.com.
- studiocitynorth.tv. 3600 IN NS ns2nsw.name.com.
- studiocitynorth.tv. 3600 IN NS ns1fkl.name.com.
- :
- (etc etc ...)
- ;; ADDITIONAL SECTION:
- ns1fkl.name.com. 453 IN A 108.168.138.47
- ns2nsw.name.com. 453 IN A 5.153.6.221
- ns3cfp.name.com. 1394 IN A 208.43.116.46
- ns4bht.name.com. 2374 IN A 184.72.223.255
- // IDs:
- Domain ID:D36007326-LRMS
- Domain Name:LAMARIANELLA.INFO
- Created On:23-Dec-2010 14:39:09 UTC
- Last Updated On:23-Dec-2012 22:22:07 UTC
- Expiration Date:23-Dec-2013 14:39:09 UTC
- Sponsoring Registrar:Name.com LLC (R279-LRMS)
- Status:CLIENT TRANSFER PROHIBITED
- Status:AUTORENEWPERIOD
- Registrant ID:ncr-257697-b88ed
- Registrant Name:Luca Vignali
- Registrant Organization:EasyAdmin web technologies di Luca Vignali
- Registrant Street1:vie E. Fermi 8
- Registrant Street2:
- Registrant Street3:
- Registrant City:Montemerano
- Registrant State/Province:Grosseto
- Registrant Postal Code:58014
- Registrant Country:IT
- Registrant Phone:+39.3392353115
- Registrant Phone Ext.:
- Registrant FAX:
- Registrant FAX Ext.:
- Registrant Email:web.easyadmin@gmail.com
- Domain Name: 13dayz.com
- Registrar: Name.com LLC
- Expiration Date: 2013-11-25 16:27:23
- Creation Date: 2012-11-25 16:27:23
- Name Servers:
- ns1fkl.name.com
- ns2nsw.name.com
- ns3cfp.name.com
- ns4bht.name.com
- REGISTRANT CONTACT INFO
- Christopher Healy
- Christopher Healy
- 60 Ruddington Drive
- Apt 408
- Toronto
- ON
- M2K 2J9
- CA
- Phone: +1.4168849466
- Email Address: chrishealytv@gmail.com
- Domain Name: studiocitynorth.tv
- Registrar: Name.com LLC
- Expiration Date: 2013-10-29 14:57:32
- Creation Date: 2007-10-29 14:57:32
- Name Servers:
- ns1fkl.name.com
- ns2nsw.name.com
- ns3cfp.name.com
- ns4bht.name.com
- REGISTRANT CONTACT INFO
- Whois Privacy Protection Service, Inc.
- Whois Agent
- PMB 368, 14150 NE 20th St - F1
- Bellevue
- WA
- 98007
- US
- Phone: +1.4252740657
- Fax: +1.4259744730
- Email Address: studiocitynorth.tv@protecteddomainservices.com
- Domain Name: laptopvspc.com
- Registrar: Name.com LLC
- Expiration Date: 2013-04-08 08:50:28
- Creation Date: 2012-04-08 08:50:28
- Name Servers:
- ns1dhq.name.com
- ns2btz.name.com
- ns3jwx.name.com
- ns4jpz.name.com
- REGISTRANT CONTACT INFO
- ariyanto
- ariyanto ,
- dsn kelir rt/rw 04/01 desa jintung
- kecamatan ayah kabupaten kebumen
- kebumen
- jawa tengah
- 54473
- ID
- Phone: +1.6285224790040
- Email Address: ary_miraclepitu@yahoo.com
- ----
- #MalwareMustDie!
Add Comment
Please, Sign In to add comment