Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Wed, Sep 11 2013
- #DhiaLite - In response to https://isc.sans.edu/diary/37.58.73.42++95.156.228.69++195.210.43.42%2C+anyone%3F/16559
- Below are malicious Domains hosted on 37.58.73.42
- They appeared in Dynamoo's blog list of May 13th 2013, http://bit.ly/19i7OyY
- In Dynamoo's blog, they were reported as being hosted on 188.241.86.33, "a malware server currently involved in injection attacks, serving up the Blackhole exploit kit, Zbot and a side order of Cdorked"
- Intel from Urlquery
- http://urlquery.net/search.php?q=37.58.73.42&type=string&start=2013-08-28&end=2013-09-12&max=200
- http://urlquery.net/search.php?q=95.156.228.69&type=string&start=2013-08-28&end=2013-09-12&max=200
- http://urlquery.net/search.php?q=195.210.43.42&type=string&start=2013-08-28&end=2013-09-12&max=200
- Intel from VirusTotal
- https://www.virustotal.com/en/ip-address/37.58.73.42/information/
- https://www.virustotal.com/en/ip-address/95.156.228.69/information/
- https://www.virustotal.com/en/ip-address/195.210.43.42/information/
- gmzuwr.ru
- hrgvrl.ru
- kinyng.ru
- luiwmt.ru
- olpnso.ru
- pvzvnp.ru
- rvwwko.ru
- tpxhpz.ru
- trlnps.ru
- zuihwg.ru
- zuknsr.ru
- Below is the data from our Umbrella passive DNS data (OpenDNS)
- gmzuwr.ru
- 9/7/13 9/11/13 37.58.73.42 (TTL: 300)
- 7/4/13 7/10/13 37.58.73.42 (TTL: 300)
- hrgvrl.ru
- 8/27/13 9/7/13 37.58.73.42 (TTL: 300)
- 7/3/13 7/10/13 37.58.73.42 (TTL: 300)
- kinyng.ru
- 9/6/13 9/8/13 37.58.73.42 (TTL: 300)
- 7/3/13 7/9/13 37.58.73.42 (TTL: 300)
- luiwmt.ru
- 8/19/13 9/7/13 37.58.73.42 (TTL: 300)
- 7/4/13 7/10/13 37.58.73.42 (TTL: 300)
- olpnso.ru
- 8/17/13 9/7/13 37.58.73.42 (TTL: 300)
- 7/4/13 7/11/13 37.58.73.42 (TTL: 300)
- pvzvnp.ru
- 9/7/13 9/8/13 37.58.73.42 (TTL: 300)
- 7/4/13 7/7/13 37.58.73.42 (TTL: 300)
- rvwwko.ru
- 9/6/13 9/7/13 37.58.73.42 (TTL: 300)
- 7/11/13 7/11/13 37.58.73.42 (TTL: 300) 88.198.227.115 (TTL: 300)
- 7/4/13 7/10/13 37.58.73.42 (TTL: 300)
- tpxhpz.ru
- 8/18/13 9/7/13 37.58.73.42 (TTL: 300)
- 7/4/13 7/10/13 37.58.73.42 (TTL: 300)
- trlnps.ru
- 8/31/13 9/7/13 37.58.73.42 (TTL: 300)
- 7/3/13 7/10/13 37.58.73.42 (TTL: 300)
- zuihwg.ru
- 8/18/13 8/31/13 37.58.73.42 (TTL: 300)
- 7/11/13 7/11/13 37.58.73.42 (TTL: 300) 88.198.227.115 (TTL: 300)
- 7/3/13 7/10/13 37.58.73.42 (TTL: 300)
- zuknsr.ru
- 9/7/13 9/7/13 37.58.73.42 (TTL: 300)
- 7/11/13 7/11/13 37.58.73.42 (TTL: 300) 88.198.227.115 (TTL: 300)
- 7/3/13 7/10/13 37.58.73.42 (TTL: 300)
- END
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement