SHARE
TWEET

#MMD Kelihos MOMMA Trojan .RU TangoDown Report

MalwareMustDie Apr 24th, 2013 330 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. // #MalwareMustDie! @unixfreaxjp /malware/checkdomains]$ date
  2. // Thu Apr 25 22:14:39 JST 2013
  3. // KELIHOS "MOMMA" TROJAN, TANGO-DOWN REPORT
  4. // CASE: http://malwaremustdie.blogspot.jp/2013/04/kelihos-via-redkit-infection-following.html
  5. //
  6. // This is the list of the .RU domains used for -
  7. // downloading the kelihos "Momma" trojan "newboss*.exe" botnet installer -
  8. // during the malvertisement campaign of incident in US
  9. // (Boston/Waco/etc)
  10. //
  11. // These domains is in process of #TangoDown
  12. // currently under process (100% done). You will see the successful
  13. // processed ones without parameters (No IPs), and the on-going ones are with IP Addresses.
  14. // Total Downloader Domains (all are in .RU/noted!): 103 domains
  15. // MESSAGE: IF you see more domains please pastebin your finding &
  16. // contact us AFTER you check the below list beforehand to avoid overlapping.
  17.  
  18. // 1. Shutdown successfully (100% confirmed): 103 domains
  19.  
  20. ritypuro.ru,,
  21. cylaktog.ru,,
  22. kowsykoj.ru,,
  23. jetzicqo.ru,,
  24. agrybnyd.ru,,
  25. akafneyd.ru,,
  26. aqloqsis.ru,,
  27. aqselsoq.ru,,
  28. bajidmed.ru,,
  29. butlesuh.ru,,
  30. bygozlof.ru,,
  31. ciwefbod.ru,,
  32. conrozof.ru,,
  33. dapxonuq.ru,,
  34. derdepan.ru,,
  35. dijxohqa.ru,,
  36. kolasoeg.ru,,
  37. dydebmek.ru,,
  38. dydowxam.ru,,
  39. dypuhtiw.ru,,
  40. emysgual.ru,,
  41. ewhynwox.ru,,
  42. fadanres.ru,,
  43. fubkimab.ru,,
  44. funkabyv.ru,,
  45. fuqiwriv.ru,,
  46. gojzawde.ru,,
  47. howoggoc.ru,,
  48. ickyrjum.ru,,
  49. ivsykifa.ru,,
  50. jabfetiq.ru,,
  51. jakyskyf.ru,,
  52. jehbuqri.ru,,
  53. jigzilys.ru,,
  54. jujeblob.ru,,
  55. juqhasri.ru,,
  56. jykoamny.ru,,
  57. kezamzoq.ru,,
  58. kolasoeg.ru,,
  59. kuiffaam.ru,,
  60. lohdyrpa.ru,,
  61. melijfes.ru,,
  62. meuhwycu.ru,,
  63. migyxluk.ru,,
  64. mujosdim.ru,,
  65. nudegnuc.ru,,
  66. nurwiwur.ru,,
  67. nyhhakfi.ru,,
  68. okxusout.ru,,
  69. ovxurxom.ru,,
  70. poretget.ru,,
  71. qeqgomha.ru,,
  72. qevihnit.ru,,
  73. qyxpucaf.ru,,
  74. rezselix.ru,,
  75. rigyhdyq.ru,,
  76. rithakip.ru,,
  77. sagucqyp.ru,,
  78. sahiwten.ru,,
  79. siajxenu.ru,,
  80. sigkeqvi.ru,,
  81. soljasek.ru,,
  82. taurbael.ru,,
  83. tuhoxkyt.ru,,
  84. tuklicit.ru,,
  85. tuswusah.ru,,
  86. ubhyfnyz.ru,,
  87. ufqinweb.ru,,
  88. ulvojfol.ru,,
  89. vezylgys.ru,,
  90. vusypxaw.ru,,
  91. wezgybso.ru,,
  92. wirxopiz.ru,,
  93. aqselsoq.ru,,
  94. wylovpuc.ru,,
  95. xikgygga.ru,,
  96. xujxiwli.ru,,
  97. yddivvev.ru,,
  98. yhwursyn.ru,,
  99. yhzewguv.ru,,
  100. ymvuchyq.ru,,
  101. yskicfuw.ru,,
  102. ytliywax.ru,,
  103. zahebfox.ru,,
  104. zajytoke.ru,,
  105. zaszigic.ru,,
  106. zurgeqyr.ru,,
  107. zydeqdud.ru,,
  108. hfapjux.ru,,
  109. annerpuh.ru,,
  110. colunveg.ru,,
  111. horikhex.ru,,
  112. ihulypzi.ru,,
  113. lowzepol.ru,,
  114. tihxuqac.ru,,
  115. vydpilny.ru,,
  116. wuvhopij.ru,,
  117. zajytoke.ru,,
  118. zevbektu.ru,,
  119. zydeqdud.ru,,
  120. kowsykoj.ru,,
  121. emgefwud.ru,,
  122. daoqwaqo.ru,,
  123.  
  124. // In process: 0(null) domains:
  125.  
  126. ---
  127. #MalwareMustDie
  128. Thank's to teamwork: @essachin, @ConradLongMore, @gN3mes1s, @nyxbone, @Set_Abominae
  129. Special Thank's to Cert-GIB for the swift cooperation in dismantling the domains.
  130. This report is checked & compiled by @unixfreaxjp /malware/checkdomains]$ date
  131. 1. Wed Apr 24 21:37:46 JST 2013
  132. 2. Thu Apr 25 22:14:39 JST 2013
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Top