Advertisement
MalwareMustDie

#MMD Kelihos MOMMA Trojan .RU TangoDown Report

Apr 24th, 2013
1,660
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.79 KB | None | 0 0
  1. // #MalwareMustDie! @unixfreaxjp /malware/checkdomains]$ date
  2. // Thu Apr 25 22:14:39 JST 2013
  3. // KELIHOS "MOMMA" TROJAN, TANGO-DOWN REPORT
  4. // CASE: http://malwaremustdie.blogspot.jp/2013/04/kelihos-via-redkit-infection-following.html
  5. //
  6. // This is the list of the .RU domains used for -
  7. // downloading the kelihos "Momma" trojan "newboss*.exe" botnet installer -
  8. // during the malvertisement campaign of incident in US
  9. // (Boston/Waco/etc)
  10. //
  11. // These domains is in process of #TangoDown
  12. // currently under process (100% done). You will see the successful
  13. // processed ones without parameters (No IPs), and the on-going ones are with IP Addresses.
  14. // Total Downloader Domains (all are in .RU/noted!): 103 domains
  15. // MESSAGE: IF you see more domains please pastebin your finding &
  16. // contact us AFTER you check the below list beforehand to avoid overlapping.
  17.  
  18. // 1. Shutdown successfully (100% confirmed): 103 domains
  19.  
  20. ritypuro.ru,,
  21. cylaktog.ru,,
  22. kowsykoj.ru,,
  23. jetzicqo.ru,,
  24. agrybnyd.ru,,
  25. akafneyd.ru,,
  26. aqloqsis.ru,,
  27. aqselsoq.ru,,
  28. bajidmed.ru,,
  29. butlesuh.ru,,
  30. bygozlof.ru,,
  31. ciwefbod.ru,,
  32. conrozof.ru,,
  33. dapxonuq.ru,,
  34. derdepan.ru,,
  35. dijxohqa.ru,,
  36. kolasoeg.ru,,
  37. dydebmek.ru,,
  38. dydowxam.ru,,
  39. dypuhtiw.ru,,
  40. emysgual.ru,,
  41. ewhynwox.ru,,
  42. fadanres.ru,,
  43. fubkimab.ru,,
  44. funkabyv.ru,,
  45. fuqiwriv.ru,,
  46. gojzawde.ru,,
  47. howoggoc.ru,,
  48. ickyrjum.ru,,
  49. ivsykifa.ru,,
  50. jabfetiq.ru,,
  51. jakyskyf.ru,,
  52. jehbuqri.ru,,
  53. jigzilys.ru,,
  54. jujeblob.ru,,
  55. juqhasri.ru,,
  56. jykoamny.ru,,
  57. kezamzoq.ru,,
  58. kolasoeg.ru,,
  59. kuiffaam.ru,,
  60. lohdyrpa.ru,,
  61. melijfes.ru,,
  62. meuhwycu.ru,,
  63. migyxluk.ru,,
  64. mujosdim.ru,,
  65. nudegnuc.ru,,
  66. nurwiwur.ru,,
  67. nyhhakfi.ru,,
  68. okxusout.ru,,
  69. ovxurxom.ru,,
  70. poretget.ru,,
  71. qeqgomha.ru,,
  72. qevihnit.ru,,
  73. qyxpucaf.ru,,
  74. rezselix.ru,,
  75. rigyhdyq.ru,,
  76. rithakip.ru,,
  77. sagucqyp.ru,,
  78. sahiwten.ru,,
  79. siajxenu.ru,,
  80. sigkeqvi.ru,,
  81. soljasek.ru,,
  82. taurbael.ru,,
  83. tuhoxkyt.ru,,
  84. tuklicit.ru,,
  85. tuswusah.ru,,
  86. ubhyfnyz.ru,,
  87. ufqinweb.ru,,
  88. ulvojfol.ru,,
  89. vezylgys.ru,,
  90. vusypxaw.ru,,
  91. wezgybso.ru,,
  92. wirxopiz.ru,,
  93. aqselsoq.ru,,
  94. wylovpuc.ru,,
  95. xikgygga.ru,,
  96. xujxiwli.ru,,
  97. yddivvev.ru,,
  98. yhwursyn.ru,,
  99. yhzewguv.ru,,
  100. ymvuchyq.ru,,
  101. yskicfuw.ru,,
  102. ytliywax.ru,,
  103. zahebfox.ru,,
  104. zajytoke.ru,,
  105. zaszigic.ru,,
  106. zurgeqyr.ru,,
  107. zydeqdud.ru,,
  108. hfapjux.ru,,
  109. annerpuh.ru,,
  110. colunveg.ru,,
  111. horikhex.ru,,
  112. ihulypzi.ru,,
  113. lowzepol.ru,,
  114. tihxuqac.ru,,
  115. vydpilny.ru,,
  116. wuvhopij.ru,,
  117. zajytoke.ru,,
  118. zevbektu.ru,,
  119. zydeqdud.ru,,
  120. kowsykoj.ru,,
  121. emgefwud.ru,,
  122. daoqwaqo.ru,,
  123.  
  124. // In process: 0(null) domains:
  125.  
  126. ---
  127. #MalwareMustDie
  128. Thank's to teamwork: @essachin, @ConradLongMore, @gN3mes1s, @nyxbone, @Set_Abominae
  129. Special Thank's to Cert-GIB for the swift cooperation in dismantling the domains.
  130. This report is checked & compiled by @unixfreaxjp /malware/checkdomains]$ date
  131. 1. Wed Apr 24 21:37:46 JST 2013
  132. 2. Thu Apr 25 22:14:39 JST 2013
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement