Advertisement
DhiaLite

New Suspicious .pl subdomain on Virut CnC IP - Feb 5, 2014

Feb 5th, 2014
441
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.87 KB | None | 0 0
  1. Wed, Feb 5th, 2014
  2.  
  3. #DhiaLite - New suspicious .pl subdomain oglo.bandycituska.pl showed today Feb 5th with a spike in traffic. It first resolved to 188.40.65.209 then currently to 88.198.203.229
  4. Its nameservers ns1.sysplex.pl and ns2.sysplex.pl are hosted on 188.40.65.209
  5.  
  6. 188.40.65.209 has been flagged since Jan 26th by VT for hosting Virut CnC domains.
  7. https://www.virustotal.com/en/ip-address/188.40.65.209/information/
  8.  
  9. #Sample domains on 188.40.65.209
  10.  
  11. oglo.bandycituska.pl
  12. www.gazetaswiat.pl
  13. bandycituska.pl
  14. www.bandycituska.pl
  15. ns1.sysplex.pl
  16. ns2.sysplex.pl
  17. old.sysplex.pl
  18. www.sysplex.pl
  19. sysplex.pl
  20. u0a.cing.pl
  21. tsm.lefi.pl
  22. sp.iqchk.pl
  23. sg.kerta.pl
  24. ps.indab.pl
  25. in.kolso.pl
  26. hus.limp.pl
  27. c7.polgo.pl
  28.  
  29. From the list the domains below are Virut CnC domains
  30.  
  31. u0a.cing.pl
  32. tsm.lefi.pl
  33. sp.iqchk.pl
  34. sg.kerta.pl
  35. ps.indab.pl
  36. in.kolso.pl
  37. hus.limp.pl
  38. c7.polgo.pl
  39.  
  40. Reports about the CnCs
  41. https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Virus:Win32/Virut.gen!AO#tab=2
  42. http://www.threatexpert.com/report.aspx?md5=609ec646ed46ff0a59afb8b6251ad4af
  43. http://www.threatexpert.com/report.aspx?md5=c8138ce6d2ae2c7ae14c1cde46fc8499
  44.  
  45. Some of the VT reports for samples communicating with the CnCs
  46. https://www.virustotal.com/en/file/b0aa5fb7eae8bb5c39712110b2fb42127f7a20a3f0bb8bef22f46ec35b323ea4/analysis/
  47. https://www.virustotal.com/en/file/9ca0c1890a418b1bef645cf9e6eb8ec9322dd541cc749269a9f9a34ed8f74acd/analysis/
  48. https://www.virustotal.com/en/file/50fbcc2614914e0e2431a7af3a74a9e0865bd016dfebee916e7d2b978aae72e9/analysis/
  49. https://www.virustotal.com/en/file/5ea1e4baf3c0ae980a8e4ce28c929a60b9ec357099ad30047906fc936f3603fa/analysis/
  50. https://www.virustotal.com/en/file/a6d26c15503de6d600feae4c17af6a259b42732d825f1e3fef8fe0b1cdbb5a5e/analysis/
  51. https://www.virustotal.com/en/file/286d972891d6b82bcc0dd7d088734e375678c7886a89817d8148a1161024b63a/analysis/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement