Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Sat, Feb 22 2014
- #DhiaLite - NuclearPack EK subdomains back to OVH on 198.50.143.65
- Check http://pastebin.com/KuxpNJwV for a recent Update
- Bad actors are slightly changing strategy. They are not using dedicated IPs to Nuclear, but using IPs used for other older content possibly to evade being singled out or to recylce resources.
- 198.50.143.65 has hosted Turkish speaking gaming sites since November 2013.
- Furthermore,
- 198.50.143.65 is part of a pre-allocated OVH range
- 198.50.143.64 - 198.50.143.79
- Other IPs in the range have also been used for hosting gaming sites + the new Nuclear on 198.50.143.65.
- First seen, Last seen of the IP range. They have been around for a while
- 198.50.143.65 2013-11-22 2014-02-22 92
- 198.50.143.64 2013-11-22 2014-01-25 64
- 198.50.143.67 2013-11-23 2014-01-09 47
- 198.50.143.66 2013-11-23 2014-01-08 46
- 198.50.143.79 2013-11-23 2013-12-10 17
- 198.50.143.78 2013-11-23 2013-12-10 17
- 198.50.143.75 2013-11-23 2013-12-10 17
- 198.50.143.74 2013-11-23 2013-12-10 17
- 198.50.143.73 2013-11-23 2013-12-10 17
- 198.50.143.72 2013-11-23 2013-12-10 17
- 198.50.143.71 2013-11-25 2013-12-10 15
- 198.50.143.69 2013-11-25 2013-12-10 15
- 198.50.143.68 2013-11-25 2013-12-10 15
- 198.50.143.70 2013-11-23 2013-12-09 16
- 198.50.143.76 2013-11-25 2013-12-09 14
- 198.50.143.77 2013-11-23 2013-12-05 12
- The Nuclear domains are usign two .ru domains for their NSs, both registered on Feb 20th, 2014
- nddns.ru been used for a couple days
- pirozhkoff.ru is newly used
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement