Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #MalwareMustDie! @unixfreaxjp /malware]$ date
- Tue Nov 20 13:44:37 JST 2012
- Supporting to Denis's case,
- PseudoRandom/DGA of EK infector misusing mynumber.org
- Source Service/Dmain'S Credential Leaks
- "A record" pointing to VPS 204.16.173.30
- Below 2(two) points of investigation:
- [1] Positive Affected Possibility domains is as per below suspected UrlQuerry Result:
- Base Report: http://urlquery.net/search.php?q=204.16.173.30&type=string&start=2011-06-25&end=2012-11-20&max=50
- *) PoC: justdied.com included in this domain list, is having an infection report of BHEK (TODAY, sifferent case handle)
- -----------------------------------------------------------------------------------------------------------------------
- Date (CET) Rep/Alerts/IDS URL IP
- -----------------------------------------------------------------------------------------------------------------------
- 2012-11-18 06:19:57 0 / 0 http://lflinkup.com 204.16.173.30 [United States]
- 2012-11-16 23:55:29 0 / 0 http://ftp1.biz 204.16.173.30 [United States]
- 2012-11-16 05:59:38 0 / 0 http://sellclassics.com 204.16.173.30 [United States]
- 2012-11-15 21:26:46 0 / 0 http://xxxy.info 204.16.173.30 [United States]
- 2012-11-15 13:01:12 0 / 0 http://almostmy.com 204.16.173.30 [United States]
- 2012-11-14 21:24:40 0 / 0 http://mynumber.org 204.16.173.30 [United States]
- 2012-11-14 11:37:02 0 / 0 http://gr8domain.biz 204.16.173.30 [United States]
- 2012-11-14 04:31:35 1 / 0 http://www.ddns.info 204.16.173.30 [United States]
- 2012-11-14 03:49:35 0 / 0 http://ddns.info 204.16.173.30 [United States]
- 2012-11-14 01:04:55 0 / 0 http://ddns.info 204.16.173.30 [United States]
- 2012-11-13 19:35:17 0 / 0 http://itemdb.com 204.16.173.30 [United States]
- 2012-11-13 14:08:34 1 / 0 http://www.onmypc.us/ 204.16.173.30 [United States]
- 2012-11-13 12:38:37 0 / 0 http://onmypc.us/ 204.16.173.30 [United States]
- 2012-11-12 05:45:12 1 / 0 http://justdied.com 204.16.173.30 [United States]
- 2012-11-12 02:47:54 0 / 0 http://port25.biz 204.16.173.30 [United States]
- 2012-11-11 14:02:36 1 / 1 http://xxxy.info/t/vc.php?go=2 204.16.173.30 [United States]
- 2012-11-10 21:30:49 0 / 0 http://portrelay.com 204.16.173.30 [United States]
- 2012-11-10 01:52:15 0 / 0 http://ddns.info 204.16.173.30 [United States]
- 2012-11-09 19:02:54 0 / 0 http://acmetoy.com 204.16.173.30 [United States]
- 2012-11-09 18:58:37 0 / 0 http://acmetoy.com 204.16.173.30 [United States]
- 2012-11-09 14:56:14 0 / 0 http://itemdb.com 204.16.173.30 [United States]
- 2012-11-09 14:26:55 0 / 0 http://justdied.com 204.16.173.30 [United States]
- 2012-11-09 05:43:00 0 / 0 http://trickip.net 204.16.173.30 [United States]
- 2012-11-08 15:38:45 0 / 0 http://ddns.us 204.16.173.30 [United States]
- 2012-11-08 15:36:23 0 / 0 http://ftpserver.biz 204.16.173.30 [United States]
- 2012-11-08 13:35:56 0 / 0 http://justdied.com 204.16.173.30 [United States]
- 2012-11-08 13:32:04 0 / 0 http://ftp1.biz 204.16.173.30 [United States]
- 2012-11-08 01:30:31 0 / 0 http://fartit.com/nt/stats.php 204.16.173.30 [United States]
- 2012-11-07 22:23:10 0 / 0 http://justdied.com 204.16.173.30 [United States]
- 2012-11-07 17:17:38 0 / 0 http://almostmy.com 204.16.173.30 [United States]
- 2012-11-07 15:07:34 0 / 0 http://dynamicdns.org.uk 204.16.173.30 [United States]
- 2012-11-07 14:38:44 0 / 0 http://dynamicdns.org.uk 204.16.173.30 [United States]
- 2012-11-07 12:48:40 0 / 0 http://lflinkup.com 204.16.173.30 [United States]
- 2012-11-06 21:04:04 0 / 0 http://ftp1.biz 204.16.173.30 [United States]
- 2012-11-06 21:01:30 0 / 0 http://justdied.com 204.16.173.30 [United States]
- 2012-11-06 03:10:33 0 / 0 http://trickip.net 204.16.173.30 [United States]
- 2012-11-06 00:00:25 1 / 0 http://www.lflinkup.com/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liA (...) 204.16.173.30 [United States]
- 2012-11-05 20:06:43 0 / 0 http://lflinkup.com 204.16.173.30 [United States]
- 2012-11-05 00:51:34 0 / 0 http://lflinkup.com 204.16.173.30 [United States]
- 2012-11-04 23:52:01 0 / 0 http://25u.com 204.16.173.30 [United States]
- 2012-11-04 22:02:20 0 / 0 http://justdied.com 204.16.173.30 [United States]
- 2012-11-04 03:24:29 0 / 0 http://ftp1.biz 204.16.173.30 [United States]
- 2012-11-02 01:22:06 0 / 0 http://ftp1.biz 204.16.173.30 [United States]
- 2012-11-01 13:02:59 0 / 0 http://lflinkup.com 204.16.173.30 [United States]
- 2012-11-01 12:37:48 0 / 0 http://ftp1.biz 204.16.173.30 [United States]
- 2012-11-01 09:28:55 0 / 0 http://lflinkup.com 204.16.173.30 [United States]
- 2012-11-01 03:40:47 0 / 0 http://dns04.com 204.16.173.30 [United States]
- 2012-10-31 22:19:09 0 / 0 http://ftp1.biz 204.16.173.30 [United States]
- [2]The shared IP of the below domains POSSIBLY afftected too..(alphabetical order)
- By seeing the name used by some domains below, seeing some suspicious already...
- --------------start-----------------------
- 1dumb.com
- 204-16-171-129.changeip.com
- 204-16-171-132.changeip.com
- 204-16-171-135.changeip.com
- 204-16-171-141.changeip.com
- 204-16-171-155.changeip.com
- 204-16-171-162.changeip.com
- 204-16-171-165.changeip.com
- 204-16-171-178.changeip.com
- 204-16-171-181.changeip.com
- 204-16-171-186.changeip.com
- 204-16-171-189.changeip.com
- 204-16-171-193.changeip.com
- 204-16-171-196.changeip.com
- 204-16-171-218.changeip.com
- 204-16-171-220.changeip.com
- 204-16-171-222.changeip.com
- 204-16-171-224.changeip.com
- 204-16-171-228.changeip.com
- 204-16-171-229.changeip.com
- 865a.changeip.com
- anitysmtp.changeip.com
- authorizeddns.net
- authorizeddns.org
- changeip.net
- cleansite.us
- ddns.com.co
- dns-stuff.com
- dns2.us
- dnsfailover.net
- dynamicdns.biz
- dynamicdns.org.uk
- edns.biz
- fartit.com
- freewww.info
- ftp.4pu.com
- ftp.mynumber.org
- gdsgdfsghhsh.changeip.com
- gettrials.com
- gr8name.biz
- jkub.com
- kcif.changeip.com
- lflinkup.net
- mrnorris.com
- myddns.com
- mypicture.info
- mypop3.net
- ns01.biz
- ns1.name
- ns2.name
- ourhobby.com
- rebatesrule.net
- relay.changeip.com
- rm-1-br2-1.changeip.com
- sexxxy.biz
- ssl443.org
- trickip.net
- trickip.org
- vanity.changeip.com
- vizvaz.com
- winupdate.changeip.com
- woaiwojia.changeip.com
- www.4mydomain.com
- www.almostmy.com
- www.cleansite.info
- www.compress.to
- www.dns1.us
- www.dnyp.com
- www.dynamicdns.co.uk
- www.dynamicdns.me.uk
- www.edns.biz
- www.esmtp.biz
- www.fartit.com
- www.freewww.info
- www.got-game.org
- www.gr8name.biz
- www.isasecret.com
- www.itsaol.com
- www.lflinkup.com
- www.longmusic.com
- www.mefound.com
- www.misecure.com
- www.mrface.com
- www.my03.com
- www.mypop3.org
- www.mysecondarydns.com
- www.ns01.biz
- www.ns2.name
- www.onedumb.com
- www.organiccrap.com
- www.poppop.com
- www.portrelay.com
- www.proxydns.com
- www.sellclassics.com
- www.trickip.net
- www.www1.biz
- www.ygto.com
- x24hr.com
- xxxy.info
- yakima.changeip.com
- ----end------
- #MalwareMustDie
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement