Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # -------------------------------------------
- # MalwareMustDie | Cridex Infection Source
- # Case: http://pastebin.com/raw.php?i=DQ7G0Vz0
- # Please block the below IP address:
- # 94.76.240.56, 212.7.219.46, 5.135.71.226 (UK, PL and FR)
- # To void Cridex infection at this moment.
- # Domains are all registered via REG.RU (Russia Federation)
- # @unixfreaxjp /malware/checkdomains]$ date
- Thu Jan 16 23:53:06 JST 2014
- # -------------------------------------------
- # ---------------------------
- # REPORTED CRIDEX CNC DOMAINS
- # Since Nov 2013 - Jan 17th 2014
- # ---------------------------
- $ cat checkru.txt|sort|uniq
- beliyvolkalak.ru
- buriymishka.ru
- deepandtouch.ru
- djubkafriend.ru
- glebstark.ru
- jvrdwnload.ru
- kolodavoloda.ru
- kuchereneltd.ru
- masterupdate.ru
- micrupdaserv.ru
- montierco.ru
- pianiykrolik.ru
- portasible.ru
- renataltd.ru
- securesrvr8.ru
- softsysdnl.ru
- ssshsecur.ru
- toolsdownloads17.ru
- updatecheck.co.ua
- updote-serv3.ru
- uppdate-servs.ru
- upper-service.ru
- # ----------------------
- # Alive IP for CNC checks
- # ----------------------
- $ bash checkru.sh
- DOMAINS A RECORD DNS
- ----------------------------------------------------------
- kuchereneltd.ru. 94.76.240.56, ns1.reg.ru. ns2.reg.ru.
- jvrdwnload.ru, 212.7.219.46, ns1.reg.ru. ns2.reg.ru.
- renataltd.ru, 5.135.71.226, ns1.reg.ru. ns2.reg.ru.
- # Geo Location:
- # --------------
- $ cat ip.txt|bash origin.sh
- Thu Jan 16 23:52:08 JST 2014|94.76.240.56|vpsxen7.gbservers.co.uk.|29550 | 94.76.192.0/18 | SIMPLYTRANSIT | GB | EUROCONNEX.NET | SIMPLY TRANSIT LTD
- Thu Jan 16 23:52:11 JST 2014|212.7.219.46||198156 | 212.7.216.0/21 | DEDISERV | PL | DEDISERV.EU | DEDISERV DEDICATED SERVERS SP. Z O.O.
- Thu Jan 16 23:52:13 JST 2014|5.135.71.226|5-135-71-226.cinfuserver.com.|16276 | 5.135.0.0/16 | OVH | FR | OVH.COM | OVH SYSTEMS
- # -----------------------------------
- # Internet registration summary check
- # Registrar source, dates
- # (domain alphabethical sorted)
- # -----------------------------------
- NS+WHOIS checker script by @unixfreaxjp
- Thu Jan 16 23:43:52 JST 2014
- >>> beliyvolkalak.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.26
- free-date: 2015.01.26
- >>> buriymishka.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.26
- free-date: 2015.01.26
- >>> deepandtouch.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.24
- free-date: 2015.01.24
- >>> djubkafriend.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.24
- free-date: 2015.01.24
- >>> glebstark.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- free-date: 2015.02.06
- >>> jvrdwnload.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.25
- free-date: 2014.12.26
- >>> kolodavoloda.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.10.28
- free-date: 2014.11.28
- >>> kuchereneltd.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- free-date: 2015.02.06
- >>> masterupdate.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.13
- free-date: 2014.12.14
- >>> micrupdaserv.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.12
- free-date: 2015.01.12
- >>> montierco.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.13
- free-date: 2014.12.14
- >>> pianiykrolik.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.13
- free-date: 2014.12.14
- >>> portasible.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- free-date: 2015.02.06
- >>> renataltd.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.13
- free-date: 2014.12.14
- >>> securesrvr8.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.25
- free-date: 2014.12.26
- >>> softsysdnl.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.25
- free-date: 2014.12.26
- >>> ssshsecur.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- free-date: 2015.02.06
- >>> toolsdownloads17.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.11.25
- free-date: 2014.12.26
- >>> updatecheck.co.ua|Created On:13-Nov-2013 13:08:33 UTC
- Last Updated On:13-Nov-2013 13:08:33 UTC
- Expiration Date:13-Nov-2014 13:08:33 UTC
- Sponsoring Registrar:Reg RU (reg-ru-mnt-cunic)
- Registrant Email:[email protected]
- Admin Email:[email protected]
- Billing Email:[email protected]
- Tech Email:[email protected]
- Name Server:NS2.REG.RU
- Name Server:NS1.REG.RU
- >>> updote-serv3.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.12
- free-date: 2015.01.12
- >>> uppdate-servs.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.12
- free-date: 2015.01.12
- >>> upper-service.ru|nserver: ns1.reg.ru.
- nserver: ns2.reg.ru.
- registrar: REGRU-REG-RIPN
- created: 2013.12.12
- free-date: 2015.01.12
- Thu Jan 16 23:44:02 JST 2014
- # -------------------------------
- # Malware Verdict per IP in VT:
- # -------------------------------
- https://www.virustotal.com/en/ip-address/94.76.240.56/information/
- https://www.virustotal.com/en/ip-address/5.135.71.226/information/
- https://www.virustotal.com/en/ip-address/212.7.219.46/information/
- ---
- #malwaremustdie
- @unixfreaxjp /malware/checkdomains]$ date
- Thu Jan 16 23:53:06 JST 2014
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement