Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Sat, Nov 30 2013
- #DhiaLite - FakeAV subdomains recently started resolving to 109.236.86.172 in the past few days
- https://www.virustotal.com/en/ip-address/109.236.86.172/information/
- 109.236.86.172 is dropping the following sample
- https://www.virustotal.com/en/file/2758652a54d6786157586d630ea4b6925900976e026f3c37839e5a350de1a2e9/analysis/
- http://support.clean-mx.de/clean-mx/viruses?id=17627377
- Subdomains are under the following 2LDs all registered in the past 2 weeks of November 2013
- webantiviruspro2013.com 2013-11-30
- safewebivirus-pro.com 2013-11-30
- www-virus-defence.com 2013-11-29
- webvirussprotect.com 2013-11-29
- webvirus-security.com 2013-11-29
- webvirussecure.com 2013-11-29
- webvirus-protectpro.com 2013-11-29
- webvirusprotect.com 2013-11-29
- web-virusprotect.com 2013-11-29
- web-securitypro.com 2013-11-29
- webantiviruspro.com 2013-11-29
- antivirus-protectpro.com 2013-11-29
- antivirus-protect.com 2013-11-29
- xantiviruspro2013.com 2013-11-26
- a-antiviruspro2013.com 2013-11-26
- isantivirus2013.com 2013-11-24
- iantiviruspro2013.com 2013-11-24
- ispantivirus.com 2013-11-23
- antiviruspro2013.com 2013-11-12
- #Sample subdomains on 109.236.86.172
- edb25522.antivirus-protect.com
- 853e4f39.webvirussprotect.com
- 853e4f39.webvirus-security.com
- 853e4f39.webvirussecure.com
- 853e4f39.webvirus-protectpro.com
- 853e4f39.web-securitypro.com
- 853e4f39.webantiviruspro.com
- 853e4f39.antivirus-protectpro.com
- 853e4f39.antivirus-protect.com
- 5c4e4143.webvirussprotect.com
- 5c4e4143.webvirussecure.com
- 5c4e4143.webantiviruspro2013.com
- 5c4e4143.safewebivirus-pro.com
- 5c4e4143.antivirus-protect.com
- 853e4f39.web-virusprotect.com
- 5c4e4143.web-virusprotect.com
- 853e4f39.webvirusprotect.com
- 5c4e4143.www-virus-defence.com
- 5c4e4143.webvirusprotect.com
- b325ddde.a-antiviruspro2013.com
- c3913c6c.iantiviruspro2013.com
- b325ddde.xantiviruspro2013.com
- 5c61f9a5.iantiviruspro2013.com
- 8c69d810f7108b8f1c634ede5c61f9a5.isantivirus2013.com
- 5c61f9a5.isantivirus2013.com
- 8c69d810f7108b8f1c634ede5c61f9a5.ispantivirus.com
- 8c69d810f7108b8f1c634ede5c61f9a5.antiviruspro2013.com
- END
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement