Advertisement
DhiaLite

FakeAV domains on 109.236.86.172 - Nov 30, 2013

Nov 30th, 2013
316
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.06 KB | None | 0 0
  1. Sat, Nov 30 2013
  2. #DhiaLite - FakeAV subdomains recently started resolving to 109.236.86.172 in the past few days
  3.  
  4. https://www.virustotal.com/en/ip-address/109.236.86.172/information/
  5.  
  6. 109.236.86.172 is dropping the following sample
  7. https://www.virustotal.com/en/file/2758652a54d6786157586d630ea4b6925900976e026f3c37839e5a350de1a2e9/analysis/
  8.  
  9. http://support.clean-mx.de/clean-mx/viruses?id=17627377
  10.  
  11. Subdomains are under the following 2LDs all registered in the past 2 weeks of November 2013
  12.  
  13. webantiviruspro2013.com 2013-11-30
  14. safewebivirus-pro.com 2013-11-30
  15. www-virus-defence.com 2013-11-29
  16. webvirussprotect.com 2013-11-29
  17. webvirus-security.com 2013-11-29
  18. webvirussecure.com 2013-11-29
  19. webvirus-protectpro.com 2013-11-29
  20. webvirusprotect.com 2013-11-29
  21. web-virusprotect.com 2013-11-29
  22. web-securitypro.com 2013-11-29
  23. webantiviruspro.com 2013-11-29
  24. antivirus-protectpro.com 2013-11-29
  25. antivirus-protect.com 2013-11-29
  26. xantiviruspro2013.com 2013-11-26
  27. a-antiviruspro2013.com 2013-11-26
  28. isantivirus2013.com 2013-11-24
  29. iantiviruspro2013.com 2013-11-24
  30. ispantivirus.com 2013-11-23
  31. antiviruspro2013.com 2013-11-12
  32.  
  33. #Sample subdomains on 109.236.86.172
  34.  
  35. edb25522.antivirus-protect.com
  36. 853e4f39.webvirussprotect.com
  37. 853e4f39.webvirus-security.com
  38. 853e4f39.webvirussecure.com
  39. 853e4f39.webvirus-protectpro.com
  40. 853e4f39.web-securitypro.com
  41. 853e4f39.webantiviruspro.com
  42. 853e4f39.antivirus-protectpro.com
  43. 853e4f39.antivirus-protect.com
  44. 5c4e4143.webvirussprotect.com
  45. 5c4e4143.webvirussecure.com
  46. 5c4e4143.webantiviruspro2013.com
  47. 5c4e4143.safewebivirus-pro.com
  48. 5c4e4143.antivirus-protect.com
  49. 853e4f39.web-virusprotect.com
  50. 5c4e4143.web-virusprotect.com
  51. 853e4f39.webvirusprotect.com
  52. 5c4e4143.www-virus-defence.com
  53. 5c4e4143.webvirusprotect.com
  54. b325ddde.a-antiviruspro2013.com
  55. c3913c6c.iantiviruspro2013.com
  56. b325ddde.xantiviruspro2013.com
  57. 5c61f9a5.iantiviruspro2013.com
  58. 8c69d810f7108b8f1c634ede5c61f9a5.isantivirus2013.com
  59. 5c61f9a5.isantivirus2013.com
  60. 8c69d810f7108b8f1c634ede5c61f9a5.ispantivirus.com
  61. 8c69d810f7108b8f1c634ede5c61f9a5.antiviruspro2013.com
  62.  
  63. END
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement