|
![]() |
|||||||
![]()
![]()
![]() |
![]() SBL252243 => Binary option spammer (T. Richert) again switched to a new landing page: Botnet spammed URLs: http://www.zkhxi.ru ---> 220.164.140.186 ---> CHINANET yunnan >>> http://www.expert-alerts.com/listde/members.php?ad= [198.20.96.50] SINGLEHOP-BV [198.20.96.50] expert-alerts.com myprofitdesk.com profitalarm.com _________ SBL251106 => Now landing on Mivitec again: http://x.co/8auwW redirects to: http://znxw.csog.ru ---> 220.164.140.186 ---> CHINANET yunnan redirects to: http://www.profitexperte.de/lp/lp8?A=7460 ---> 46.245.181.113 ---> 46-245-181-113.static.mivitec.net [46.245.181.113] profitexperte.com earningexpert.com ___________ http://vkvfcl.saszmp.ru --> 220.164.140.186 ---> CHINANET yunnan domain: SASZMP.RU nserver: ns1.imalna.ru. 213.136.76.37 nserver: ns2.imalna.ru. 213.136.76.38 now not on a fast flux botnet but on 220.164.140.186. All redirecting to: http://www.crazycashformula.net/LP/8/de/index.htm?A=7460 IP: 199.83.129.198 ---> 199.83.129.198.ip.incapdns.net ________ [220.164.140.186] http://www.loaep.ru http://www.rebazp.ru both redirect to: http://avengertrader.com/de 54.243.148.187 ---> ec2-54-243-148-187.compute-1.amazonaws.com _______ SBL250996 => DNS @213.136.76.37 & 213.136.76.38 bkxim.ru cbvv.ru cjzvma.ru csaece.ru csog.ru cwthk.ru egfnp.ru eovn.ru fhbtu.ru fpscy.ru hwte.ru ilasy.ru illfh.ru izjeb.ru jjwr.ru loaep.ru lohzsz.ru mctjgt.ru mfmv.ru nwxt.ru pejhj.ru qfzdw.ru qqlwwf.ru qugemx.ru qulg.ru rdtmw.ru rebazp.ru rjzcr.ru saszmp.ru sjlyp.ru tpduok.ru urqgie.ru vomwv.ru vtjx.ru wprps.ru xfjdks.ru xiqcx.ru ybvrbb.ru yqmm.ru zkhxi.ru ______________ [220.164.140.186] bkxim.ru cbvv.ru cjzvma.ru csaece.ru csog.ru cwthk.ru egfnp.ru eovn.ru fhbtu.ru fpscy.ru hwte.ru ilasy.ru illfh.ru izjeb.ru jjwr.ru loaep.ru lohzsz.ru mctjgt.ru mfmv.ru nwxt.ru pejhj.ru qfzdw.ru qqlwwf.ru qugemx.ru qulg.ru rdtmw.ru rebazp.ru rjzcr.ru saszmp.ru sjlyp.ru tpduok.ru urqgie.ru vomwv.ru vtjx.ru wprps.ru ____________ [220.164.140.186] http://www.loaep.ru http://www.rebazp.ru both redirect to: http://avengertrader.com/de 54.243.148.187 ---> ec2-54-243-148-187.compute-1.amazonaws.com ___________ SBL250995 => http://vkvfcl.saszmp.ru --> 220.164.140.186 ---> CHINANET yunnan domain: SASZMP.RU nserver: ns1.imalna.ru. 213.136.76.37 nserver: ns2.imalna.ru. 213.136.76.38 --- contacting nameserver: 213.136.76.37 [213.136.76.37] saszmp.ru SOA origin = socks.socks mail addr = root@imalna.ru serial = 2015032101 refresh = 10800 (3 hours) retry = 3600 (1 hour) expire = 604800 (7 days) minimum ttl = 86400 () saszmp.ru NS ns2.imalna.ru saszmp.ru NS ns1.imalna.ru saszmp.ru MX 10 mail.saszmp.ru saszmp.ru MX 20 mail.saszmp.ru saszmp.ru A 220.164.140.186 saszmp.ru text = v=spf1 ip4:213.136.76.37 a mx ~all.ns1.imalna.ru ns1.imalna.ru A 213.136.76.37 ns2.imalna.ru A 220.164.140.186 mail.saszmp.ru A 220.164.140.186 --- DNS Lookup completed now not on a fast flux botnet but on 220.164.140.186. All redirecting to: http://www.crazycashformula.net/LP/8/de/index.htm?A=7460 IP: 199.83.129.198 ---> 199.83.129.198.ip.incapdns.net DNS @213.136.76.37 & 213.136.76.38 bkxim.ru cbvv.ru cjzvma.ru csaece.ru csog.ru cwthk.ru egfnp.ru eovn.ru fhbtu.ru fpscy.ru hwte.ru ilasy.ru illfh.ru izjeb.ru jjwr.ru loaep.ru lohzsz.ru mctjgt.ru mfmv.ru nwxt.ru pejhj.ru qfzdw.ru qqlwwf.ru qugemx.ru qulg.ru rdtmw.ru rebazp.ru rjzcr.ru saszmp.ru sjlyp.ru tpduok.ru urqgie.ru vomwv.ru vtjx.ru wprps.ru xfjdks.ru xiqcx.ru ybvrbb.ru yqmm.ru zkhxi.ru ______________ [220.164.140.186] bkxim.ru cbvv.ru cjzvma.ru csaece.ru csog.ru cwthk.ru egfnp.ru eovn.ru fhbtu.ru fpscy.ru hwte.ru ilasy.ru illfh.ru izjeb.ru jjwr.ru loaep.ru lohzsz.ru mctjgt.ru mfmv.ru nwxt.ru pejhj.ru qfzdw.ru qqlwwf.ru qugemx.ru qulg.ru rdtmw.ru rebazp.ru rjzcr.ru saszmp.ru sjlyp.ru tpduok.ru urqgie.ru vomwv.ru vtjx.ru wprps.ru xfjdks.ru xiqcx.ru ybvrbb.ru yqmm.ru zkhxi.ru _________ SBL250768 => The binary option spammer (T. Richert) has a new nameserver: [67.70.232.205] laipebvds.com NS2.HDNSCNM.COM NS1.HDNXCNS.COM billige-krankenversicherung.ru btuzr.ru bxpp.ru cvld.ru dsdvfdns.com fdwpv.ru fdzo.ru flflgbdms.com hdnscnm.com hdnxcns.com igfe.ru internet-wap.com ipiue.ru iqlj.ru iseserverdns.com iwjc.ru jdfyay.ru jhmos.ru jlibhaedns.com jzyxay.ru ktqovj.ru kxwjr.ru laipebvds.com mmljpk.ru nrofde.ru nxakx.ru pdqmk.ru postbank-deutschland-sicherheit.com pudj.ru pwsm.ru scjz.ru seiubjsns.com tcrwwv.ru txdqy.ru vkdzfs.ru wejcd.ru yysdva.ru [125.138.34.66] Server Name: NS1.SEIUBJSNS.COM Server Name: NS2.SEIUBJSNS.COM billige-krankenversicherung.ru dsdvfdns.com flflgbdms.com hdnxcns.com iseserverdns.com seiubjsns.com [2.229.90.234] Server Name: NS4.SEIUBJSNS.COM amazon-deutschland-bestellung-stornierung.com cjxhxjvhj.ru dvhvshv.ru fldnsforfreeonlynow.com flflgbdms.com gppv.ru gutscheiner24.ru hdnxcns.com hfeo.ru hostingfreednsserv.com hostingfreensserv.com iapz.ru internet-wap.com jlibhaedns.com kreditkarten-team-deutschland.com mixrku.ru paypal-deutschland-sicherheit-verifizierung.com postbank-deutschland-sicherheit.com qisn.ru secureduplink.com seiubjsns.com sikwej.ru soef.ru suqw.su vlefox.ru wuokdns.com yourdnsforfree888.com z1rkel.com [115.176.164.54] Server Name: NS1.ISESERVERDNS.COM Server Name: NS2.ISESERVERDNS.COM Server Name: NS3.ISESERVERDNS.COM Server Name: NS4.ISESERVERDNS.COM [153.232.119.89] Server Name: NS1.DSDVFDNS.COM acluzr.ru bbrkr.ru ceeckc.ru dsdvfdns.com dxtzi.ru ecsim.ru fjhr4t4t.ru fldnsforfreeonlynow.com flfldnsfree.com flflgbdms.com gcfh.su gqpr.ru hgqkei.ru hostingfreednsserv.com hostingfreensserv.com hsgr.ru iseserverdns.com jacmli.ru jlibhaedns.com laipebvds.com migiga.ru nunsdal.su nvbldk.ru okfdff.ru panbax.su pansedrt.su pmasden.ru uampe.su wuokdns.com yzkjq.ru zlimtc.ru [67.82.227.89] Server Name: NS3.DSDVFDNS.COM Server Name: NS4.DSDVFDNS.COM [119.25.89.204] NS2.DSDVFDNS.COM NS1.DSDVFDNS.COM NS4.HDNXCNS.COM NS3.FLDNSFORFREEONLYNOW.COM NS2.HDNSCNM.COM [46.196.208.82] NS4.LAIPEBVDS.COM [125.197.253.185] NS2.LAIPEBVDS.COM NS4.LAIPEBVDS.COM NS4.JLIBHAEDNS.COM Domain Name: HDNSCNM.COM Registrar: BIZCN.COM, INC. Sponsoring Registrar IANA ID: 471 Whois Server: whois.bizcn.com Referral URL: http://www.bizcn.com Name Server: NS1.HDNSCNM.COM Name Server: NS2.HDNSCNM.COM Name Server: NS3.HDNSCNM.COM Name Server: NS4.HDNSCNM.COM Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited Updated Date: 18-mar-2015 Creation Date: 18-mar-2015 Expiration Date: 18-mar-2016 domain: FDWPV.RU nserver: ns1.hdnscnm.com. nserver: ns2.hdnscnm.com. nserver: ns3.hdnscnm.com. nserver: ns4.hdnscnm.com. state: REGISTERED, DELEGATED, VERIFIED person: Private Person registrar: R01-RU admin-contact: https://partner.r01.ru/contact_admin.khtml created: 2015.03.17 paid-till: 2016.03.17 free-date: 2016.04.17 source: TCI Domain Name: YOURDNSFORFREE888.COM Registrar: BIZCN.COM, INC. Sponsoring Registrar IANA ID: 471 Whois Server: whois.bizcn.com Referral URL: http://www.bizcn.com Name Server: NS1.YOURDNSFORFREE888.COM Name Server: NS2.YOURDNSFORFREE888.COM Name Server: NS3.YOURDNSFORFREE888.COM Name Server: NS4.YOURDNSFORFREE888.COM Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited Status: clientHold http://www.icann.org/epp#clientHold Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited Updated Date: 13-mar-2015 Creation Date: 05-mar-2015 Expiration Date: 05-mar-2016 _________ SBL244474 => Fast Flux hosting: hqkm.ru ---> 87.116.228.92, 217.16.130.188 qtfpy.ru ---> 46.214.101.219 oyumkk.ru ---> 87.116.228.92, 46.214.101.219, 115.86.38.68, 37.203.107.49 all redirectors to: Domain Name: karrierejournal-de.net ---> 104.28.28.77 ---> Cloudflare domain: HQKM.RU nserver: ns1.dnshostingcool.com. nserver: ns2.dnshostingcool.com. nserver: ns3.dnshostingcool.com. nserver: ns4.dnshostingcool.com. state: REGISTERED, DELEGATED, VERIFIED person: Private Person registrar: R01-RU admin-contact: https://partner.r01.ru/contact_admin.khtml created: 2014.11.23 paid-till: 2015.11.23 free-date: 2015.12.24 source: TCI ns1.dnshostingcool.com [67.70.232.202] ns4.dnshostingcool.com [111.90.35.163] _______________ 14.97.104.236 hqkm.ru 14.97.104.236 iinawasx.su 14.97.104.236 iiqw.ru 14.97.104.236 inxxc.su 14.97.104.236 jkem.su 14.97.104.236 jqdquq.ru 14.97.104.236 jtjjqt.ru 14.97.104.236 jtjjqt.su 14.97.104.236 kkywpi.ru 14.97.104.236 mhfes.ru 14.97.104.236 mlxeqz.ru 14.97.104.236 nbblqv.ru 14.97.104.236 ndnvkq.ru 14.97.104.236 nhupp.su 14.97.104.236 njwp.su 14.97.104.236 nljj.ru 14.97.104.236 nnujtk.ru 14.97.104.236 nrwr.ru 14.97.104.236 oczv.ru 14.97.22.180 uiumr.ru 14.97.22.180 vbmmv.su 14.97.22.180 wcxcac.ru 14.97.22.180 weevbk.su 14.97.22.180 wjwwpf.ru 14.97.22.180 wspujo.ru 14.97.22.180 xafsc.ru 14.97.22.180 xgvp.ru 14.97.22.180 xktpwb.ru 14.99.173.120 fzryh.su 14.99.173.120 gdwhi.ru 14.99.173.120 gegop.ru 14.99.173.120 ggfuo.ru 14.99.173.120 ghyx.ru 14.99.173.120 gppv.ru 14.99.173.120 gswln.ru 14.99.173.120 gvaf.ru 14.99.173.120 gvhl.ru 14.99.173.120 gxqg.ru 14.99.173.120 gzvsbo.ru 14.99.173.120 hajfq.ru 14.99.173.120 hmvud.ru 14.99.173.120 kcouhe.ru 14.99.173.120 onxaswert.su 14.99.173.120 opayaqv.su 14.99.173.120 oypre.ru 14.99.173.120 paaswdlv.ru 14.99.173.120 pcshx.ru 14.99.173.120 pkouq.ru 14.99.173.120 pndum.ru 14.99.173.120 psdp.su 14.99.173.120 pstnzv.ru 14.99.173.120 pwsaxc.su 14.99.173.120 qibkhr.ru 14.99.173.120 qmhjl.ru 14.99.173.120 qncxf.ru 14.99.173.120 xqcziv.ru 14.99.173.120 ychsqt.ru 14.99.173.120 yfzw.ru 14.99.173.120 yogqt.su 14.99.173.120 ypttlf.ru 14.99.173.120 yzkjq.ru 14.99.173.120 zduzd.ru 14.99.173.120 zlimtc.ru 14.99.173.120 zmdih.ru 14.99.173.120 zodowj.ru 14.99.173.120 zogh.ru 27.49.2.211 amympv.ru 27.49.2.211 bvhqm.ru 27.49.2.211 fbxy.ru 27.49.2.211 fmqdc.ru 27.49.2.211 fnarit.ru 27.49.2.211 fzryh.ru 27.49.2.211 gxcy.ru 27.49.2.211 hsgr.ru 27.49.2.211 jounya.ru 27.49.2.211 knrfet.ru 27.49.2.211 mkyur.ru 27.49.2.211 pmasden.ru 27.49.2.211 sghdxu.ru 27.49.2.211 ttnxdr.su 27.49.2.211 ttymqq.ru 27.49.2.211 tuuil.ru 27.49.2.211 vfqrg.ru 27.49.2.211 vqzpo.ru 27.49.2.211 waqhga.ru 27.49.2.211 weevbk.ru 27.49.2.211 zrry.ru 27.49.2.211 zzcp.ru 62.210.74.52 aettra.ru 62.210.74.52 ahaeiz.ru 62.210.74.52 ajbkp.ru 62.210.74.52 akylwg.ru 62.210.74.52 awdhvc.ru 62.210.74.52 blofs.ru 62.210.74.52 bwrz.ru 62.210.74.52 cahyba.ru 62.210.74.52 cqbzxg.ru 62.210.74.52 cquxuw.ru 62.210.74.52 dktqu.ru 62.210.74.52 epjtaw.ru 62.210.74.52 evqou.ru 62.210.74.52 fadhiv.ru 62.210.74.52 kmzodt.ru 62.210.74.52 ksbck.ru 62.210.74.52 ktgmdk.ru 62.210.74.52 pawwmn.su 62.210.74.52 rcmgp.ru 62.210.74.52 rxhf.ru 67.70.232.202 rnld.ru 91.200.13.4 ajklxc.su 91.200.13.4 anasowpmansw.su 91.200.13.4 anmasaywsd.su 91.200.13.4 annsec.su 91.200.13.4 ansedrtn.su 91.200.13.4 apmansdws.su 91.200.13.4 aqcnsi.ru 91.200.13.4 ascgm.ru 91.200.13.4 ayxwl.ru 91.200.13.4 bldzqe.ru 91.200.13.4 cdapog.ru 91.200.13.4 csbgs.ru 91.200.13.4 diigfx.ru 91.200.13.4 dmzvmh.ru 91.200.13.4 dntqh.ru 91.200.13.4 drnsy.ru 91.200.13.4 duygn.ru 91.200.13.4 dzcpv.ru 91.200.13.4 eiqilf.ru 91.200.13.4 elsrcv.ru 91.200.13.4 elytj.su 91.200.13.4 epbn.ru 91.200.13.4 eqaibr.ru 91.200.13.4 euchfp.ru 91.200.13.4 faqwneic.ru 91.200.13.4 fawmeg.ru 91.200.13.4 ffhqmc.ru 91.200.13.4 fksuyr.ru 91.200.13.4 frlwa.ru 91.200.13.4 kpurwm.ru 91.200.13.4 lfonv.ru 91.200.13.4 ribizu.su 91.200.13.4 rqtybo.ru 91.200.13.4 sbgmwv.ru 91.200.13.4 soef.ru 91.200.13.4 sqfjp.su 91.200.13.4 tcpdcz.ru 91.200.13.4 tgtahn.ru 91.200.13.4 ykquw.ru [87.116.228.92] bnaczx.ru brmgnr.ru ckqjrm.ru dnshostingcool.com glyjdi.ru hfeo.ru igbsva.ru jrdxl.ru mxbwq.ru syqlny.ru tidauj.ru vyukgf.ru xlblmo.ru yhpnuf.ru ywqvgk.ru zdjkq.ru zyvcz.ru [217.16.130.188] dnshostingcool.com kbswl.ru oasx.su [46.214.101.219] dnshostingcool.com dnsfrnws.com [37.203.107.49] dnshostingcool.com kbswl.ru mxbwq.ru dnsfrnws.com _________ SBL236181 => IP: 212.129.57.124 ---> 212-129-57-124.rev.poneytelecom.eu [212.129.57.124] geldsofortxmlw5.link geldsofortxmlw7.com geldsofortxmlw8.com millionen-geheimnis20.com mopneadswnp6.com mopneadswnp7.com _______ SBL233563 => 62.210.74.52 ---> 62-210-74-52.rev.poneytelecom.eu Domains: www.geheimnisderinsider24.com [62.210.74.52] www.geheim2448.com [62.210.74.52] alibaba202010.com aufgedeckt15685.com baba3333.com bank112699.com folollo2016.com geheim145215.com geheim2448.com geheim2449.com geheim2451.com geheim2452.com geheimcode115662.com kologosos2033.com kredit660.com rababar2020.com Domain Name: GEHEIMNISDERINSIDER24.COM Registrar: ENOM, INC. Whois Server: whois.enom.com Referral URL: http://www.enom.com Name Server: DNS1.REGISTRAR-SERVERS.COM Name Server: DNS2.REGISTRAR-SERVERS.COM Name Server: DNS3.REGISTRAR-SERVERS.COM Name Server: DNS4.REGISTRAR-SERVERS.COM Name Server: DNS5.REGISTRAR-SERVERS.COM Status: clientTransferProhibited Updated Date: 04-sep-2014 Creation Date: 04-sep-2014 Expiration Date: 04-sep-2015 Domain Name: GEHEIMNISDERINSIDER24.COM Registry Domain ID: NA Registrar WHOIS Server: whois.enom.com Registrar URL: www.enom.com Updated Date: 2014-09-04 04:57:29Z Creation Date: 2014-09-04 11:57:00Z Registrar Registration Expiration Date: 2015-09-04 11:57:00Z Registrar: ENOM, INC. Registrar IANA ID: 48 Registrar Abuse Contact Email: abuse@enom.com Registrar Abuse Contact Phone: +1.4252744500 Reseller: NAMECHEAP.COM Domain Status: ok Registry Registrant ID: Registrant Name: ANTHONY CARISIO Registrant Organization: NOS Registrant Street: P.O. BOX Registrant City: BELIZE Registrant State/Province: BZ Registrant Postal Code: 78583 Registrant Country: BZ Registrant Phone: +501.111111111 Registrant Phone Ext: Registrant Fax: Registrant Fax Ext: Registrant Email: ANTHONYO992@GMX.COM Registry Admin ID: Admin Name: ANTHONY CARISIO Admin Organization: NOS Admin Street: P.O. BOX Admin City: BELIZE Admin State/Province: BZ Admin Postal Code: 78583 Admin Country: BZ Admin Phone: +501.111111111 Admin Phone Ext: Admin Fax: Admin Fax Ext: Admin Email: ANTHONYO992@GMX.COM Registry Tech ID: Tech Name: ANTHONY CARISIO Tech Organization: NOS Tech Street: P.O. BOX Tech City: BELIZE Tech State/Province: BZ Tech Postal Code: 78583 Tech Country: BZ Tech Phone: +501.111111111 Tech Phone Ext: Tech Fax: Tech Fax Ext: Tech Email: ANTHONYO992@GMX.COM Name Server: BLOCKEDDUETOSPAM.PLEASECONTACTSUPPORT.COM Name Server: DUMMYSECONDARY.PLEASECONTACTSUPPORT.COM DNSSEC: unSigned Domain Name: GEHEIMNISDERINSIDER24.COM Registry Domain ID: NA Registrar WHOIS Server: whois.enom.com Registrar URL: www.enom.com Updated Date: 2014-09-04 04:57:29Z Creation Date: 2014-09-04 11:57:00Z Registrar Registration Expiration Date: 2015-09-04 11:57:00Z Registrar: ENOM, INC. Registrar IANA ID: 48 Registrar Abuse Contact Email: abuse@enom.com Registrar Abuse Contact Phone: +1.4252744500 Reseller: NAMECHEAP.COM Domain Status: clientTransferProhibited Registry Registrant ID: Registrant Name: WHOISGUARD PROTECTED Registrant Organization: WHOISGUARD, INC. Registrant Street: P.O. BOX 0823-03411 Registrant City: PANAMA Registrant State/Province: PANAMA Registrant Postal Code: 00000 Registrant Country: PA Registrant Phone: +507.8365503 Registrant Phone Ext: Registrant Fax: +51.17057182 Registrant Fax Ext: Registrant Email: 501CE9F3E60B4EB5879924C73CDC9AA0.PROTECT@WHOISGUARD.COM Registry Admin ID: Admin Name: WHOISGUARD PROTECTED Admin Organization: WHOISGUARD, INC. Admin Street: P.O. BOX 0823-03411 Admin City: PANAMA Admin State/Province: PANAMA Admin Postal Code: 00000 Admin Country: PA Admin Phone: +507.8365503 Admin Phone Ext: Admin Fax: +51.17057182 Admin Fax Ext: Admin Email: 501CE9F3E60B4EB5879924C73CDC9AA0.PROTECT@WHOISGUARD.COM Registry Tech ID: Tech Name: WHOISGUARD PROTECTED Tech Organization: WHOISGUARD, INC. Tech Street: P.O. BOX 0823-03411 Tech City: PANAMA Tech State/Province: PANAMA Tech Postal Code: 00000 Tech Country: PA Tech Phone: +507.8365503 Tech Phone Ext: Tech Fax: +51.17057182 Tech Fax Ext: Tech Email: 501CE9F3E60B4EB5879924C73CDC9AA0.PROTECT@WHOISGUARD.COM Name Server: DNS1.REGISTRAR-SERVERS.COM Name Server: DNS2.REGISTRAR-SERVERS.COM Name Server: DNS3.REGISTRAR-SERVERS.COM Name Server: DNS4.REGISTRAR-SERVERS.COM Name Server: DNS5.REGISTRAR-SERVERS.COM |
||||||
![]() The Register of Known Spam Operations (ROKSO) collates information and evidence on entities with a history of spamming or providing spam services, and entities affiliated or otherwise connected with them, for the purpose of assisting ISP Abuse Desks and Law Enforcement Agencies. |
![]() |
|