1 25-Jul-2013
2 27-Jul-2013
73586 28-Jul-2013
This domain has been actively for ... some purpose:
http://webcache.googleusercontent.com/search?q=cache:nBmADhmYPbsJ:hizbullah.me/+&cd=1&hl=en&ct=clnk&gl=nl
Anyway: http://en.wikipedia.org/wiki/Hezbollah
Response:
244 A records in the 204.46.43.x range.
;; MSG SIZE rcvd: 3973
I'm seeing queries for both IN A as well as IN ANY.
IPtables rule:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0948495a && 0x2c&0xDFDFDFDF=0x42554c4c && 0x30&0xDFDFFFDF=0x4148024d && 0x34&0xDFFFFFFF=0x450000FF" -j DROP -m comment --comment "DROP DNS Q ANY hizbullah.me"
Name server:
hizbullah.me. 1800 IN NS ns2.hizbullah.me.
ns2.hizbullah.me. 876 IN A 176.227.205.34
176.227.205.34 AS35662 Redstation Limited
Whois
Domain ID:D8379044-ME
Domain Name:HIZBULLAH.ME
Domain Create Date:28-May-2013 10:52:44 UTC
Domain Last Updated Date:27-Jul-2013 20:50:07 UTC
Domain Expiration Date:28-May-2014 10:52:44 UTC
Last Transferred Date:
Sponsoring Registrar:1API GmbH R17-ME
Created by:1API GmbH R17-ME
Last Updated by Registrar:Afilias R54-ME
Domain Status:CLIENT TRANSFER PROHIBITED
Registrant ID:KMP15502545-REAZ
Registrant Name:Kimberley Mently
Registrant Organization:Private Person
Registrant Address:102 po box
Registrant Address2:
Registrant Address3:
Registrant City:chicago
Registrant State/Province:VA
Registrant Country/Economy:US
Registrant Postal Code:43212
Registrant Phone:+1.2837732283
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant E-mail:
Admin ID:KMP15502545-REAZ
Admin Name:Kimberley Mently
Admin Organization:Private Person
Admin Address:102 po box
Admin Address2:
Admin Address3:
Admin City:chicago
Admin State/Province:VA
Admin Country/Economy:US
Admin Postal Code:43212
Admin Phone:+1.2837732283
Admin Phone Ext.:
Admin FAX:
Admin FAX Ext.:
Admin E-mail:
Tech ID:KMP15502545-REAZ
Tech Name:Kimberley Mently
Tech Organization:Private Person
Tech Address:102 po box
Tech Address2:
Tech Address3:
Tech City:chicago
Tech State/Province:VA
Tech Country/Economy:US
Tech Postal Code:43212
Tech Phone:+1.2837732283
Tech Phone Ext.:
Tech FAX:
Tech FAX Ext.:
Tech E-mail:
Nameservers:NS1.HIZBULLAH.ME
Nameservers:NS2.HIZBULLAH.ME
Attacked IPs:
Top 50
15481 204.75.167.165
2922 99.153.244.45
2674 37.252.102.25
2557 137.116.186.96
2488 112.175.69.112
2483 37.252.102.41
2438 37.114.52.35
2188 208.98.37.162
1969 177.71.150.244
1878 84.108.228.43
1231 94.23.18.145
1214 65.52.24.110
1120 188.224.19.204
1003 94.23.6.52
989 212.224.114.158
826 82.66.184.16
801 2.24.90.247
778 5.39.68.139
722 80.139.126.113
711 71.59.18.2
657 208.98.37.163
629 107.197.252.69
587 98.254.241.202
578 199.180.251.9
560 74.91.113.63
517 78.145.214.3
500 78.129.224.17
490 109.64.60.235
490 108.50.48.48
481 109.123.126.145
420 69.31.20.84
393 80.179.219.56
380 66.87.24.16
380 174.54.135.5
361 77.251.53.38
338 208.98.56.228
326 37.142.185.36
320 84.200.69.115
318 74.91.122.78
315 208.98.37.164
312 94.197.127.72
311 94.23.199.109
311 62.219.125.174
310 78.35.109.201
307 173.56.45.175
304 76.110.53.166
301 168.61.144.13
289 188.165.58.31
280 79.195.184.168
279 5.39.92.42