Monday, September 23, 2013

Domain: fkfkfkfa.com

Received a Tip for this domain

Source:

--

Response:

About 255 A records in the 204.46.43.x range.

IPtables rule:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x08464b46 && 0x2c&0xDFDFDFDF=0x4b464b46 && 0x30&0xDFFFDFDF=0x4103434f" -j DROP -m comment --comment "DROP DNS Q fkfkfkfa.com"

More rules here

Name servers:

fkfkfkfa.com.           86400   IN      NS      ns2.fkfkfkfa.com.
fkfkfkfa.com.           86400   IN      NS      ns1.fkfkfkfa.com.

;; ADDITIONAL SECTION:
ns1.fkfkfkfa.com.       86400   IN      A       94.102.56.154
ns2.fkfkfkfa.com.       86400   IN      A       94.102.56.154

Whois:


http://www.networksolutions.com

Visit AboutUs.org for more information about FKFKFKFA.COM
<a href="http://www.aboutus.org/FKFKFKFA.COM">AboutUs: FKFKFKFA.COM </a>




Registrant:
Rattani, Altaf
   ATTN FKFKFKFA.COM
   care of Network Solutions
   PO Box 459
   Drums, PA.  US  18222


   Domain Name: FKFKFKFA.COM

   ------------------------------------------------------------------------
   Promote your business to millions of viewers for only $1 a month
   Learn how you can get an Enhanced Business Listing here for your domain name.
   Learn more at http://www.NetworkSolutions.com/
   ------------------------------------------------------------------------

   Administrative Contact, Technical Contact:
      Rattani, Altaf            nr25b87p72b@networksolutionsprivateregistration.com
      ATTN FKFKFKFA.COM
      care of Network Solutions
      PO Box 459
      Drums, PA 18222
      US
      570-708-8780


   Record expires on 22-Sep-2014.
   Record created on 22-Sep-2013.
   Database last updated on 23-Sep-2013 17:13:08 EDT.

   Domain servers in listed order:

   NS1.FKFKFKFA.COM             94.102.56.154
   NS2.FKFKFKFA.COM             94.102.56.153

This listing is a Network Solutions Private Registration. Mail
correspondence to this address must be sent via USPS Express Mail(TM) or
USPS Certified Mail(R); all other mail will not be processed. Be sure to
include the registrant's domain name in the address.


3 comments:

  1. I'm seeing probes for a DNS server allowing recursive lookups from this host pretty regularly. Looks like SURBL has blacklisted them within the past few weeks based on the IDS, but he's still up.

    ReplyDelete
  2. looking at my ironwall log
    i stil don't get this packet with fkfkfkfa.com
    ip packet spam? from ramdom ip
    well i got to lol

    ReplyDelete