Showing posts with label Ecatel. Show all posts
Showing posts with label Ecatel. Show all posts

Sunday, December 22, 2013

Domain: amp.crack-zone.ru

Domain: amp.crack-zone.ru

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x03414d50 && 0x2c&0xFFDFDFDF=0x0a435241 && 0x30&0xDFDFFFDF=0x434b2d5a && 0x34&0xDFDFDFFF=0x4f4e4502 && 0x38&0xDFDFFF00=0x52550000" -j DROP -m comment --comment "DROP DNS Q amp.crack-zone.ru"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 59 --algo bm --hex-string '|03616d700A637261636b2d7a6f6e6502727500|' -j DROP -m comment --comment "DROP DNS Q amp.crack-zone.ru"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


94.102.51.228

Name server:

;; ANSWER SECTION:
crack-zone.ru.          51518   IN      NS      jim.ns.cloudflare.com.
crack-zone.ru.          51518   IN      NS      fay.ns.cloudflare.com.

;; ADDITIONAL SECTION:
fay.ns.cloudflare.com.  72548   IN      A       173.245.58.115
jim.ns.cloudflare.com.  85943   IN      A       173.245.59.125
jim.ns.cloudflare.com.  85943   IN      AAAA    2400:cb00:2049:1::adf5:3b7d
fay.ns.cloudflare.com.  72548   IN      AAAA    2400:cb00:2049:1::adf5:3a73

Response:


TXT 3
Rsize 9226


Whois

% By submitting a query to RIPN's Whois Service
% you agree to abide by the following terms of use:
% http://www.ripn.net/about/servpol.html#3.2 (in Russian)
% http://www.ripn.net/about/en/servpol.html#3.2 (in English).

domain:        CRACK-ZONE.RU
nserver:       fay.ns.cloudflare.com.
nserver:       jim.ns.cloudflare.com.
state:         REGISTERED, DELEGATED, UNVERIFIED
person:        Private Person
registrar:     REGRU-REG-RIPN
admin-contact: http://www.reg.ru/whois/admin_contact
created:       2013.06.22
paid-till:     2014.06.22
free-date:     2014.07.23
source:        TCI





Wednesday, December 4, 2013

Domain: dnsamplificationattacks.cc

Domain: dnsamplificationattacks.cc

# This domain does not belong to me # (yet)

Well how about that. Some one bought me a domain name! Maybe I can seize it... ;-)

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x17444e53 && 0x2c&0xDFDFDFDF=0x414d504c && 0x30&0xDFDFDFDF=0x49464943 && 0x34&0xDFDFDFDF=0x4154494f && 0x38&0xDFDFDFDF=0x4e415454 && 0x3c&0xDFDFDFDF=0x41434b53 && 0x40&0xFFDFDFFF=0x02434300" -j DROP -m comment --comment "DROP DNS Q dnsamplificationattacks.cc"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 68 --algo bm --hex-string '|17646e73616d706c696669636174696f6e61747461636b7302636300|' -j DROP -m comment --comment "DROP DNS Q dnsamplificationattacks.cc"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


80.82.65.237 - Ecatel

Name server:


;; ANSWER SECTION:
dnsamplificationattacks.cc. 9533 IN NS b.dns.gandi.net.
dnsamplificationattacks.cc. 9533 IN NS a.dns.gandi.net.
dnsamplificationattacks.cc. 9533 IN NS c.dns.gandi.net.


Response:


A 246
NS 3
SOA 1
Rsize 4072


Whois



Whois Server Version 2.0

Domain names can now be registered with many different competing registrars.
Go to http://registrar.verisign-grs.com/whois/ for detailed information.

Domain Name: DNSAMPLIFICATIONATTACKS.CC
Domain ID: 108517593
Whois Server: whois.gandi.net
Referral URL: http://www.gandi.net
Updated Date: 2013-12-04T14:44:17Z
Creation Date: 2013-12-04T14:44:16Z
Expiration Date: 2014-12-04T14:44:16Z
Sponsoring Registrar: GANDI SAS
Sponsoring Registrar IANA ID: 81
Domain Status: CLIENT-XFER-PROHIBITED
Name Server: A.DNS.GANDI.NET
Name Server: B.DNS.GANDI.NET
Name Server: C.DNS.GANDI.NET
DNSSEC: Unsigned delegation


>>> Last update of whois database: 2013-12-04T22:28:30Z <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the
expiration date of the domain name registrant's agreement with the
sponsoring registrar. Users may consult the sponsoring registrar's
Whois database to view the registrar's reported date of expiration
for this registration.


The Registry database contains ONLY .cc, .tv, and .jobs domains
and Registrars.
--- #YAML:1.0
# GANDI Registrar whois database for .COM, .NET, .ORG., .INFO, .BIZ, .NAME
#

domain: dnsamplificationattacks.cc
reg_created: 2013-12-04 19:44:16
expires: 2014-12-04 19:44:16
created: 2013-12-04 20:44:16
changed: 2013-12-04 20:55:28
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
admin-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
tech-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
bill-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58



Friday, October 11, 2013

Domain: babywow.co.uk

Domain: babywow.co.uk

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x07424142 && 0x2c&0xDFDFDFDF=0x59574f57 && 0x30&0xFFDFDFFF=0x02434f02 && 0x34&0xDFDFFF00=0x554b0000" -j DROP -m comment --comment "DROP DNS Q babywow.co.uk"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 55 --algo bm --hex-string '|0762616279776f7702636f02756b00|' -j DROP -m comment --comment "DROP DNS Q babywow.co.uk"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


94.102.52.44 - Ecatel

Name server:


;; ANSWER SECTION:
babywow.co.uk. 10800 IN NS b.dns.gandi.net.
babywow.co.uk. 10800 IN NS a.dns.gandi.net.
babywow.co.uk. 10800 IN NS c.dns.gandi.net.

;; ADDITIONAL SECTION:
a.dns.gandi.net. 44411 IN A 173.246.97.2
a.dns.gandi.net. 44411 IN AAAA 2604:3400:a::2
b.dns.gandi.net. 44411 IN A 217.70.184.40
b.dns.gandi.net. 44411 IN AAAA 2001:4b98:b:a::40
c.dns.gandi.net. 44411 IN A 217.70.182.20
c.dns.gandi.net. 44411 IN AAAA 2001:4b98:c:521::20


Response:


A 243
NS 3
SOA 1
TXT 2
Rsize 4515


Whois



Domain name:
babywow.co.uk

Registrant:
Jesy Leu

Registrant type:
UK Individual

Registrant's address:
The registrant is a non-trading individual who has opted to have their
address omitted from the WHOIS service.

Registrar:
Gandi t/a Gandi [Tag = GANDI]
URL: http://www.gandi.net

Relevant dates:
Registered on: 07-Oct-2013
Expiry date: 07-Oct-2014
Last updated: 07-Oct-2013

Registration status:
Registered until expiry date.

Name servers:
a.dns.gandi.net
b.dns.gandi.net
c.dns.gandi.net

WHOIS lookup made at 22:35:53 11-Oct-2013

--
This WHOIS information is provided for free by Nominet UK the central registry
for .uk domain names. This information and the .uk WHOIS are:

Copyright Nominet UK 1996 - 2013.

You may not access the .uk WHOIS or use any data from it except as permitted
by the terms of use available in full at http://www.nominet.org.uk/whoisterms, which
includes restrictions on: (A) use of the data for advertising, or its
repackaging, recompilation, redistribution or reuse (B) obscuring, removing
or hiding any or all of this notice and (C) exceeding query rate or volume
limits. The data is provided on an 'as-is' basis and may lag behind the
register. Access may be withdrawn or restricted at any time.



Wednesday, October 2, 2013

Domain: irlwinning.com

Scan and attacks for: irlwinning.com (In Real Life Winning .com) funny guy. He's probably 16.

Source IP seems to be a busy beaver.

IPtables:

There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0a49524c && 0x2c&0xDFDFDFDF=0x57494e4e && 0x30&0xDFDFDFFF=0x494e4703 && 0x34&0xDFDFDFFF=0x434f4d00" -j DROP -m comment --comment "DROP DNS Q irlwinning.com"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt


String:

iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 56 --algo bm --hex-string '|0A69726c77696e6e696e6703636f6d00|' -j DROP -m comment --comment "DROP DNS Q irlwinning.com"

More Iptables rules for the STRING module can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:

80.82.65.204 - Ecatel

   2052 hizbullah.me
    431 bitstress.com
     80 8js44.xplodin.com
     59 hak4umz.net
      3 xplodin.com
      2 srvit.org
      1 directedat.asia
      1 anonsc.com

89.248.168.136 -  Ecatel

      4 theswat.net
      1 hizbullah.me

Name server:


irlwinning.com.         21600   IN      NS      ns1.irlwinning.com.
irlwinning.com.         21600   IN      NS      ns2.irlwinning.com.

;; ADDITIONAL SECTION:
ns2.irlwinning.com.     21600   IN      A       69.42.219.74
ns1.irlwinning.com.     21600   IN      A       69.42.219.74


Response:


243 A records in the 1.1.1.226

Whois


Domain irlwinning.com

Date Registered: 2013-10-1
Expiry Date: 2014-10-1

DNS1: ns1.irlwinning.com
DNS2: ns2.irlwinning.com

Registrant
    Fundacion Private Whois
    Domain Administrator
    Email:524b08137qidwx4b@5225b4d0pi3627q9.privatewhois.net
    Attn: irlwinning.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Administrative Contact
    Fundacion Private Whois
    Domain Administrator
    Email:524b0813sfmrmn27@5225b4d0pi3627q9.privatewhois.net
    Attn: irlwinning.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Technical Contact
    Fundacion Private Whois
    Domain Administrator
    Email:524b081301e20o65@5225b4d0pi3627q9.privatewhois.net
    Attn: irlwinning.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Registrar: Internet.bs Corp.
Registrar's Website : <a href='http://www.internetbs.net/'>http://www.internetbs.net/</a>







Tuesday, October 1, 2013

Domain: pkts.asia

Thanks Allan for the tip. Also observed a discovery from:


IPtables:

There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x04504b54 && 0x2c&0xDFFFDFDF=0x53044153 && 0x30&0xDFDFFFFF=0x49410000" -j DROP -m comment --comment "DROP DNS Q pkts.asia"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt


String:

iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 51 --algo bm --hex-string '|04706b7473046173696100|' -j DROP -m comment --comment "DROP DNS Q pkts.asia"

More Iptables rules for the STRING module can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


89.248.168.136 - Ecatel

Seen this ip before:

TheSwat.net
Hizbullah.met

Name server:


pkts.asia.              14676   IN      NS      ns1.pkts.asia.
pkts.asia.              14676   IN      NS      ns2.pkts.asia.

;; ADDITIONAL SECTION:
ns1.pkts.asia.          14676   IN      A       69.42.219.74
ns2.pkts.asia.          14676   IN      A       69.42.219.74

Response:


245 A records in the 1.1.1.x range

Whois


Domain ID:D2806247-ASIA
Domain Name:PKTS.ASIA
Domain Create Date:01-Oct-2013 03:22:21 UTC
Domain Expiration Date:01-Oct-2014 03:22:21 UTC
Domain Last Updated Date:01-Oct-2013 19:54:25 UTC
Last Transferred Date:
Created by:Internet.bs Corp. R176-ASIA (814)
Last Updated by Registrar:Internet.bs Corp. R176-ASIA (814)
Sponsoring Registrar:Internet.bs Corp. R176-ASIA (814)
Domain Status:CLIENT TRANSFER PROHIBITED
Domain Status:TRANSFER PROHIBITED
Status:ADDPERIOD
Registrant ID:INTEj09wxvky9cwv
Registrant Name:Domain Administrator
Registrant Organization:Fundacion Private Whois
Registrant Address:Attn: pkts.asia
Registrant Address2:Aptds. 0850-00056
Registrant Address3:
Registrant City:Panama
Registrant State/Province:
Registrant Country/Economy:PA
Registrant Postal Code:Zona 15
Registrant Phone:+507.65995877
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant E-mail:524a3fe3bbnpgi8d@5225b4d0pi3627q9.privatewhois.net
Administrative ID:INTEord72uqcb16n
Administrative Name:Domain Administrator
Administrative Organization:Fundacion Private Whois
Administrative Address:Attn: pkts.asia
Administrative Address2:Aptds. 0850-00056
Administrative Address3:
Administrative City:Panama
Administrative State/Province:
Administrative Country/Economy:PA
Administrative Postal Code:Zona 15
Administrative Phone:+507.65995877
Administrative Phone Ext.:
Administrative FAX:
Administrative FAX Ext.:
Administrative E-mail:524a3fe5and4zbsf@5225b4d0pi3627q9.privatewhois.net
Technical ID:INTEzihq17tjuf2q
Technical Name:Domain Administrator
Technical Organization:Fundacion Private Whois
Technical Address:Attn: pkts.asia
Technical Address2:Aptds. 0850-00056
Technical Address3:
Technical City:Panama
Technical State/Province:
Technical Country/Economy:PA
Technical Postal Code:Zona 15
Technical Phone:+507.65995877
Technical Phone Ext.:
Technical FAX:
Technical FAX Ext.:
Technical E-mail:524a3fe5ilbgz7g6@5225b4d0pi3627q9.privatewhois.net
Billing ID:INTElq2psm15rdqt
Billing Name:Domain Administrator
Billing Organization:Fundacion Private Whois
Billing Address:Attn: pkts.asia
Billing Address2:Aptds. 0850-00056
Billing Address3:
Billing City:Panama
Billing State/Province:
Billing Country/Economy:PA
Billing Postal Code:Zona 15
Billing Phone:+507.65995877
Billing Phone Ext.:
Billing FAX:
Billing FAX Ext.:
Billing E-mail:524a3fe7w1y9heh2@5225b4d0pi3627q9.privatewhois.net
CED ID:INTEj09wxvky9cwv
CED CC Locality:AM
CED Type of Legal Entity:Natural Persons
CED Form of Identification:Passport or Citizenship ID
Operations and Notifications ID:INTEj09wxvky9cwv
Operations and Notifications Name:Domain Administrator
Operations and Notifications Organization:Fundacion Private Whois
Operations and Notifications Address:Attn: pkts.asia
Operations and Notifications Address2:Aptds. 0850-00056
Operations and Notifications Address3:
Operations and Notifications City:Panama
Operations and Notifications State/Province:
Operations and Notifications Country/Economy:PA
Operations and Notifications Postal Code:Zona 15
Operations and Notifications Phone:+507.65995877
Operations and Notifications Phone Ext.:
Operations and Notifications FAX:
Operations and Notifications FAX Ext.:
Operations and Notifications E-mail:524a3fe3bbnpgi8d@5225b4d0pi3627q9.privatewhois.net
Nameservers:NS1.PKTS.ASIA
Nameservers:NS2.PKTS.ASIA





Monday, September 30, 2013

domain: zaikapaika.com

Seen a scan for this domain on 30-09-2013.

IPtables:


iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0a5a4149 && 0x2c&0xDFDFDFDF=0x4b415041 && 0x30&0xDFDFDFFF=0x494b4103 && 0x34&0xDFDFDFFF=0x434f4d00" -j DROP -m comment --comment "DROP DNS Q zaikapaika.com"

Source:


89.248.174.54 - Ecatel (everytime)

Also seen this IP for:

 kiddy3233655.ru

Name server:


zaikapaika.com.         10800   IN      NS      b.dns.gandi.net.
zaikapaika.com.         10800   IN      NS      a.dns.gandi.net.
zaikapaika.com.         10800   IN      NS      c.dns.gandi.net.

;; ADDITIONAL SECTION:
c.dns.gandi.net.        85933   IN      AAAA    2001:4b98:c:521::20
b.dns.gandi.net.        85933   IN      AAAA    2001:4b98:b:a::40
a.dns.gandi.net.        85933   IN      AAAA    2604:3400:a::2
a.dns.gandi.net.        85933   IN      A       173.246.97.2
b.dns.gandi.net.        85933   IN      A       217.70.184.40
c.dns.gandi.net.        85933   IN      A       217.70.182.20


Response:


241 A records in the 204.46.43.x range.

Whois

domain: zaikapaika.com
reg_created: 2013-09-23 08:41:35
expires: 2014-09-23 08:41:35
created: 2013-09-23 10:41:36
changed: 2013-09-26 22:32:45
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18
admin-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18
tech-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18
bill-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18

Saturday, September 21, 2013

Domain: kiddy3233655.ru

89.248.174.54

Source:

Observed the first requests for this domain on September 21th from:

89.248.174.54 - Ecatel !


Response:

About 257 A records in the 204.46.43.x range.


IPtables rule:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0c4b4944 && 0x2c&0xDFDFFFFF=0x44593332 && 0x30&0xFFFFFFFF=0x33333635 && 0x34&0xFFFFDFDF=0x35025255" -j DROP -m comment --comment "DROP DNS Q kiddy3233655.ru"

More rules here

Name servers:

kiddy3233655.ru.        43200   IN      NS      ns1.reg.ru.
kiddy3233655.ru.        43200   IN      NS      ns2.reg.ru.

;; ADDITIONAL SECTION:
ns1.reg.ru.             86399   IN      AAAA    2a00:f940::25
ns1.reg.ru.             86399   IN      A       31.31.205.39
ns2.reg.ru.             86399   IN      A       88.212.207.122
ns1.reg.ru.             86399   IN      A       31.31.204.37
ns2.reg.ru.             86399   IN      AAAA    2a00:f940::37
ns1.reg.ru.             86399   IN      A       31.31.205.55
ns1.reg.ru.             86399   IN      A       31.31.204.52
ns2.reg.ru.             86399   IN      A       144.76.40.132
ns2.reg.ru.             86399   IN      A       31.31.205.56
ns2.reg.ru.             86399   IN      A       198.100.149.22
ns1.reg.ru.             86399   IN      A       31.31.204.25
ns2.reg.ru.             86399   IN      A       31.31.205.74
ns1.reg.ru.             86399   IN      A       31.31.205.73


Whois:

domain:        KIDDY3233655.RU
nserver:       ns1.reg.ru.
nserver:       ns2.reg.ru.
state:         REGISTERED, DELEGATED, UNVERIFIED
person:        Private Person
registrar:     REGRU-REG-RIPN
admin-contact: http://www.reg.ru/whois/admin_contact
created:       2013.01.27
paid-till:     2014.01.27
free-date:     2014.02.27
source:        TCI

Last updated on 2013.09.22 00:56:37 MSK



Domain: bitstress.com

Received a tip about this domain before I had the time to discover it in my log files. Thanks! :)

Source:

Observed the first requests for this domain on September 18th from:

80.82.65.204 - Ecatel


Response:

About 242 A records in the 204.46.43.x range.


IPtables rule:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x09424954 && 0x2c&0xDFDFDFDF=0x53545245 && 0x30&0xDFDFDFDF=0x53530343 && 0x34&0xDFDFFFFF=0x4f4d0000" -j DROP -m comment --comment "DROP DNS Q bitstress.com"

More rules here

Name servers:

bitstress.com.          73670   IN      NS      ns2.bitstress.com.
bitstress.com.          73670   IN      NS      ns1.bitstress.com.

;; ADDITIONAL SECTION:
ns1.bitstress.com.      73670   IN      A       94.102.56.151
ns2.bitstress.com.      73670   IN      A       69.42.219.74


Whois:

Domain bitstress.com

Date Registered: 2013-9-16
Expiry Date: 2014-9-16

DNS1: ns1.bitstress.com
DNS2: ns2.bitstress.com

Registrant
    Fundacion Private Whois
    Domain Administrator
    Email:523780aed7qk26dt@5225b4d0pi3627q9.privatewhois.net
    Attn: bitstress.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Administrative Contact
    Fundacion Private Whois
    Domain Administrator
    Email:523780ae2ke1mbef@5225b4d0pi3627q9.privatewhois.net
    Attn: bitstress.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Technical Contact
    Fundacion Private Whois
    Domain Administrator
    Email:523780aen5ps83ng@5225b4d0pi3627q9.privatewhois.net
    Attn: bitstress.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Registrar: Internet.bs Corp.
Registrar's Website : <a href='http://www.internetbs.net/'>http://www.internetbs.net/</a>