Showing posts with label domain. Show all posts
Showing posts with label domain. Show all posts

Sunday, December 22, 2013

Domain: amp.crack-zone.ru

Domain: amp.crack-zone.ru

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x03414d50 && 0x2c&0xFFDFDFDF=0x0a435241 && 0x30&0xDFDFFFDF=0x434b2d5a && 0x34&0xDFDFDFFF=0x4f4e4502 && 0x38&0xDFDFFF00=0x52550000" -j DROP -m comment --comment "DROP DNS Q amp.crack-zone.ru"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 59 --algo bm --hex-string '|03616d700A637261636b2d7a6f6e6502727500|' -j DROP -m comment --comment "DROP DNS Q amp.crack-zone.ru"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


94.102.51.228

Name server:

;; ANSWER SECTION:
crack-zone.ru.          51518   IN      NS      jim.ns.cloudflare.com.
crack-zone.ru.          51518   IN      NS      fay.ns.cloudflare.com.

;; ADDITIONAL SECTION:
fay.ns.cloudflare.com.  72548   IN      A       173.245.58.115
jim.ns.cloudflare.com.  85943   IN      A       173.245.59.125
jim.ns.cloudflare.com.  85943   IN      AAAA    2400:cb00:2049:1::adf5:3b7d
fay.ns.cloudflare.com.  72548   IN      AAAA    2400:cb00:2049:1::adf5:3a73

Response:


TXT 3
Rsize 9226


Whois

% By submitting a query to RIPN's Whois Service
% you agree to abide by the following terms of use:
% http://www.ripn.net/about/servpol.html#3.2 (in Russian)
% http://www.ripn.net/about/en/servpol.html#3.2 (in English).

domain:        CRACK-ZONE.RU
nserver:       fay.ns.cloudflare.com.
nserver:       jim.ns.cloudflare.com.
state:         REGISTERED, DELEGATED, UNVERIFIED
person:        Private Person
registrar:     REGRU-REG-RIPN
admin-contact: http://www.reg.ru/whois/admin_contact
created:       2013.06.22
paid-till:     2014.06.22
free-date:     2014.07.23
source:        TCI





Wednesday, December 4, 2013

Domain: dnsamplificationattacks.cc

Domain: dnsamplificationattacks.cc

# This domain does not belong to me # (yet)

Well how about that. Some one bought me a domain name! Maybe I can seize it... ;-)

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x17444e53 && 0x2c&0xDFDFDFDF=0x414d504c && 0x30&0xDFDFDFDF=0x49464943 && 0x34&0xDFDFDFDF=0x4154494f && 0x38&0xDFDFDFDF=0x4e415454 && 0x3c&0xDFDFDFDF=0x41434b53 && 0x40&0xFFDFDFFF=0x02434300" -j DROP -m comment --comment "DROP DNS Q dnsamplificationattacks.cc"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 68 --algo bm --hex-string '|17646e73616d706c696669636174696f6e61747461636b7302636300|' -j DROP -m comment --comment "DROP DNS Q dnsamplificationattacks.cc"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


80.82.65.237 - Ecatel

Name server:


;; ANSWER SECTION:
dnsamplificationattacks.cc. 9533 IN NS b.dns.gandi.net.
dnsamplificationattacks.cc. 9533 IN NS a.dns.gandi.net.
dnsamplificationattacks.cc. 9533 IN NS c.dns.gandi.net.


Response:


A 246
NS 3
SOA 1
Rsize 4072


Whois



Whois Server Version 2.0

Domain names can now be registered with many different competing registrars.
Go to http://registrar.verisign-grs.com/whois/ for detailed information.

Domain Name: DNSAMPLIFICATIONATTACKS.CC
Domain ID: 108517593
Whois Server: whois.gandi.net
Referral URL: http://www.gandi.net
Updated Date: 2013-12-04T14:44:17Z
Creation Date: 2013-12-04T14:44:16Z
Expiration Date: 2014-12-04T14:44:16Z
Sponsoring Registrar: GANDI SAS
Sponsoring Registrar IANA ID: 81
Domain Status: CLIENT-XFER-PROHIBITED
Name Server: A.DNS.GANDI.NET
Name Server: B.DNS.GANDI.NET
Name Server: C.DNS.GANDI.NET
DNSSEC: Unsigned delegation


>>> Last update of whois database: 2013-12-04T22:28:30Z <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the
expiration date of the domain name registrant's agreement with the
sponsoring registrar. Users may consult the sponsoring registrar's
Whois database to view the registrar's reported date of expiration
for this registration.


The Registry database contains ONLY .cc, .tv, and .jobs domains
and Registrars.
--- #YAML:1.0
# GANDI Registrar whois database for .COM, .NET, .ORG., .INFO, .BIZ, .NAME
#

domain: dnsamplificationattacks.cc
reg_created: 2013-12-04 19:44:16
expires: 2014-12-04 19:44:16
created: 2013-12-04 20:44:16
changed: 2013-12-04 20:55:28
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
admin-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
tech-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58
bill-c:
nic-hdl: JK3349-GANDI
owner-name: Jorj Keria
organisation: ~
person: Jorj Keria
address: 'St.Patrick 183 , 2'
zipcode: 11012
city: New York
country: United States of America
phone: +1.2811243314
fax: ~
email: 529347fb1b098f6ad72b8fbb39d00fce-1820552@contact.gandi.net
lastupdated: 2013-12-04 20:45:58



Friday, November 29, 2013

Domain: marusiaattack.pw

Domain: marusiaattack.pw

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0d4d4152 && 0x2c&0xDFDFDFDF=0x55534941 && 0x30&0xDFDFDFDF=0x41545441 && 0x34&0xDFDFFFDF=0x434b0250 && 0x38&0xDFFF0000=0x57000000" -j DROP -m comment --comment "DROP DNS Q marusiaattack.pw"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 58 --algo bm --hex-string '|0D6d61727573696161747461636b02707700|' -j DROP -m comment --comment "DROP DNS Q marusiaattack.pw"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


No IP source for this domain

Name server:


;; ANSWER SECTION:
marusiaattack.pw. 21600 IN NS ns1.reg.ru.
marusiaattack.pw. 21600 IN NS ns2.reg.ru.


Response:


A 242
NS 2
SOA 1
Rsize 3979


Whois


This whois service is provided by CentralNic Ltd and only contains
information pertaining to Internet domain names we have registered for
our customers. By using this service you are agreeing (1) not to use any
information presented here for any purpose other than determining
ownership of domain names, (2) not to store or reproduce this data in
any way, (3) not to use any high-volume, automated, electronic processes
to obtain data from this service. Abuse of this service is monitored and
actions in contravention of these terms will result in being permanently
blacklisted. All data is (c) CentralNic Ltd https://www.centralnic.com/

Domain ID:CNIC-DO1656911
Domain Name:MARUSIAATTACK.PW
Created On:2013-11-28T23:27:45.0Z
Last Updated On:2013-11-28T23:27:46.0Z
Expiration Date:2014-11-28T23:59:59.0Z
Status:TRANSFER PROHIBITED
Status:ADD PERIOD
Registrant ID:H4516280
Registrant Name:Magamed Ishakov
Registrant Organization:Private Person
Registrant Street1:fonar d 81 kv 188
Registrant City:Moscow
Registrant State/Province:Moscow
Registrant Postal Code:119484
Registrant Country:RU
Registrant Phone:+7.9264756756
Registrant Email:webmaster@search-alles.us
Admin ID:H4516283
Admin Name:Magamed Ishakov
Admin Organization:Private Person
Admin Street1:fonar d 81 kv 188
Admin City:Moscow
Admin State/Province:Moscow
Admin Postal Code:119484
Admin Country:RU
Admin Phone:+7.9264756756
Admin Email:webmaster@search-alles.us
Tech ID:H4516286
Tech Name:Magamed Ishakov
Tech Organization:Private Person
Tech Street1:fonar d 81 kv 188
Tech City:Moscow
Tech State/Province:Moscow
Tech Postal Code:119484
Tech Country:RU
Tech Phone:+7.9264756756
Tech Email:webmaster@search-alles.us
Billing ID:H4516289
Billing Name:Magamed Ishakov
Billing Organization:Private Person
Billing Street1:fonar d 81 kv 188
Billing City:Moscow
Billing State/Province:Moscow
Billing Postal Code:119484
Billing Country:RU
Billing Phone:+7.9264756756
Billing Email:webmaster@search-alles.us
Sponsoring Registrar ID:H2440764
Sponsoring Registrar IANA ID:1606
Sponsoring Registrar Organization:Registrar of Domain Names REG.RU, LLC
Sponsoring Registrar Street1:Office 326, House 3 Vasily Petushkov Street
Sponsoring Registrar City:Moscow
Sponsoring Registrar Postal Code:125476
Sponsoring Registrar Country:RU
Sponsoring Registrar Phone:+74955801111
Sponsoring Registrar FAX:+74954915553
Sponsoring Registrar Website:http://www.reg.ru/
Name Server:NS1.REG.RU
Name Server:NS2.REG.RU
DNSSEC:Unsigned





Wednesday, November 27, 2013

Domain: stopdrugs77.com

Domain: stopdrugs77.com



If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0b53544f && 0x2c&0xDFDFDFDF=0x50445255 && 0x30&0xDFDFFFFF=0x47533737 && 0x34&0xFFDFDFDF=0x03434f6d" -j DROP -m comment --comment "DROP DNS Q stopdrugs77.com"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 66 --algo bm --hex-string '|0b73 746f706472756773373703636f6d00|' -j DROP -m comment --comment "DROP DNS Q stopdrugs77.com"

More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:

Unknown

Name server:



;; ANSWER SECTION:
stopdrugs77.com. 10800 IN NS a.dns.gandi.net.
stopdrugs77.com. 10800 IN NS b.dns.gandi.net.
stopdrugs77.com. 10800 IN NS c.dns.gandi.net.


Response:


A 239
NS 3
MX 2
SOA 1
Rsize 4027


Whois


Registrars.
Domain Name: stopdrugs77.com
Registry Domain ID: 1836814491_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.gandi.net
Registrar URL: http://www.gandi.net
Updated Date: 2013-11-25T21:14:22Z
Creation Date: 2013-11-25T20:17:27Z
Registrar Registration Expiration Date: 2014-11-25T19:17:26Z
Registrar: GANDI SAS
Registrar IANA ID: 81
Registrar Abuse Contact Email: abuse@support.gandi.net
Registrar Abuse Contact Phone: +33.170377661
Reseller:
Domain Status: clientTransferProhibited
Domain Status:
Domain Status:
Domain Status:
Domain Status:
Registry Registrant ID:
Registrant Name: Vasa Petrov
Registrant Organization:
Registrant Street: Gandi, 63-65 boulevard Massena
Registrant City: (Gandi) Paris
Registrant State/Province:
Registrant Postal Code: (Gandi) 75013
Registrant Country: (Gandi) FR
Registrant Phone: (Gandi) +33.170377666
Registrant Phone Ext:
Registrant Fax: (Gandi) +33.143730576
Registrant Fax Ext:
Registrant Email: 2d531f20f9ec1578c38b964aea7c748f-1815942@contact.gandi.net
Registry Admin ID:
Admin Name: Vasa Petrov
Admin Organization:
Admin Street: Gandi, 63-65 boulevard Massena
Admin City: (Gandi) Paris
Admin State/Province:
Admin Postal Code: (Gandi) 75013
Admin Country: (Gandi) FR
Admin Phone: (Gandi) +33.170377666
Admin Phone Ext:
Admin Fax: (Gandi) +33.143730576
Admin Fax Ext:
Admin Email: 2d531f20f9ec1578c38b964aea7c748f-1815942@contact.gandi.net
Registry Tech ID:
Tech Name: Vasa Petrov
Tech Organization:
Tech Street: Gandi, 63-65 boulevard Massena
Tech City: (Gandi) Paris
Tech State/Province:
Tech Postal Code: (Gandi) 75013
Tech Country: (Gandi) FR
Tech Phone: (Gandi) +33.170377666
Tech Phone Ext:
Tech Fax: (Gandi) +33.143730576
Tech Fax Ext:
Tech Email: 2d531f20f9ec1578c38b964aea7c748f-1815942@contact.gandi.net
Name Server: A.DNS.GANDI.NET
Name Server: B.DNS.GANDI.NET
Name Server: C.DNS.GANDI.NET
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
Name Server:
DNSSEC: Unsigned
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2013-11-27T13:08:25Z <<<

Reseller Email:
Reseller URL:


Thursday, October 17, 2013

Domain: pipcvsemnaher.com

Domain: pipcvsemnaher.com

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0d504950 && 0x2c&0xDFDFDFDF=0x43565345 && 0x30&0xDFDFDFDF=0x4d4e4148 && 0x34&0xDFDFFFDF=0x45520343 && 0x38&0xDFDFFF00=0x4f4d0000" -j DROP -m comment --comment "DROP DNS Q pipcvsemnaher.com"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 59 --algo bm --hex-string '|0D706970637673656d6e6168657203636f6d00|' -j DROP -m comment --comment "DROP DNS Q pipcvsemnaher.com"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


No IP source for this domain

Name server:


;; ANSWER SECTION:
pipcvsemnaher.com. 10800 IN NS a.dns.gandi.net.
pipcvsemnaher.com. 10800 IN NS c.dns.gandi.net.
pipcvsemnaher.com. 10800 IN NS b.dns.gandi.net.

;; ADDITIONAL SECTION:
a.dns.gandi.net. 86400 IN A 173.246.97.2
a.dns.gandi.net. 86400 IN AAAA 2604:3400:a::2
b.dns.gandi.net. 86400 IN A 217.70.184.40
b.dns.gandi.net. 86400 IN AAAA 2001:4b98:b:a::40
c.dns.gandi.net. 86400 IN A 217.70.182.20
c.dns.gandi.net. 86400 IN AAAA 2001:4b98:c:521::20


Response:


A 240
MX 2
NS 3
SOA 1
Rsize 4013


Whois



Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

Domain Name: PIPCVSEMNAHER.COM
Registrar: GANDI SAS
Whois Server: whois.gandi.net
Referral URL: http://www.gandi.net
Name Server: A.DNS.GANDI.NET
Name Server: B.DNS.GANDI.NET
Name Server: C.DNS.GANDI.NET
Status: clientTransferProhibited
Updated Date: 27-sep-2013
Creation Date: 27-sep-2013
Expiration Date: 27-sep-2014

>>> Last update of whois database: Thu, 17 Oct 2013 22:10:35 UTC <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar. Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.


The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.
--- #YAML:1.0
# GANDI Registrar whois database for .COM, .NET, .ORG., .INFO, .BIZ, .NAME
#

domain: pipcvsemnaher.com
reg_created: 2013-09-27 19:48:23
expires: 2014-09-27 19:48:23
created: 2013-09-27 21:48:23
changed: 2013-10-03 12:26:18
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
nic-hdl: DP4983-GANDI
organisation: ~
person: Denis Pulman
obfuscated: Obfuscated by Gandi
address: (Gandi) 63-65 boulevard Massena
zipcode: (Gandi) 75013
city: (Gandi) Paris
country: (Gandi) France
phone: (Gandi) +33.170377666
fax: (Gandi) +33.143730576
email: af703dda29383534e30a3133cc4c41cc-1785642@contact.gandi.net
lastupdated: 2013-09-27 17:57:31
admin-c:
nic-hdl: DP4983-GANDI
organisation: ~
person: Denis Pulman
obfuscated: Obfuscated by Gandi
address: (Gandi) 63-65 boulevard Massena
zipcode: (Gandi) 75013
city: (Gandi) Paris
country: (Gandi) France
phone: (Gandi) +33.170377666
fax: (Gandi) +33.143730576
email: af703dda29383534e30a3133cc4c41cc-1785642@contact.gandi.net
lastupdated: 2013-09-27 17:57:31
tech-c:
nic-hdl: DP4983-GANDI
organisation: ~
person: Denis Pulman
obfuscated: Obfuscated by Gandi
address: (Gandi) 63-65 boulevard Massena
zipcode: (Gandi) 75013
city: (Gandi) Paris
country: (Gandi) France
phone: (Gandi) +33.170377666
fax: (Gandi) +33.143730576
email: af703dda29383534e30a3133cc4c41cc-1785642@contact.gandi.net
lastupdated: 2013-09-27 17:57:31
bill-c:
nic-hdl: DP4983-GANDI
organisation: ~
person: Denis Pulman
obfuscated: Obfuscated by Gandi
address: (Gandi) 63-65 boulevard Massena
zipcode: (Gandi) 75013
city: (Gandi) Paris
country: (Gandi) France
phone: (Gandi) +33.170377666
fax: (Gandi) +33.143730576
email: af703dda29383534e30a3133cc4c41cc-1785642@contact.gandi.net
lastupdated: 2013-09-27 17:57:31



Friday, October 11, 2013

Domain: babywow.co.uk

Domain: babywow.co.uk

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x07424142 && 0x2c&0xDFDFDFDF=0x59574f57 && 0x30&0xFFDFDFFF=0x02434f02 && 0x34&0xDFDFFF00=0x554b0000" -j DROP -m comment --comment "DROP DNS Q babywow.co.uk"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 55 --algo bm --hex-string '|0762616279776f7702636f02756b00|' -j DROP -m comment --comment "DROP DNS Q babywow.co.uk"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


94.102.52.44 - Ecatel

Name server:


;; ANSWER SECTION:
babywow.co.uk. 10800 IN NS b.dns.gandi.net.
babywow.co.uk. 10800 IN NS a.dns.gandi.net.
babywow.co.uk. 10800 IN NS c.dns.gandi.net.

;; ADDITIONAL SECTION:
a.dns.gandi.net. 44411 IN A 173.246.97.2
a.dns.gandi.net. 44411 IN AAAA 2604:3400:a::2
b.dns.gandi.net. 44411 IN A 217.70.184.40
b.dns.gandi.net. 44411 IN AAAA 2001:4b98:b:a::40
c.dns.gandi.net. 44411 IN A 217.70.182.20
c.dns.gandi.net. 44411 IN AAAA 2001:4b98:c:521::20


Response:


A 243
NS 3
SOA 1
TXT 2
Rsize 4515


Whois



Domain name:
babywow.co.uk

Registrant:
Jesy Leu

Registrant type:
UK Individual

Registrant's address:
The registrant is a non-trading individual who has opted to have their
address omitted from the WHOIS service.

Registrar:
Gandi t/a Gandi [Tag = GANDI]
URL: http://www.gandi.net

Relevant dates:
Registered on: 07-Oct-2013
Expiry date: 07-Oct-2014
Last updated: 07-Oct-2013

Registration status:
Registered until expiry date.

Name servers:
a.dns.gandi.net
b.dns.gandi.net
c.dns.gandi.net

WHOIS lookup made at 22:35:53 11-Oct-2013

--
This WHOIS information is provided for free by Nominet UK the central registry
for .uk domain names. This information and the .uk WHOIS are:

Copyright Nominet UK 1996 - 2013.

You may not access the .uk WHOIS or use any data from it except as permitted
by the terms of use available in full at http://www.nominet.org.uk/whoisterms, which
includes restrictions on: (A) use of the data for advertising, or its
repackaging, recompilation, redistribution or reuse (B) obscuring, removing
or hiding any or all of this notice and (C) exceeding query rate or volume
limits. The data is provided on an 'as-is' basis and may lag behind the
register. Access may be withdrawn or restricted at any time.



Wednesday, October 2, 2013

Domain: irlwinning.com

Scan and attacks for: irlwinning.com (In Real Life Winning .com) funny guy. He's probably 16.

Source IP seems to be a busy beaver.

IPtables:

There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0a49524c && 0x2c&0xDFDFDFDF=0x57494e4e && 0x30&0xDFDFDFFF=0x494e4703 && 0x34&0xDFDFDFFF=0x434f4d00" -j DROP -m comment --comment "DROP DNS Q irlwinning.com"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt


String:

iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 56 --algo bm --hex-string '|0A69726c77696e6e696e6703636f6d00|' -j DROP -m comment --comment "DROP DNS Q irlwinning.com"

More Iptables rules for the STRING module can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:

80.82.65.204 - Ecatel

   2052 hizbullah.me
    431 bitstress.com
     80 8js44.xplodin.com
     59 hak4umz.net
      3 xplodin.com
      2 srvit.org
      1 directedat.asia
      1 anonsc.com

89.248.168.136 -  Ecatel

      4 theswat.net
      1 hizbullah.me

Name server:


irlwinning.com.         21600   IN      NS      ns1.irlwinning.com.
irlwinning.com.         21600   IN      NS      ns2.irlwinning.com.

;; ADDITIONAL SECTION:
ns2.irlwinning.com.     21600   IN      A       69.42.219.74
ns1.irlwinning.com.     21600   IN      A       69.42.219.74


Response:


243 A records in the 1.1.1.226

Whois


Domain irlwinning.com

Date Registered: 2013-10-1
Expiry Date: 2014-10-1

DNS1: ns1.irlwinning.com
DNS2: ns2.irlwinning.com

Registrant
    Fundacion Private Whois
    Domain Administrator
    Email:524b08137qidwx4b@5225b4d0pi3627q9.privatewhois.net
    Attn: irlwinning.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Administrative Contact
    Fundacion Private Whois
    Domain Administrator
    Email:524b0813sfmrmn27@5225b4d0pi3627q9.privatewhois.net
    Attn: irlwinning.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Technical Contact
    Fundacion Private Whois
    Domain Administrator
    Email:524b081301e20o65@5225b4d0pi3627q9.privatewhois.net
    Attn: irlwinning.com
    Aptds. 0850-00056
    Zona 15 Panama
    Panama
    Tel: +507.65995877

Registrar: Internet.bs Corp.
Registrar's Website : <a href='http://www.internetbs.net/'>http://www.internetbs.net/</a>







Tuesday, October 1, 2013

Domain: pkts.asia

Thanks Allan for the tip. Also observed a discovery from:


IPtables:

There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x04504b54 && 0x2c&0xDFFFDFDF=0x53044153 && 0x30&0xDFDFFFFF=0x49410000" -j DROP -m comment --comment "DROP DNS Q pkts.asia"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt


String:

iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 51 --algo bm --hex-string '|04706b7473046173696100|' -j DROP -m comment --comment "DROP DNS Q pkts.asia"

More Iptables rules for the STRING module can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


89.248.168.136 - Ecatel

Seen this ip before:

TheSwat.net
Hizbullah.met

Name server:


pkts.asia.              14676   IN      NS      ns1.pkts.asia.
pkts.asia.              14676   IN      NS      ns2.pkts.asia.

;; ADDITIONAL SECTION:
ns1.pkts.asia.          14676   IN      A       69.42.219.74
ns2.pkts.asia.          14676   IN      A       69.42.219.74

Response:


245 A records in the 1.1.1.x range

Whois


Domain ID:D2806247-ASIA
Domain Name:PKTS.ASIA
Domain Create Date:01-Oct-2013 03:22:21 UTC
Domain Expiration Date:01-Oct-2014 03:22:21 UTC
Domain Last Updated Date:01-Oct-2013 19:54:25 UTC
Last Transferred Date:
Created by:Internet.bs Corp. R176-ASIA (814)
Last Updated by Registrar:Internet.bs Corp. R176-ASIA (814)
Sponsoring Registrar:Internet.bs Corp. R176-ASIA (814)
Domain Status:CLIENT TRANSFER PROHIBITED
Domain Status:TRANSFER PROHIBITED
Status:ADDPERIOD
Registrant ID:INTEj09wxvky9cwv
Registrant Name:Domain Administrator
Registrant Organization:Fundacion Private Whois
Registrant Address:Attn: pkts.asia
Registrant Address2:Aptds. 0850-00056
Registrant Address3:
Registrant City:Panama
Registrant State/Province:
Registrant Country/Economy:PA
Registrant Postal Code:Zona 15
Registrant Phone:+507.65995877
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant E-mail:524a3fe3bbnpgi8d@5225b4d0pi3627q9.privatewhois.net
Administrative ID:INTEord72uqcb16n
Administrative Name:Domain Administrator
Administrative Organization:Fundacion Private Whois
Administrative Address:Attn: pkts.asia
Administrative Address2:Aptds. 0850-00056
Administrative Address3:
Administrative City:Panama
Administrative State/Province:
Administrative Country/Economy:PA
Administrative Postal Code:Zona 15
Administrative Phone:+507.65995877
Administrative Phone Ext.:
Administrative FAX:
Administrative FAX Ext.:
Administrative E-mail:524a3fe5and4zbsf@5225b4d0pi3627q9.privatewhois.net
Technical ID:INTEzihq17tjuf2q
Technical Name:Domain Administrator
Technical Organization:Fundacion Private Whois
Technical Address:Attn: pkts.asia
Technical Address2:Aptds. 0850-00056
Technical Address3:
Technical City:Panama
Technical State/Province:
Technical Country/Economy:PA
Technical Postal Code:Zona 15
Technical Phone:+507.65995877
Technical Phone Ext.:
Technical FAX:
Technical FAX Ext.:
Technical E-mail:524a3fe5ilbgz7g6@5225b4d0pi3627q9.privatewhois.net
Billing ID:INTElq2psm15rdqt
Billing Name:Domain Administrator
Billing Organization:Fundacion Private Whois
Billing Address:Attn: pkts.asia
Billing Address2:Aptds. 0850-00056
Billing Address3:
Billing City:Panama
Billing State/Province:
Billing Country/Economy:PA
Billing Postal Code:Zona 15
Billing Phone:+507.65995877
Billing Phone Ext.:
Billing FAX:
Billing FAX Ext.:
Billing E-mail:524a3fe7w1y9heh2@5225b4d0pi3627q9.privatewhois.net
CED ID:INTEj09wxvky9cwv
CED CC Locality:AM
CED Type of Legal Entity:Natural Persons
CED Form of Identification:Passport or Citizenship ID
Operations and Notifications ID:INTEj09wxvky9cwv
Operations and Notifications Name:Domain Administrator
Operations and Notifications Organization:Fundacion Private Whois
Operations and Notifications Address:Attn: pkts.asia
Operations and Notifications Address2:Aptds. 0850-00056
Operations and Notifications Address3:
Operations and Notifications City:Panama
Operations and Notifications State/Province:
Operations and Notifications Country/Economy:PA
Operations and Notifications Postal Code:Zona 15
Operations and Notifications Phone:+507.65995877
Operations and Notifications Phone Ext.:
Operations and Notifications FAX:
Operations and Notifications FAX Ext.:
Operations and Notifications E-mail:524a3fe3bbnpgi8d@5225b4d0pi3627q9.privatewhois.net
Nameservers:NS1.PKTS.ASIA
Nameservers:NS2.PKTS.ASIA





Monday, September 30, 2013

domain: zaikapaika.com

Seen a scan for this domain on 30-09-2013.

IPtables:


iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0a5a4149 && 0x2c&0xDFDFDFDF=0x4b415041 && 0x30&0xDFDFDFFF=0x494b4103 && 0x34&0xDFDFDFFF=0x434f4d00" -j DROP -m comment --comment "DROP DNS Q zaikapaika.com"

Source:


89.248.174.54 - Ecatel (everytime)

Also seen this IP for:

 kiddy3233655.ru

Name server:


zaikapaika.com.         10800   IN      NS      b.dns.gandi.net.
zaikapaika.com.         10800   IN      NS      a.dns.gandi.net.
zaikapaika.com.         10800   IN      NS      c.dns.gandi.net.

;; ADDITIONAL SECTION:
c.dns.gandi.net.        85933   IN      AAAA    2001:4b98:c:521::20
b.dns.gandi.net.        85933   IN      AAAA    2001:4b98:b:a::40
a.dns.gandi.net.        85933   IN      AAAA    2604:3400:a::2
a.dns.gandi.net.        85933   IN      A       173.246.97.2
b.dns.gandi.net.        85933   IN      A       217.70.184.40
c.dns.gandi.net.        85933   IN      A       217.70.182.20


Response:


241 A records in the 204.46.43.x range.

Whois

domain: zaikapaika.com
reg_created: 2013-09-23 08:41:35
expires: 2014-09-23 08:41:35
created: 2013-09-23 10:41:36
changed: 2013-09-26 22:32:45
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18
admin-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18
tech-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18
bill-c:
  nic-hdl: VV1405-GANDI
  organisation: ~
  person: Vyacheslav Volkov
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 5e2223699a84baf9c6365442bfa79494-1782482@contact.gandi.net
  lastupdated: 2013-09-20 18:00:18

Saturday, September 28, 2013

Domain: Sandia.gov

Some attacks are using this legit domain with ANY queries.
Seeing as ANY queries are not really used in a legit manner I have no problem dropping these.. like its hot.

IPtables:


iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0653414e && 0x2c&0xDFDFDFFF=0x44494103 && 0x30&0xDFDFDFFF=0x474f5600 && 0x34&0xFFFFFFFF=0x00ff0001" -j DROP -m comment --comment "DROP DNS Q ANY sandia.gov"


More rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

Source:


First scan I observed for Sandia.gov came from sweden:

First:

94.185.81.128 - Netrouting

Later on:
89.248.172.121 - Ecatel
-hackwhatlol.cc
-edelion.su
-2soe.ru

Name server:


sandia.gov. 3600 IN NS ns8.sandia.gov.
sandia.gov. 3600 IN NS ns2.ca.sandia.gov.
sandia.gov. 3600 IN NS ns9.sandia.gov.
sandia.gov. 3600 IN NS ns1.ca.sandia.gov.

;; ADDITIONAL SECTION:
ns1.ca.sandia.gov. 3600 IN A 198.206.219.65
ns9.sandia.gov. 3600 IN A 132.175.7.210
ns2.ca.sandia.gov. 3600 IN A 198.206.219.66
ns8.sandia.gov. 3600 IN A 132.175.7.209

Response:


Just massive!

;; ANSWER SECTION:
Sandia.gov. 3600 IN SOA taurus.Sandia.gov. dnsadmin.Sandia.gov. 448880 1800 900 604800 3600
Sandia.gov. 0 IN RRSIG NSEC3PARAM 7 2 0 20131009150422 20130909150422 30602 sandia.gov. lqLdGBXNggppzQAHk0F3LsG70+AMHJVEgOj0+tYV7i7F3EguhK1K/wWg NmMmm2s2yhuOQDHOvKc3RXoVLbumXqIuu9cr/Mqbnx06dsTrlbmfoSNM Lc9+Lye/hf57u2etlsLt2krwAvSliOcIARg5CxyRj1ckbRoBvoMpsFt4 SkiHJlpw2/YpAb30MsPz0HHNwL4kwidv3HS+kR6RlSy0bBpPIrQBit7A 1OwxaWnzpB645EJjVAB5CBi7edGFQL9dyOh8PTWKAC4dOxo6MObukIDX 81sd1DeVj/aTvaZzK/ImXlZnraw1qwO9B90caQG6+lPKmXVJQK8pxQvQ 9Dz2gg==
Sandia.gov. 0 IN NSEC3PARAM 1 0 2 8BEC6F
Sandia.gov. 3600 IN RRSIG DNSKEY 7 2 3600 20131009150422 20130909150422 20739 sandia.gov. UIKkraXl1rSrpCORN6+0XFjNQFeJXBSiF9UT/nPabh3g+BGaBcZqpIjW NloD2cgW+Q43VsRlSwoiDYzB9OafzYknVxhI2WaG9aNrrtoCuCl+Bz7r auHhmN/HQq7VVSPp0YOL4Tw2RasvbLmNT/mKAEFGPmHm5dVWtmR/aiJj Fx4vUFCoquG1FUYdE8cwhOutIfhNulzCm41HsRoleKLy3yzwqZCtMoeg ow8g+HBSEt3j1ZrFyIg1WjOuPi2Il66EIz7yCBi3PKLKMJYd9DNpU+BR xx9viNX+jI05w7Ds96AO6zVyE1wRxj3twPOTTuVFvWeRVWFpxzUv9iR9 1z75EQ==
Sandia.gov. 3600 IN RRSIG DNSKEY 7 2 3600 20131009150422 20130909150422 30602 sandia.gov. nFKdZ1BJAqsOt2M8J50nFjRwrMs3Om0x2LHx/bW8PgE5i4r/OE8yl5Or qBS34MpNSJG9y059OALcSVWv/Y7yzEhnFuAJw1JM0gbXjTDWAvdOJToI 7B0lQ2rZU+REvZzgp6FVcEzH1MgoR/LRqlxaP/93/CSvOBEsQfnTcH/+ YdD4TYw02jHYSFYCGbvDSn+Z6RmvvLdlcSn9FyMDes8uDshW+niPGEr2 iET5UHnn7TMFk/nnj8f8esP7Rgc5PDMbSFj4w3AkCyWT7K5dqk5IwpfL coKMAf+2i4/PmaPHQySBie0JirKGufuTpIllKEVXMOdu/nGQjSdCXd8B UaHFVg==
Sandia.gov. 3600 IN RRSIG DNSKEY 7 2 3600 20131009150422 20130909150422 36033 sandia.gov. bOwF9y4fTZvEeWwJYEQfwpkzAaQz1jjuP/vrcODtNWIZjPCH2r+KAq9P NIyRMlPxveybfJPqVT0xhDL97stjhUldzXH3hgFnra/OnhSC/4xH5ipR +ExCuuL6vsJHiORpIMXKZ2IqDdbIqYCiy2pOdYlFXDliI264AF/kp1V9 5zwuz2ohKIjtEU9eeZdgdynFlpFNt7Cl0HrdlOBsOLZAQdT6Tfvrh73T zuW3kkYXUiDo4z1FE8SwcMoSULyP8YBU10Es1JBBQNIVcv3artgzz4q1 L2ZqpTuvZ+bwZUfY93QYHTnEvjCo14psTAK3lAhEoU62CKPPxhmmsToR kFuwSg==
Sandia.gov. 3600 IN DNSKEY 256 3 7 AwEAAZ0oH+W7xJXP7f/O7J25tQQEG9xqj6LecK9pESLccr0MwEO+Xha9 4qMClFvQ8uCjogyPuFizBNk0s0WjOa+XyBVzhZg2djpqARmq8VmPMXEx GpkDgkP1ukdoTESrc1XC+Sbi0uE8tRGmu+eus4n3Yk/+tS9L3ka3daOZ CJuaCV0Om9XTnDP+m8ElUdHju0RUFN63hKdx++/7PNzTw6prj2ddeKW6 Zao3naBvYsGbfzKpAd1d7NDK29QYh+MFUe1s3ccBhTmgvCiRjsl1LAAQ jaZ9KZYOPT0JJZQ9Qtlxmj6enQtdIPOYzyjALkIv193dXlE+G0S5Arr9 fjMaf7lEyNc=
Sandia.gov. 3600 IN DNSKEY 256 3 7 AwEAAfaaLgwMLLou2EXeq0lw3dHUos46XgWEGczA2xz1r2RttO8ATyrR gx4rW+MaIyLLO5es0Et8Fum5qRHa9uwAqkrF5mNC2o05HyA4lv8zr9Px Q6xWDBlvkQMSBVmfgyMT0hLBt4wwrKycYsDEpxJFuQcZih8lZaInSRG2 RNZL7ThwycRawvgKMDWO59giOcU51AWAks8BQN5z/33jvFgbPwYJObV1 CytBZlyDdLlCryOn+xRKZKtF6TTCzOfvlquKcEeqzfhGNn5nUquZWAay klBDYM6NnSjmui2482/KRImoygE8DayJ9aN9BIH5v+ehdegWsRtX/U8m HIA4/E/2//U=
Sandia.gov. 3600 IN DNSKEY 257 3 7 AwEAAb80HHQXbrsrmm8L5T1V3QDoXEEDJpts4S6ttkFVOa+fb4anMU3B 7KNK4jgg8sDXMhDfgTWHOc9EEAuy3Obv/6ArD4+385P+EuH5NGLd5f/l Wl8GC9S24mDTpe2sNKi4AHJQxnREuI8Oxr/Mh92W5+HWDdIBt5IKH/nu 9Wlf76Yg3x8jHZYgxVBMgPGF+UYUMQLKAjtJ/XFRObLLL+RQNdNkBqrQ LDkPBxbG1m8rDNa+uCbBiOWGBjZxrjEyQCA/2ZAKQ9lhVFZWuxb8DA3m eiu8sfhWb3tbuZHhCb2HniV43oPKICN4GdIDrHQkZCUOzEMKLSyX98VW QoHdaaOT1is=
Sandia.gov. 3600 IN DNSKEY 257 3 7 AwEAAeWCWZhMfUwZSU+3Sqqk3OvDCDPw9sBWL7HioNjo8FI90QdbNYRh 6z9Ks2fEoguMRHlTobVbptJ2wlRQPWTyC8qlaWnT82hdj5tpOzNlfuWy wRu7Yw+DOBJUT1d1ygwGVl9YbNl2gw4JCbVjqyZl2SogXAXWJecQKrJZ gToYW/hkoTUWEnW80j60wwXyeBR6TExVNTsuimV4vNas1nDqKd3jf8fS pszH5CFR/Ytw29f4qaZRxGfgtQf05AwMLrKNfiHXjRnhQ/Wc4irjW4o6 J07xJumdVm2edvevOwPc5HvoTcHKueBn+8cyq7FDc0pwutB190FV8WU6 XTTQMJQpOAE=
Sandia.gov. 3600 IN RRSIG TXT 7 2 3600 20131009150422 20130909150422 30602 sandia.gov. 5qOYnmGkx1fdXmDe5gtUNeFFqEJFcQ9EFxQ4Txl1ptaDHQasmN1FZBvP YKR1bZB6hPTfxDnUZt8vNwuMNOquoRYRjUOerfs6l6BrrY5K/9ax9w3I 5v9TwsfSf9CtQBRJPg+Rlmu5hHk1CqtR3D9SmDiTyTxmItOW24uoPz3f ZW5d652/laiIU8i1YKSVlOdUXzyuyBRfCyjH4K83h/dsne5tKM8qtKAK g+5zPJq1F48jfROwO8JFtxDSB7jya1Kdg5vGPSJqFsWKGGkDoz52Axen d4qPLcb2bOSo2JGRBcGuPj8glSMzWAInD5Jswmsc1cqrPZoN9MxXNrq+ Afa+SQ==
Sandia.gov. 3600 IN TXT "v=spf1 mx ip4:132.175.109.20 ip4:132.175.109.21  ip4:132.175.109.1  ip4:132.175.109.4 ~all"
Sandia.gov. 1200 IN RRSIG MX 7 2 1200 20131009150422 20130909150422 30602 sandia.gov. 6VIvlQ0KK1YsBmArv9XcVNbhRygoMRxyi1iNEWZ1Unv3UF46tMu/oW/r hxkOpZvnAhf4hQvXh21Mkd2m4N+MLo9iYV8E+Abwy+ppDg2AbFqmk6jh GFwdq2Ea3Lm3cRU4es0paBNmyJjl5TMV9LVcyBjJps9xA157p0qBJThW EqRadUpk/e0AJydsIjTC5v1iss5QjuTmZW8TmSIWRvHa1WHi0W3VWRiA Q3REr+t45ADgvRHOUFf4fxvwjx7/7rXrQNlUpoMJDzZhNb2in2m3p1Yo BezZH5pGsj0bwVSlaBvAmxUGUIsydrTppGF20TgwwyDxx98/YJbwYZLN 8wV82g==
Sandia.gov. 1200 IN MX 10 sentry-three.Sandia.gov.
Sandia.gov. 1200 IN MX 30 hubble.ca.Sandia.gov.
Sandia.gov. 1200 IN MX 10 sentry-two.Sandia.gov.
Sandia.gov. 3600 IN RRSIG A 7 2 3600 20131009150422 20130909150422 30602 sandia.gov. psOBfXIvGsNDNeSJQyGvRdo33ewhWmMrUxazO8n2/elAuyv9o58/TXKO O+D2NtjuqFcBg22oYm2Yj0zEBWmYl7QsjH5Ys1HJT3kfQUex9NeS9yvF iUA5mNeP9iynByZYDW5ySkunOgrpVz4T6VafEfZKrckj41Q4dVa71h8h ksSVRmhSE5WWM9qcs/emrssdSqLz9ea/UrylzZVtdrUxbDe7wYZ1SRli I5FKv8KLHY/XyY8mYRWD8dKx7VAdyOP3P2y5J12V5ueZkLYBuYKqFXdI Z2ZAG3X6pA1fEEkIRO1oAufMNtVkzQflgOVopuJVTwNd8IPgjqtpNSwZ 2JXNDg==
Sandia.gov. 3600 IN A 132.175.81.4
Sandia.gov. 3600 IN RRSIG NS 7 2 3600 20131009150422 20130909150422 30602 sandia.gov. 00A++N5y/op/NXmIeV3MSVKn+qOtpWkrGXxX+Z1xn/n+VXRiLsC0hSO2 AKf+WsdlQ8mfs3k91ez2ecYg/MTwjGkwy4ZGieuG4t7yLxKBC3yc9cXm 7VYKpFEvDZAJo/5pk8BjN2y8dzZ78vB1xt+vkBdpgFZe8L1SRCOLVtKz HuAIsG9g3WU1S6VIKog9kOECnSaQ5iTfKSbc7SgqY+1Qfk66DSpulELL 8TL8vlW8THgwqYLbJ/mgOvQ+6MmTzKR5ydeDc4/8W0SkQzQe6TYVFNLo sa4KLJxPKoCZ2eiulrvh2HD+usrLTMRs10jMCyORQAwgdRn3a8bjrMa4 11x+sQ==
Sandia.gov. 3600 IN NS ns1.ca.Sandia.gov.
Sandia.gov. 3600 IN NS ns2.ca.Sandia.gov.
Sandia.gov. 3600 IN NS ns9.Sandia.gov.
Sandia.gov. 3600 IN NS ns8.Sandia.gov.
Sandia.gov. 3600 IN RRSIG SOA 7 2 3600 20131027181002 20130927171002 30602 sandia.gov. OkmrnYqJU9TMCebksFWYaCPkd2UGZNL/z7rVm2YkbyBk+HpTZvQbF8DA lPUZFTLycHEjaGxlR7Gd/W2cYnkuIol9X7zq+/+KSd13CTLJBS2kbneZ vV98yzzNDNH56BoIEG6A8xTyaZ4sSyiO5rm2aJxoMpvypF9niKjIPcmn 74vsBRsTbWMxsAj4cwhz8K9T3EhzuD1DlS4TPivsWMyS7nWCVHQEK+0R fBNfWWbLRTREpGBF0FFSLewztbIhmCtHKhoWvreWoylfMiDXaEooImjx sVswO6AEO4nqjK7qGEak2P8nBzLpIzSnqgln2Bk/5/qfmfIkSmKz+4wo XVTYAg==

Whois


% DOTGOV WHOIS Server ready
   Domain Name: SANDIA.GOV
   Status: ACTIVE




Domain: 4fwhk.com

Received a few tips for this domain: 4fwhk.com that is related to mmtac1.com.

IPtables:


iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFFFDFDF=0x05344657 && 0x2c&0xDFDFFFDF=0x484b0343 && 0x30&0xDFDFFFFF=0x4f4d0000" -j DROP -m comment --comment "DROP DNS Q 4fwhk.com"


More rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

Source:


Unknown


Name server:


4fwhk.com. 7200 IN NS ns3.mmtac1.com.
4fwhk.com. 7200 IN NS ns2.mmtac1.com.
4fwhk.com. 7200 IN NS ns1.mmtac1.com.
4fwhk.com. 7200 IN NS ns4.mmtac1.com.


Name servers 1-4 point to:

222.163.192.106
222.163.192.104


The name server domain looked familiar:

http://dnsamplificationattacks.blogspot.com/2013/09/domain-aammtac1com.html

Response:


257 records in the 121.122.157.x range

Whois


Domain: 4fwhk.com
Status: Protected

DNS:
        ns1.mmtac1.com
        ns2.mmtac1.com

Created: 2013-09-14 16:33:56
Expires: 2014-09-14 08:33:56
Last Modified: 2013-09-14 16:33:54

Registrant Contact:
        Hong Yuan
        yuan hong (asdf@gmail.com)
        No.236, Jingai Road
        Huaihu, Hunan, cn 418000
        P: +745.2714381 F: +0.0

Administrative Contact:
        Hong Yuan
        yuan hong (asdf@gmail.com)
        No.236, Jingai Road
        Huaihu, Hunan, cn 418000
        P: +745.2714381 F: +0.0

Technical Contact:
        Hong Yuan
        yuan hong (asdf@gmail.com)
        No.236, Jingai Road
        Huaihu, Hunan, cn 418000
        P: +745.2714381 F: +0.0

Billing Contact:
        Hong Yuan
        yuan hong (asdf@gmail.com)
        No.236, Jingai Road
        Huaihu, Hunan, cn 418000
        P: +745.2714381 F: +0.0


Domain: cmiui.com

Seen a scan for this domain yesterday. Query was for TXT


IPtables:


iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x05434d49 && 0x2c&0xDFDFFFDF=0x55490343 && 0x30&0xDFDFFFFF=0x4f4d0000" -j DROP -m comment --comment "DROP DNS Q cmiui.com"

Source:


96.46.2.82 - AS19853 USONL-2 - US Online Sales, Inc.

Also seen this IP for:

16-Aug-2013 - bfhmm.com in TXT
19-Aug-2013 - bfhmm.com in AAAA

Name server:


cmiui.com. 1334 IN NS pdns03.domaincontrol.com.
cmiui.com. 1334 IN NS pdns04.domaincontrol.com.


Response:


TXT "\"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\""

Whois


Registrars.
Domain Name: CMIUI.COM
Registrar URL: http://www.godaddy.com
Updated Date: 2013-09-24 23:55:27
Creation Date: 2013-09-23 13:19:22
Registrar Expiration Date: 2014-09-23 13:19:22
Registrar: GoDaddy.com, LLC
Registrant Name: Peter Wang
Registrant Organization:
Registrant Street: No.10 Nanjing Rd, Huangpu DIST
Registrant City: Shanghai
Registrant State/Province: Shanghai
Registrant Postal Code: 200010
Registrant Country: China
Admin Name: Peter Wang
Admin Organization:
Admin Street: No.10 Nanjing Rd, Huangpu DIST
Admin City: Shanghai
Admin State/Province: Shanghai
Admin Postal Code: 200010
Admin Country: China
Admin Phone: +0.862065739586
Admin Fax:
Admin Email: jjhenteng@gmail.com
Tech Name: Peter Wang
Tech Organization:
Tech Street: No.10 Nanjing Rd, Huangpu DIST
Tech City: Shanghai
Tech State/Province: Shanghai
Tech Postal Code: 200010
Tech Country: China
Tech Phone: +0.862065739586
Tech Fax:
Tech Email: jjhenteng@gmail.com
Name Server: PDNS03.DOMAINCONTROL.COM
Name Server: PDNS04.DOMAINCONTROL.COM

Tuesday, September 24, 2013

Domain: grappyblog.com

Received a tip!

Source:

Not observed myself.

Response:

About 255 A records in the 204.46.43.x range.


IPtables rule:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0a475241 && 0x2c&0xDFDFDFDF=0x50505942 && 0x30&0xDFDFDFFF=0x4c4f4703 && 0x34&0xDFDFDFFF=0x434f4d00" -j DROP -m comment --comment "DROP DNS Q grappyblog.com"

More rules here

Name servers:

grappyblog.com.         10720   IN      NS      a.dns.gandi.net.
grappyblog.com.         10720   IN      NS      c.dns.gandi.net.
grappyblog.com.         10720   IN      NS      b.dns.gandi.net.

;; ADDITIONAL SECTION:
b.dns.gandi.net.        86164   IN      A       217.70.184.40
c.dns.gandi.net.        86164   IN      A       217.70.182.20
c.dns.gandi.net.        86164   IN      AAAA    2001:4b98:c:521::20
a.dns.gandi.net.        86164   IN      AAAA    2604:3400:a::2
b.dns.gandi.net.        86164   IN      AAAA    2001:4b98:b:a::40
a.dns.gandi.net.        86164   IN      A       173.246.97.2

Whois:

domain: grappyblog.com
reg_created: 2013-06-13 09:30:21
expires: 2014-06-13 09:30:21
created: 2013-06-13 11:30:23
changed: 2013-09-22 14:52:54
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
  nic-hdl: CKV4-GANDI
  organisation: ~
  person: charlotte karila vaillant
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 7cbec7cb44a69cc598cc257f51c3604e-1728756@contact.gandi.net
  lastupdated: 2013-06-04 20:18:53
admin-c:
  nic-hdl: CKV4-GANDI
  organisation: ~
  person: charlotte karila vaillant
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 7cbec7cb44a69cc598cc257f51c3604e-1728756@contact.gandi.net
  lastupdated: 2013-06-04 20:18:53
tech-c:
  nic-hdl: CKV4-GANDI
  organisation: ~
  person: charlotte karila vaillant
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 7cbec7cb44a69cc598cc257f51c3604e-1728756@contact.gandi.net
  lastupdated: 2013-06-04 20:18:53
bill-c:
  nic-hdl: CKV4-GANDI
  organisation: ~
  person: charlotte karila vaillant
  obfuscated: Obfuscated by Gandi
  address: (Gandi) 63-65 boulevard Massena
  zipcode: (Gandi) 75013
  city: (Gandi) Paris
  country: (Gandi) France
  phone: (Gandi) +33.170377666
  fax: (Gandi) +33.143730576
  email: 7cbec7cb44a69cc598cc257f51c3604e-1728756@contact.gandi.net
  lastupdated: 2013-06-04 20:18:53

Monday, September 23, 2013

Domain: fkfkfkfa.com

Received a Tip for this domain

Source:

--

Response:

About 255 A records in the 204.46.43.x range.

IPtables rule:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x08464b46 && 0x2c&0xDFDFDFDF=0x4b464b46 && 0x30&0xDFFFDFDF=0x4103434f" -j DROP -m comment --comment "DROP DNS Q fkfkfkfa.com"

More rules here

Name servers:

fkfkfkfa.com.           86400   IN      NS      ns2.fkfkfkfa.com.
fkfkfkfa.com.           86400   IN      NS      ns1.fkfkfkfa.com.

;; ADDITIONAL SECTION:
ns1.fkfkfkfa.com.       86400   IN      A       94.102.56.154
ns2.fkfkfkfa.com.       86400   IN      A       94.102.56.154

Whois:


http://www.networksolutions.com

Visit AboutUs.org for more information about FKFKFKFA.COM
<a href="http://www.aboutus.org/FKFKFKFA.COM">AboutUs: FKFKFKFA.COM </a>




Registrant:
Rattani, Altaf
   ATTN FKFKFKFA.COM
   care of Network Solutions
   PO Box 459
   Drums, PA.  US  18222


   Domain Name: FKFKFKFA.COM

   ------------------------------------------------------------------------
   Promote your business to millions of viewers for only $1 a month
   Learn how you can get an Enhanced Business Listing here for your domain name.
   Learn more at http://www.NetworkSolutions.com/
   ------------------------------------------------------------------------

   Administrative Contact, Technical Contact:
      Rattani, Altaf            nr25b87p72b@networksolutionsprivateregistration.com
      ATTN FKFKFKFA.COM
      care of Network Solutions
      PO Box 459
      Drums, PA 18222
      US
      570-708-8780


   Record expires on 22-Sep-2014.
   Record created on 22-Sep-2013.
   Database last updated on 23-Sep-2013 17:13:08 EDT.

   Domain servers in listed order:

   NS1.FKFKFKFA.COM             94.102.56.154
   NS2.FKFKFKFA.COM             94.102.56.153

This listing is a Network Solutions Private Registration. Mail
correspondence to this address must be sent via USPS Express Mail(TM) or
USPS Certified Mail(R); all other mail will not be processed. Be sure to
include the registrant's domain name in the address.


Domain: aa3247.com

Just observed this a scan for this domain. No attacks just yet. 

Source:

122.136.196.116 - AS4837 CHINA169-BACKBONE CNCGROUP

Response:

About 255 A records in the 182.156.202.x range.

IPtables rule:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFFF=0x06414133 && 0x2c&0xFFFFFFFF=0x32343703 && 0x30&0xDFDFDFFF=0x434f4d00" -j DROP -m comment --comment "DROP DNS Q aa3247.com"

More rules here

Name servers:

aa3247.com.             7200    IN      NS      ns3.mmtac1.com.
aa3247.com.             7200    IN      NS      ns4.mmtac1.com.
aa3247.com.             7200    IN      NS      ns1.mmtac1.com.
aa3247.com.             7200    IN      NS      ns2.mmtac1.com.

;; ADDITIONAL SECTION:
ns3.mmtac1.com.         300     IN      A       222.163.192.106
ns2.mmtac1.com.         86400   IN      A       162.212.182.165
ns2.mmtac1.com.         86400   IN      A       162.212.182.66
ns2.mmtac1.com.         86400   IN      A       64.62.186.91
ns2.mmtac1.com.         86400   IN      A       222.163.192.106
ns1.mmtac1.com.         300     IN      A       222.163.192.106
ns1.mmtac1.com.         300     IN      A       222.163.192.104
ns4.mmtac1.com.         300     IN      A       222.163.192.106
ns4.mmtac1.com.         300     IN      A       222.163.192.104
ns3.mmtac1.com.         300     IN      A       222.163.192.104
ns2.mmtac1.com.         86400   IN      A       64.62.186.74
ns2.mmtac1.com.         86400   IN      A       222.163.192.104
ns2.mmtac1.com.         86400   IN      A       64.62.186.77

Whois:


Domain: aa3247.com
Status: Protected

DNS:
        ns1.mmtac1.com
        ns2.mmtac1.com

Created: 2013-09-14 16:33:55
Expires: 2014-09-14 08:33:55
Last Modified: 2013-09-14 16:33:54

Registrant Contact:
        Whoisprotection.cc
        Domain Admin  (reg_1358531@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0

Administrative Contact:
        Whoisprotection.cc
        Domain Admin  (adm_1358531@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0

Technical Contact:
        Whoisprotection.cc
        Domain Admin  (tec_1358531@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0

Billing Contact:
        Whoisprotection.cc
        Domain Admin  (bil_1358531@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0

Domain: d6991.com

From 3 or 4 sources I received tips about this domain. Funny enough, I haven't seen this domain at all!

Thanks for all the tips, warm feeling :)

Well here it goes!

Source:

Not observed myself.


Response:

About 255 A records in the 121.100.152.x range.


IPtables rule:

iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFFFFF=0x05443639 && 0x2c&0xFFFFFFDF=0x39310343 && 0x30&0xDFDFFFFF=0x4f4d0000" -j DROP -m comment --comment "DROP DNS Q d6991.com"

More rules here

Name servers:

d6991.com.              4354    IN      NS      ns2.mmtac1.com.
d6991.com.              4354    IN      NS      ns1.mmtac1.com.
d6991.com.              4354    IN      NS      ns3.mmtac1.com.
d6991.com.              4354    IN      NS      ns4.mmtac1.com.


Whois:


Domain: d6991.com
Status: Protected

DNS:
        ns1.mmtac1.com
        ns2.mmtac1.com

Created: 2013-09-14 16:33:56
Expires: 2014-09-14 08:33:55
Last Modified: 2013-09-14 16:33:54

Registrant Contact:
        Whoisprotection.cc
        Domain Admin  (reg_1358532@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0

Administrative Contact:
        Whoisprotection.cc
        Domain Admin  (adm_1358532@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0

Technical Contact:
        Whoisprotection.cc
        Domain Admin  (tec_1358532@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0

Billing Contact:
        Whoisprotection.cc
        Domain Admin  (bil_1358532@whoisprotection.cc)
        Lot 2-1, Incubator 1, Technology Park Malaysia, Bukit Jalil
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 57000
        P: +603.89966788 F: +0.0